Skip to main content

szl-evidence-mandate

A Scientific Evidence Gate engine plus evidence-backed, read-only audits of the szl-holdings GitHub organisation and the SZLHOLDINGS Hugging Face estate.

A passing check must emit enough evidence to prove it had the opportunity to fail. The system producing an answer must not be the sole authority certifying that its own verification occurred.

Maturity: research prototype (v0.1.0). Licence: Apache-2.0 (org standard; see LICENSE).

What it does

Component What it verifies
szl_evidence engine Manifest-declared inputs are present, opened and fully examined; every required check ran (hash-chained invocation ledger); claims are registered, replayable and numerically correct; dependency staleness blocks publication; receipts are canonical and content-bound. Exit codes: PASS 0, FAIL 1, ABSTAIN 2, ERROR 3.
Mutation harness 19 mandated mutations + 4 blind-spot probes; undetected mutations are reported as BLIND_SPOT, never hidden.
audit.github Every repo (all pages), shallow clones, file-class presence, licence consistency, secret scan (locations only), risky-code patterns, CI/release/protection state, clean-venv install/import/--help/tests, 12-axis scorecard.
audit.huggingface Every model/dataset/Space, card scorecard, Space runtime + read-only probes, weight-header checks by HTTP range, small-array loads without pickle, dataset slices, conformance-corpus replay against the paired verifier.
reconcile / zoomout Cross-surface links, orphans, version drift, schema skew, recomputed inventories vs every stated count; band-aid detection with root cause and structural fix.

Quick start (under ten minutes)

python -m venv .venv
.venv/bin/pip install -e ".[dev]"          # Windows: .venv\Scripts\pip
szl-audit engine verify fixtures/valid      # exit 0
szl-audit engine verify fixtures/empty-input  # exit 2 (ABSTAIN: nothing examined)
szl-audit engine mutate fixtures/valid      # prints BLIND_SPOTS
python -m pytest -q

Full audit (read-only; uses GITHUB_TOKEN/gh auth token and HF_TOKEN/HF cache token if present, never printed):

szl-audit engine report --output reports
szl-audit github --org szl-holdings --clone --stream --deep --output reports   # --stream: one repo on disk at a time
szl-audit hf --org SZLHOLDINGS --functional --output reports
szl-audit reconcile --output reports
szl-audit zoomout --output reports      # also renders reports/00..11

Every command writes a receipt under reports/receipts/ and supports --dry-run.

Evidence boundary

  • Integrity: receipts bind content by SHA-256 and chain invocations. Receipts are UNSIGNED unless a real key is configured; no signature is ever fabricated.
  • Performance: not measured by this tool beyond wall-clock durations of smoke tests.
  • Validity: not established. A receipt supports integrity, provenance, and replayability. It does not establish scientific truth, accuracy, safety, or fitness for use.

What this does not prove

  • That audited repositories or models are correct, secure, or fit for any purpose.
  • That the engine catches defect classes outside its mutation set (see published blind spots).
  • That a claim marked UNVERIFIABLE is false, or that a STALE claim was ever wrong.
  • That install failures observed on the (Windows) audit host reproduce on Linux.

Layout

src/szl_evidence/ engine and audits · fixtures/ 19 generated fixtures (regenerate with szl_evidence.fixturegen.build_all) · schemas/ receipt and manifest JSON Schemas · tests/ · reports/ generated output · examples/.

Metadata

Release files for szl-evidence-mandate 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for szl-evidence-mandate 0.1.0
File Size Uploaded
szl_evidence_mandate-0.1.0.tar.gz 150.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for szl-evidence-mandate 0.1.0
File Interpreter ABI Platform
szl_evidence_mandate-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 304.7 kB

Release files / szl_evidence_mandate-0.1.0.tar.gz

Download URL szl_evidence_mandate-0.1.0.tar.gz
Size 150.2 kB
Tags Source
SHA-256 checksum
How to use checksums
06e7c7e5a0138e883bb0c57e4003b95476e93012e146a26226d1988a851b7e18
BLAKE2b-256 checksum
How to use checksums
f6108be0f9ec4a41dac962479d2d1c7579a7e2e2ceb7c62eb2825c2530e1b5e8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / szl_evidence_mandate-0.1.0-py3-none-any.whl

Download URL szl_evidence_mandate-0.1.0-py3-none-any.whl
Size 154.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
85973eeba9057c50fdac372b609f50925e9ad199d52753e62577512eadcce951
BLAKE2b-256 checksum
How to use checksums
ae1104d353c2b8c6f3aed3e3a238613d74d2e6fd982ffeb5fe69c282785405c7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page