szl-evidence-mandate
A Scientific Evidence Gate engine plus evidence-backed, read-only audits of the
szl-holdings GitHub organisation and the SZLHOLDINGS Hugging Face estate.
A passing check must emit enough evidence to prove it had the opportunity to fail. The system producing an answer must not be the sole authority certifying that its own verification occurred.
Maturity: research prototype (v0.1.0). Licence: Apache-2.0 (org standard; see LICENSE).
What it does
| Component | What it verifies |
|---|---|
szl_evidence engine |
Manifest-declared inputs are present, opened and fully examined; every required check ran (hash-chained invocation ledger); claims are registered, replayable and numerically correct; dependency staleness blocks publication; receipts are canonical and content-bound. Exit codes: PASS 0, FAIL 1, ABSTAIN 2, ERROR 3. |
| Mutation harness | 19 mandated mutations + 4 blind-spot probes; undetected mutations are reported as BLIND_SPOT, never hidden. |
audit.github |
Every repo (all pages), shallow clones, file-class presence, licence consistency, secret scan (locations only), risky-code patterns, CI/release/protection state, clean-venv install/import/--help/tests, 12-axis scorecard. |
audit.huggingface |
Every model/dataset/Space, card scorecard, Space runtime + read-only probes, weight-header checks by HTTP range, small-array loads without pickle, dataset slices, conformance-corpus replay against the paired verifier. |
reconcile / zoomout |
Cross-surface links, orphans, version drift, schema skew, recomputed inventories vs every stated count; band-aid detection with root cause and structural fix. |
Quick start (under ten minutes)
python -m venv .venv
.venv/bin/pip install -e ".[dev]" # Windows: .venv\Scripts\pip
szl-audit engine verify fixtures/valid # exit 0
szl-audit engine verify fixtures/empty-input # exit 2 (ABSTAIN: nothing examined)
szl-audit engine mutate fixtures/valid # prints BLIND_SPOTS
python -m pytest -q
Full audit (read-only; uses GITHUB_TOKEN/gh auth token and HF_TOKEN/HF cache token if present, never printed):
szl-audit engine report --output reports
szl-audit github --org szl-holdings --clone --stream --deep --output reports # --stream: one repo on disk at a time
szl-audit hf --org SZLHOLDINGS --functional --output reports
szl-audit reconcile --output reports
szl-audit zoomout --output reports # also renders reports/00..11
Every command writes a receipt under reports/receipts/ and supports --dry-run.
Evidence boundary
- Integrity: receipts bind content by SHA-256 and chain invocations. Receipts are
UNSIGNEDunless a real key is configured; no signature is ever fabricated. - Performance: not measured by this tool beyond wall-clock durations of smoke tests.
- Validity: not established. A receipt supports integrity, provenance, and replayability. It does not establish scientific truth, accuracy, safety, or fitness for use.
What this does not prove
- That audited repositories or models are correct, secure, or fit for any purpose.
- That the engine catches defect classes outside its mutation set (see published blind spots).
- That a claim marked
UNVERIFIABLEis false, or that aSTALEclaim was ever wrong. - That install failures observed on the (Windows) audit host reproduce on Linux.
Layout
src/szl_evidence/ engine and audits · fixtures/ 19 generated fixtures (regenerate
with szl_evidence.fixturegen.build_all) · schemas/ receipt and manifest JSON Schemas ·
tests/ · reports/ generated output · examples/.
Metadata
Release files for szl-evidence-mandate 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| szl_evidence_mandate-0.1.0.tar.gz | 150.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| szl_evidence_mandate-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 304.7 kB
Release files / szl_evidence_mandate-0.1.0.tar.gz
| Download URL | szl_evidence_mandate-0.1.0.tar.gz |
|---|---|
| Size | 150.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
06e7c7e5a0138e883bb0c57e4003b95476e93012e146a26226d1988a851b7e18
|
|
BLAKE2b-256 checksum How to use checksums |
f6108be0f9ec4a41dac962479d2d1c7579a7e2e2ceb7c62eb2825c2530e1b5e8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / szl_evidence_mandate-0.1.0-py3-none-any.whl
| Download URL | szl_evidence_mandate-0.1.0-py3-none-any.whl |
|---|---|
| Size | 154.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
85973eeba9057c50fdac372b609f50925e9ad199d52753e62577512eadcce951
|
|
BLAKE2b-256 checksum How to use checksums |
ae1104d353c2b8c6f3aed3e3a238613d74d2e6fd982ffeb5fe69c282785405c7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log