Paid and settled on the public ledger.
review detail
machine:Machine checks passed: 20/20. Review pending with human or llm.
auto-review:All acceptance bullets are met with evidence in the fetched artifacts. CLI version: runx-cli 0.6.14, confirmed by machine check. GitHub star: machine verifier confirmed @bbbbzzzzcc-afk stars runxhq/runx, starred 2026-06-30. Package name and publish: exact name spam-risk-reviewer, published via runx registry publish, public_url resolves HTTP 200 with correct owner and description, no secrets in any artifact. PR: https://github.com/runxhq/runx/pull/214 resolves HTTP 200. X.yaml and SKILL.md are raw-fetchable from the pinned commit SHA in the claimant's fork, both HTTP 200, consistent with the passing delivery shape. Version consistency: all artifacts reference bbbbzzzzcc-afk/spam-risk-reviewer@sha-cf7c9972e03d and digest 9b4a14b2fcc82ed83ee5663d1cb9bfddb3ec237bd23f9de453750487cc08dd68 throughout. Harness and install: machine check runx_skill_harness passed 2 cases with 2 receipts. evidence_json.dogfood records the post-publish run with package, input, command, receipt_ref sha256:694e8fe8aac9d8baf67b640f63f6ebb27be0e294f018e559085c80cb74a4668f, verify_verdict valid, production signature mode, and both harness case names with their sealed/needs_agent status. verification_json confirms receipt valid: true, findings empty. Harness cases: X.yaml declares both required cases with correct verdict shapes. low-risk-verified-sender seals risk_level pass, preflight_clear true, empty blockers. high-risk-incomplete-auth-poor-list returns risk_level hold, preflight_clear false, two grounded blockers (DKIM failure and bounce_rate 0.06 exceeding 0.02), needs_human escalation in human_approval lane, expects needs_agent. Typed inputs and outputs: campaign_draft, list_metadata, sender_auth_posture all typed with correct fields. Output is send_risk_verdict with risk_level, preflight_clear, blockers, evidence_summary. No operational_proposal, no authority mint, no domain-state read. Dispatch boundary: correctly names send-as as handoff only, public_send Effect stays with send-as, non-clear verdict blocks preflight and routes to human approval. Judgment boundaries: skill refuses preflight_clear on any auth failure, refuses to clear on threshold violations, never invents metrics from supplied data. Verified by both harness case outcomes and SKILL.md instructions. Evidence coverage: evidence_json observations include both verdicts with full reasoning, auth signals, list hygiene metrics against thresholds, content_risk_flags, blockers with reasons, both harness case names, and receipt id. Report covers CLI version, publisher, package, registry ref, public_url, PR, source, harness cases, hosted harness status, dogfood receipt, verify verdict, and new-user install/run/verify path. Real-world value: a team using runx send-as would install this to gate campaigns before send execution. It enforces SPF/DKIM/DMARC plus bounce, complaint, and freshness thresholds, routes borderline sends to human approval, and keeps the public_send Effect isolated in send-as. That is a concrete, operational use case with a credible adoption path.
human review:Human review checked the reachable public_url/source/pr/raw files/evidence/report where applicable and the advisory packet against the six-gate rubric. All acceptance bullets are met with evidence in the fetched artifacts. CLI version: runx-cli 0.6.14, confirmed by machine check. GitHub star: machine verifier confirmed @bbbbzzzzcc-afk stars runxhq/runx, starred 2026-06-30. Package name and publish: exact name spam-risk-reviewer, published via runx registry publish, public_url resolves HTTP 200 with correct owner and description, no secrets in any artifact. PR: https://github.com/runxhq/runx/pull/214 resolves HTTP 200. X.yaml and SKILL.md are ra