The review record
Machine review was the first gauntlet. Human review is the one that matters.
Before publication the whitepaper went through adversarial machine review — not a substitute for human judgment, but a way to find the cheap failures early. Every finding and its disposition is in the public record, next to the claims it graded.
The gauntlet
Adversarial machine review, using frontier models from OpenAI, xAI, and Google
Some passes were consumed; at least one was excluded — it had read a stale draft and carried reliability problems — and it is preserved in the corpus anyway, because an excluded pass that disappears is indistinguishable from one that never happened.
The counts are deliberately not stated here. This page tracks the record as it currently stands, and a count written onto a living surface is a moving target stated without a boundary. The record itself carries the counts and the specifics — the manifest and the dispositions ledger are authoritative, and both are published below.
First — the architecture
Whitepaper, release-candidate line
Attacked the design.
Produced the adoption cluster — governance tax, cold-start, migration playbook — and a convergence across independent instruments on the exception layer as the consensus-predicted failure surface. That convergence became the pre-registration of hypothesis H1.
Then — the wording
Whitepaper, later candidates
Attacked the prose, and found one composition attack.
Credited the earlier repairs as held. Produced the self-dilution finding — two separately declared postures composing into an attack inside the governance plane itself — plus a precision batch and a set of adversarial probes now folded into the gate-0 probe suite.
Finally — the substrate
The live repository
Stopped reading the paper and inspected the thing itself.
Repository-grounded instruments cross-examined the paper against the running record, and upgraded their assessment on inspection. The programme closed on a convergence that the next useful artifact is data rather than prose — so it was closed deliberately, with the first end-to-end chain run named as the next reviewer.
The wider corpus
The corpus is wider than the whitepaper line: it also holds the independent reviews of the companion documents, across several instrument families, every one operator-anchored, with consumed and excluded passes counted separately. The exact figures live in the manifest and are stated there per set, because a single headline number would have to pick a denominator and would then be quoted without it. Every file carries a SHA-256, and the manifest states the rule plainly: the digest identifies, the filename locates; if they disagree, the digest governs.
What the last round said
The repository-grounded instruments upgraded their assessment on inspection
This is the part worth weighing carefully, because it is the verify-rather-than-trust posture being exercised by exactly the audience it was built for — and holding.
“not vaporware… a working, self-governing software substrate… one of the most intellectually honest agentic AI projects in open source”
“high-quality design argument with a public, partially operating implementation”
“crossed from a coherent governance architecture with prototype evidence into a real, publicly inspectable substrate”
Read those with the discount they deserve
They are machine assessments of a document and a repository, reproduced because they are on the public record — not because a model’s praise is evidence of anything. AI reviewers can share blind spots in ways that make agreement cheaper than it looks. Instruments converging is weaker evidence than it appears if they converge for correlated reasons. That is precisely why the request below is for human review.
The uncomfortable entries
Two findings the record keeps that a cleaner record would have dropped
An overclaim, identified as the project’s own regression
A repository-grounded reviewer found that “a red suite blocks merge” holds only if the status check is required on the protected branch — the workflow is a control; the repository rule is the enforcement.
The disposition does not just accept the finding. It records that the overclaim was a regression the project introduced itself during a rewrite that dropped a disclosure earlier reviewers had praised. The fix went to both the paper and the repository — the branch-protection state became a governed evidence object, captured live rather than asserted.
That control is the one you can run yourself, with no credential.
A review artifact that misidentifies its own author
One companion-document review carries frontmatter claiming a different model produced it than actually did. The manifest corrects the attribution and binds the correction to the exact bytes by digest.
The file keeps its false header. Quietly editing it would have produced a tidier corpus and destroyed the evidence that the attribution method can fail — which is itself a finding, and a more useful one than the review it appeared in.
Two further standing corrections ride the same manifest, and the excluded passes are named rather than omitted from the counts.
A review record that contains only the findings you accepted tells you nothing about the reviewer and less about the author. The declines are where the reasoning is.
Read it yourself
The full record, rendered from source
Unedited, at the pinned commit. These are the working documents, not a summary of them — they are dense, and that is what they are for.
Review dispositions
The review-round ledger. Each external finding with its disposition — applied, declined with reasons stated, or routed as tracked work. This document carries the counts and the specifics; the site refers to it rather than restating them.
docs/EXTERNAL_REVIEW_DISPOSITIONS_v1.0.md
Review corpus manifest
Inventory and identity record: every artifact with its SHA-256, which instrument produced it, and what was done with it — including the two passes excluded from absorption and the artifact whose own frontmatter misattributes its author.
docs/ADVERSARIAL_REVIEW_CORPUS_MANIFEST.md
Review corpus classification
Per-artifact subject and instrument attribution, per-set review counts, and findings about the attribution method itself.
docs/ADVERSARIAL_REVIEW_CORPUS_CLASSIFICATION.md
Reference audit
The internal citation audit: zero support-class gaps, three precision upgrades. Executed in response to a reviewer finding rather than volunteered.
docs/REFERENCE_AUDIT_v0.1.md
The ask
Now the review that matters
If you build agent platforms, run governance programs, or review systems work professionally — tear into this.
Every human finding gets the same treatment the machine findings did: applied, declined with reasons, or tracked openly — on the public record, credited to you if you want it.
The paper, the corpus, and the evidence are public. Where the claims and the record disagree, the record wins. Come find where they disagree.
An issue on the platform repository is the preferred route — a finding filed in the open is already halfway to being dispositioned in the open. If you would rather not start there, republic@eldritchlabs.net.