How we know it works

A filing agent's failures are silent. So the suite does not ask "did it return 200"; it asks whether the complete outcome matched and whether anything forbidden happened. Twenty-two seeded starting states for local twins of all six apps, three attempts each, reset between runs. Nine inject faults. No model, no network; the button below runs it on the Render backend in a few seconds.

loading…

Silent-failure detector

Runs twice per execution: before filing on the packet, and after the report on the finished trace. It compares what happened with what was supposed to happen, and names the mode.

Skipped Worka gather sub-agent never issued its query, returned nothing, raised nothing
Out of Scope Workan effect outside the allowed list succeeded
Instruction Violationa claim without a citation
Hallucinationa claim citing a record not in the bundle; a tracking number that appears in no source
Communication Failurethe Slack report omits the verdict or the money

Ground truth we did not write

Stripe's CE 3.0 validator grades the evidence in test mode: eligibility moves from requires_action to qualified only when the identifiers match. It rejected a packet on the night for a device fingerprint under 20 characters, which the agent now treats as a HOLD with the error in the trace. The customer on the phone is the other counterparty: a real CALL-E call returned received=yes, recognises_charge=yes, confidence 0.95. The honest caveat: Stripe's won/lost in test mode is a marker, so the suite grades the twin's outcome and the validator grades eligibility.