verification/TK-11415/README.md
# TK-11415 verified triage closure Verified September 10, 2026, on macstudio3. Result: **PASS**, 25 boundary assertions. The blocker was stale. The canonical decision at `~/.claude/yolo-queue/pending-approval/_decisions.jsonl:683`, timestamp `2026-09-10T20:48:51Z`, records approval-agent/TK-11435 filing `2026-09-02-TK11133-meilisearch-key-rotation-routing.md` into `_resolved` as SUPERSEDED/BLOCK with “No pending Steve action.” The archived memo exists and the former pending path does not. No new approval was inferred or issued. The key ending **fbd6**, digest prefix `66fd704dc09f`, matches Momentum's anonymously served [public JavaScript bundle](https://momentumco.com/build/assets/app-DOnLSWOi.js). A one-result search returned HTTP 200. An invalid-key search and the actual key's GET `/keys` both returned HTTP 403 `invalid_api_key`. All six classification annotations and their three commits remain present. Three JavaScript syntax checks and three Python in-memory compile checks passed. The authenticated HTML snapshot remains untracked, explicitly gitignored, and absent from path history. Its contents and credential were not exercised. The existing client happy-path, authentication failure, and malformed-response tests passed 3/3. ## Limits - Key-management denial does **not** prove absence of every write permission. The earlier memo and comments overstated that inference. This report and the ticket correction supersede that claim; vendor security is not certified here. - All three annotated repositories currently have no configured remotes. This does **not** prove they were never pushed historically. - Snapshot containment was rechecked using tracking, ignore rules, and path history. No new whole-disk exposure scan was performed. - Vendor rate-limit/attribution risk and future repository governance remain considerations. ## Evidence and reproduction - `e2e-proof.json`: timestamped API, file, queue, and test assertions, checked repository heads, and limitations. - `client-tests.tap`: 3/3 client tests with explicit TAP reporting. - `dtd-verdict.md`: zero-cost review, two valid votes, four abstentions, adversarial KEEP. - `verify.mjs`: read-only verifier. Run `node verification/TK-11415/verify.mjs` from this checkout on macstudio3; it needs network access and the existing sibling repositories and writes redacted results to `/tmp/tk11415-e2e-proof.json`. It never prints the literal key or response hits. It does not regenerate this committed report. The initial verifier expected TAP while Node 26 selected its spec reporter. Only that harness assertion failed; an explicit TAP rerun passed and was recorded without repeating live API calls. Evidence changes are additive and require no operational rollback. No credentials were rotated or routed, no vendor writes were attempted, and no production, publishing, deletion, or remote-push action occurred.