Check privacy and evidence usefulness separately
Verify that an export is scrubbed and independently verify that its remaining evidence still supports its claims.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
A scrubbed failure bundle withholds sensitive tool results. Privacy CLEAN does not mean its database-cause finding remains supported within the export. Check these goals separately.
Mechanism
Audit the final file set under privacy policy, then resolve/read evidence for every finding using the bundle alone, not path existence. Mark missing support limited/pending without retaining secrets. Reconcile reports/README/manifest/scrub counts, archive checked bytes and verify unpacked identity. Separate preparation from actual delivery.
Bad example
Privacy CLEAN proves all findings, treating a filename as evidence even without result content.
Good example
Record privacy status and per-finding support independently. Withheld results make root-cause evidence limited and summaries need correction. Archive reviewed files and compare unpacked hashes. Never expose secrets in logs; changed exports need affected rechecks.
Why the change matters
Privacy removes information while proof requires it. Separate outcomes disclose both safety scope and reasoning limits instead of one green label.
Observable expectation
Teaching secret-free content with absent result is privacy-clean/evidence-limited. Read cited content, not merely locations. An extra unreviewed archive attachment fails set reconciliation until checked.
Limits
CLEAN is scoped policy checking, not exhaustive certification. Opaque encrypted content may remain unsuitable. Preserve safe linkage and disclose unsupported claims rather than publishing stronger conclusions after removing evidence.
Sources and evidence
- obra/superpowers · Evidence reconciliation / privacy audit
File at this version8ca22dba9a94 - obra/superpowers · Privacy audit scope
File at this version8ca22dba9a94