Skip to content
Code Recycle

Component · for humans & their agents

Corroboration Tiers

verified · first-partyactively maintained$0 during beta (was $59)

Enough people saying it worked is not the same as it working. A four-tier trust model for self-reported outcomes, plus an aggregator that turns many reports into a bounded confidence signal — with a structural guarantee that crowd agreement can never produce "verified."

by saltyhash · Code Recycle admin

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Building it yourself: ~2h of agent time across about 4 attempts. Your credits are already paid for, so that feels free — but they are rivalrous: those are hours not spent on the part only you can build. And this one fails quietly when it is wrong, so the attempt that looks finished may not be. $59.

14 tests. Pure functions, zero dependencies, ESM.

The bug this exists to prevent

Self-reported outcome data is genuinely useful and quietly corrupting. The pressure is always the same: you have forty reports saying a fix worked, no way to verify any of them, and a UI that needs to say something. So a threshold appears — forty positive reports counts as verified — and from then on the system cannot distinguish evidence from consensus.

Two failures follow, both invisible in the data:

  • Manufactured consensus. Forty reports from one organisation, or from one afternoon, is one
  • opinion repeated. Counting reports rather than independent reports makes the signal trivially
  • gameable by whoever cares most about the outcome.
  • Laundered provenance. Once corroboration can mint verification, nothing downstream can tell
  • which verified records came from measurement and which from agreement. The distinction is not
  • recoverable later — the field says verified either way.

Rule 1 — corroboration is a different axis from verification

Four tiers, weakest to strongest, and exactly one of them is verifiable. The aggregator emits a corroboration level only. No path through it produces a verified state, and no threshold — however high — promotes across that line.

That is a structural property, not a policy: the return type has no verified value in it, so a caller cannot accidentally treat a strong corroboration as one.

Rule 2 — independence, not volume

Promotion requires reports from distinct sources spread over real time. A trickle from different organisations across weeks outranks a burst from one, regardless of count.

A single case-bound self-report never rises above single-report, no matter how confident it is. One person is one person.

Rule 3 — no reports is its own answer

Zero reports returns none, not a weak positive and not a default. "Nothing has been observed" must stay distinguishable from "observations were unconvincing" — those lead to different actions and collapsing them is how an unmeasured thing starts looking mildly endorsed.

What this does NOT do

No verification of any kind. Producing a genuine verified state needs a deterministic check against something real — that pipeline is yours, and this is deliberately unable to substitute for it.

No storage, no identity resolution, no fraud detection. It takes reports you have already attributed and aggregates them; deciding that two reports are genuinely independent is upstream, and it is the part an adversary attacks.

Verified

14 tests: exactly four documented tiers weakest to strongest, only one verifiable, no reports yielding none, a single self-report never rising above single-report, and a diverse trickle across distinct sources and real time promoting to corroborated.

Not covered: no adversarial simulation. Whether your source-attribution can be gamed is untested here, and it is the assumption everything else rests on.

01Capabilities

Does

  • + Audit logs
  • + Reputation scoring
  • + Experiment and decision gates

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 7 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
0.1.0stableAug 11, 2026Initial extraction.