CODEPLUSONE - GLOBAL SHORTCUT ISOLATION TEST

Read the PDF for the review scope, result and behavioral procedure.
Test: 24 September 2026, 19:22:12-19:22:57 EDT.
Presentation update only: recorded event data is unchanged. The owner-supplied
completion screenshot is added as visual evidence of the same test.
New York time is a display convention only; no test location is asserted.

Astra / Codex AI reviewed. Astra is a requested label, not an independently
verified model identity. No OpenAI endorsement or independent certification.

PUBLIC EVIDENCE SHA-256
65b2e00feb5186045405a941db0a6a2b9414393856ec5adf56fff86342e1400f
PUBLIC KEY SHA-256 (DER SubjectPublicKeyInfo)
1abfb0d5882b03ba52859eebc44e557d11e0671f8bb483db70746faf78304d2d

INCLUDED
The PDF, its detached signature, public-evidence.json, verification-key.pem,
manifest.json, manifest.sig, completed-test-screen.png, and this README. The
public evidence JSON and screenshot are embedded in the PDF. Screenshot bytes
are unchanged, under a neutral filename. Redacted extracts are not raw logs. Original
source record hashes identify privately retained records, which recipients
cannot compare without obtaining those records separately.

EXCLUDED
Collection/test scripts, feature source, internal component/API names, internal
action identifiers, binding configuration, private keys, local paths, and raw
unredacted logs. Verification commands below only check hashes and signatures;
they do not collect inputs or implement the shortcut feature.

VERIFY FROM THIS EXTRACTED FOLDER (OpenSSL and shasum)
1. Compare the key fingerprint with a separately trusted copy of the report:
openssl pkey -pubin -in verification-key.pem -outform DER | openssl dgst -sha256
2. Verify the signed manifest:
openssl dgst -sha256 -verify verification-key.pem -signature manifest.sig manifest.json
3. Verify the PDF signature:
openssl dgst -sha256 -verify verification-key.pem -signature codeplusone-shortcut-validation-public.pdf.sig codeplusone-shortcut-validation-public.pdf
4. Recompute every listed file hash and compare with manifest.json:
shasum -a 256 README.txt public-evidence.json completed-test-screen.png verification-key.pem codeplusone-shortcut-validation-public.pdf codeplusone-shortcut-validation-public.pdf.sig
5. Inspect the public evidence to check the 23 activation records, zero main-key
browser events, 58 modifier events and the separate OFF/ON control. Cross-check
summary rows against event records, not only against the headline.

SIGNATURE LIMITS
RSA-3072 / PKCS#1 v1.5 / SHA-256. A new local key was generated in memory for
this revision; its private key was not saved or distributed. The prior package
signature and file hashes were verified before preparing the redacted extracts.
A valid new signature does not prove the old events happened or establish the
signer's identity. There is no trusted timestamp or independent witness.
Replacing the public key, evidence and signatures together can create a new
internally consistent package. Retain the expected fingerprint separately.
The evidence hash on page 1 covers public-evidence.json, not the PDF itself;
the PDF's hash is in manifest.json to avoid self-referential hashing.
