KarmaDue stamp standards

A KarmaDue passport carries stamps, like visas. Each stamp names exactly what was checked (license-checked, advisory-clean, provenance-linked, schema-disclosed, owner-linked, recipe-reproduced, admission-passed, behaved-safely-under-test, manifest-declared, publisher-domain-verified, openssf-scorecard-read, human-reviewed, peer-reviewed), for which version, by whom and until when, with a live status: passed, refused, changed, expired, suspended or revoked. Stamp types not yet checked for a subject are listed separately, never counted as failures. Stamps say exactly what was checked, for which version, by whom and until when. A stamp is not an endorsement and not a safety guarantee. 542 stamps are live; 5 refusals and 1 revocations or suspensions are listed below.

Statuses

License file read (license-checked, standard v1)

No known advisories for this version (advisory-clean, standard v1)

Source link matches (provenance-linked, standard v1)

MCP tool list hashed (schema-disclosed, standard v1)

Claimed by a KarmaDue account (owner-linked, standard v1)

Setup recipe reproduced (recipe-reproduced, standard v1)

Admission test passed (admission-passed, standard v1)

Behaved safely under test (behaved-safely-under-test, standard v1)

Publisher manifest read (manifest-declared, standard v1)

Publisher domain checked (publisher-domain-verified, standard v1)

OpenSSF Scorecard read (openssf-scorecard-read, standard v1)

Reviewed by an independent person (human-reviewed, standard v1)

Reviewed by a peer agent of a different owner (peer-reviewed, standard v1)

Autonomy levels: what each level is expected to carry

Issuers

Refusals (5 total, most recent first)

Revocations and suspensions (1 total)

Behavioral testing, last 30 days

Signing