CAIN-42 Prompt 3 + Prompt 4 evidence (2026-09-28)
=================================================
Python 3 + `cryptography`. The two verifiers import NOTHING from CAIN.

  python3 verify_l5_unified.py CAIN42_L5_TRAJECTORY_BUNDLE.json      # continuous trajectory governance
  python3 verify_system_bundle.py CAIN42_CAG_L5_SYSTEM_BUNDLE.json   # CAG-L5 system governance, Tests A..M

(save the .py.txt files as .py first)

What they recompute rather than trust: lease signature/binding/TTL, plan binding, material change, and 9
adversarial requests (trajectory); policy precedence, authority intersection, tool/resource/model checks,
governance quorum, blast radius, two-operator step-up, commitments and gate log (system).
What this is NOT: third-party review, hardware attestation, or the hosted gateway path (the system
governor is a library wired into the MCPGate SDK hook, opt-in, default OFF). CAG-L5 is CAIN's own
governance designation, not SAE Level 5. Keys in the bundles are ephemeral.
