{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp12_substrate_denial72_20260805","research_id":"eoa_inverse_innovation_exp12_light_screen_20260805","cell_id":"authority_legitimacy_and_consent_foundations__computer_science","search_lanes":{"direct_problem_and_intervention":{"queries":["package registry malware quarantine policy appeal maintainer npm PyPI","software package registry governance malware removal appeal transparency maintainer","package registry removal policy transparency appeal malicious packages"],"source_ids":["SRC1","SRC3","SRC4"],"no_result_note":"No retained source described the complete proposed mandate with 24-hour emergency authority, seven-day representative review, automatic expiration, and governing-body reservation of permanent sanctions."},"synonyms_and_historical_terms":{"queries":["package repository quarantine malicious package governance review","package deletion unpublish yank retract policy maintainer consent","content moderation emergency removal time limit appeal statement of reasons"],"source_ids":["SRC1","SRC2","SRC3"],"no_result_note":"The search found quarantine, deletion, unpublishing, yanking, retraction, moderation, and appeal practices, but not the full authority-charter bundle."},"products_practices_and_standards":{"queries":["PyPI project quarantine security feature specification quarantine malware","OpenSSF package deletion policy transparency appeal maintainer removal","npm malware package remove security policy appeal"],"source_ids":["SRC1","SRC2","SRC4"],"no_result_note":null},"component_combination":{"queries":["package repository security policy transparency log removal decisions appeal maintainer","package registry malware reversible quarantine public reasons independent review","platform governance emergency suspension decision review time limit appeal transparency standard"],"source_ids":["SRC1","SRC2","SRC3"],"no_result_note":"Adjacent components were found across sources, but no opened source combined fixed emergency duration, conflict-screened technical and constituency review, public signed reasons, automatic expiry, and an outcome-changing appeal."}},"sources":[{"source_id":"SRC1","title":"Project Quarantine","publisher":"Python Package Index","url":"https://blog.pypi.org/posts/2024-12-30-quarantine/","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["Malware reports are a persistent operational problem for PyPI.","Complete project removal was disruptive and nearly irrevocable, motivating a reversible quarantine state.","Quarantine makes a project un-installable and unmodifiable while allowing an administrator to restore or delete it.","About 140 projects had been quarantined; one exited quarantine and the others were removed.","PyPI had not yet defined what report quantity and credibility should trigger proposed automatic quarantine."]},{"source_id":"SRC2","title":"Crafting a Package Deletion Policy","publisher":"OpenSSF Securing Software Repositories Working Group","url":"https://repos.openssf.org/package-deletion-policies","source_type":"OFFICIAL_GUIDANCE","claims_supported":["Registry deletion policies must balance maintainers, consumers, administrators, and ecosystem interests.","Administrator intervention is needed for malicious content even when removal disrupts users.","Policies should distinguish deletion, yanking, retraction, and deprecation and be precise about granularity and alternatives.","Guidance recommends explaining when administrators intervene, when users may petition for deletion, and keeping the community involved.","Dependency relationships and mirror or registry architecture make package-removal consequences broader than the publisher alone."]},{"source_id":"SRC3","title":"The MCP Registry Moderation Policy","publisher":"Model Context Protocol","url":"https://modelcontextprotocol.io/registry/moderation-policy","source_type":"OFFICIAL_GUIDANCE","claims_supported":["An operational registry policy explicitly enumerates malware and other removal categories.","Removal sets a deleted status while normally retaining metadata for API access.","Affected publishers can appeal a suspected mistake through a stated route.","The policy distinguishes material that will and will not be removed, but gives no fixed decision duration, independent reviewer requirements, or automatic expiration."]},{"source_id":"SRC4","title":"Reporting malware in an npm package","publisher":"npm","url":"https://docs.npmjs.com/reporting-malware-in-an-npm-package/","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["npm reports having removed hundreds of malicious packages.","Its stated workflow confirms a report, removes the package, publishes a placeholder and advisory, and considers banning the uploader.","The published malware workflow establishes a reporting and technical-action process but does not describe temporary quarantine limits or an appeal within that workflow."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The operational substrate is clearly visible: registries receive persistent malware reports, remove or quarantine artifacts, and face disruption, reversibility, staffing, ecosystem-impact, and false-positive concerns. Published guidance also recognizes competing maintainer, consumer, administrator, and ecosystem interests and the need for precise policies. However, the retained sources do not directly document repeated incidents in which quarantine was delayed or circumvented specifically because actors contested the registry's legitimacy or standing. The proposed authority-foundation diagnosis is therefore only partly supported.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"closest_prior_art":[{"name":"PyPI Project Quarantine","source_ids":["SRC1"],"overlap":"A registry administrator can impose a reversible, non-destructive state that prevents installation and owner modification while preserving the option to restore visibility after a false positive.","remaining_difference":"The published design does not specify a 24-hour automatic expiry, a separate seven-day extension class, conflict-screened technical and constituency reviewers, a signed partially public reason record, or an outcome-changing independent appeal."},{"name":"OpenSSF package-deletion-policy guidance","source_ids":["SRC2"],"overlap":"Calls for explicit, granular policies that balance maintainers, consumers, administrators, and ecosystem effects; distinguishes less destructive alternatives and recommends community involvement and petition routes.","remaining_difference":"It is general guidance, not an operative emergency-quarantine mandate, and does not allocate timed decision classes or prescribe credentials, conflicts, independent review, automatic expiration, or signed reason records."},{"name":"MCP Registry Moderation Policy","source_ids":["SRC3"],"overlap":"Defines removal scope and categories, retains metadata after removal, and supplies a stated appeal route for alleged mistakes.","remaining_difference":"It lacks emergency-versus-permanent decision classes, fixed expiry, competence criteria, conflict screening, affected-constituency participation, independent extension review, and specified appeal powers."},{"name":"npm malware-report handling process","source_ids":["SRC4"],"overlap":"Specifies evidence submission, validation, package removal, public placeholder and advisory, and possible account action.","remaining_difference":"The published process is removal-centered and does not expose bounded temporary authority, automatic expiry, independent review, affected-party representation, or an appeal within the malware workflow."}],"prior_art_disposition":"ADJACENT_PRIOR_ART","contrastive_claim_remaining":"For registries where disputes about who may decide materially contribute to quarantine delay or relitigation, the testable remaining claim is that combining explicit timed decision classes with domain-matched competence, conflict-screened technical and affected-party review, automatic expiry, signed redacted reasons, and an appeal empowered to alter the result will improve independent identification of decision rights and reduce unresolved jurisdiction objections without exceeding the predeclared response-time budget. The bounded search found individual and partial combinations, but not this complete registry-specific bundle.","contrastive_claim_falsifier":"The claim would be falsified by an opened operational registry policy implementing materially the same bundle, or by the proposed record review showing no failures attributable to authority, boundaries, competence, conflicts, reasons, representation, or remedy. It would also fail if tabletop participants cannot identify the decision rights, quarantine becomes indefinite without new authorization, review cannot change an erroneous result, redaction cannot protect sensitive evidence, or the procedure exceeds the governing body's emergency-response budget.","gates":{"adequate_source_search":{"status":"PASS","rationale":"The bounded search covered the proposal directly, quarantine and removal synonyms, older practices such as unpublishing, yanking and retraction, current registry products and policies, cross-registry guidance, and combinations involving transparency, appeals, review, and time limits. Exactly four opened sources from four publisher identities were retained, including first-party and official guidance.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"supported_problem":{"status":"PASS","rationale":"The sources support persistent registry malware, consequential removal decisions, false-positive reversibility, limited moderation capacity, ecosystem disruption, competing stakeholder interests, and policy-definition needs. Direct evidence of legitimacy disputes is absent, so support is partial rather than full.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"distinct_testable_claim":{"status":"PASS","rationale":"Although reversible quarantine, policy granularity, public artifacts, and appeal routes are prior art, the located sources do not disclose the candidate's combined timed delegation, dual-role extension review, competence and conflict rules, automatic expiry, signed redacted reasons, and outcome-changing appeal. Its effect can be tested against stated comprehension, objection, timing, redaction, and reversibility measures.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"bounded_next_test":{"status":"PASS","rationale":"The proposed two-week diagnostic is bounded to eight redacted records, four synthetic cases, and at most twelve voluntary participants. It is non-production, has explicit measures and falsifiers, and forbids changes to package availability, accounts, credentials, rankings, or incident response.","source_ids":["SRC1","SRC2"]},"no_obvious_safety_or_authority_stop":{"status":"PASS","rationale":"The first step requires governing-body approval, preserves existing production authority, uses redacted historical and synthetic material, permits withdrawal, and has confidentiality and misunderstanding stop conditions. No obvious authority or safety stop remains for that diagnostic, provided approved data handling and incident separation are enforced.","source_ids":["SRC1","SRC2"]}},"screen_survival":true,"world_novelty_boundary":"This bounded public-web screen supports only an adjacent-prior-art disposition and a researchable contrastive claim. It cannot establish world novelty, patentability, freedom to operate, market size, expert acceptance, realized value, or the absence of unpublished, non-indexed, proprietary, foreign-language, or differently termed prior art."}