{
  "tool_id": "art-194-digest-manifest-builder",
  "kernel_id": "art-194-digest-manifest-builder",
  "display_name": "Digest Manifest Builder",
  "tool_version": "1.0.0",
  "mandate_type": "cryptographic_mandate",
  "purpose": "Binds N file digests into one canonical, hash-anchored manifest. manifest_sha256 is SHA-256 over the JCS-canonical sorted entries array. This builds flat manifests with no tree, which is a different job from verify_merkle_batch (cry-04, which verifies Merkle proofs); BrowserChain's log owns Merkle trees. Also serves the plain checksum-tool use case. Returns the manifest plus checks for duplicate names, duplicate digests, malformed hex, and path-like names that are flagged and basenamed. Feeds the conversion receipt builder. Zero network, zero PII.",
  "control_description": "Binds N file digests into one canonical, hash-anchored manifest. manifest_sha256 is SHA-256 over the JCS-canonical sorted entries array. This builds flat manifests with no tree, which is a different job from verify_merkle_batch (cry-04, which verifies Merkle proofs); BrowserChain's log owns Merkle trees. Also serves the plain checksum-tool use case. Returns the manifest plus checks for duplicate names, duplicate digests, malformed hex, and path-like names that are flagged and basenamed. Feeds the conversion receipt builder. Zero network, zero PII.",
  "declared_inputs": [],
  "declared_outputs": [
    "art-191-conversion-receipt-builder"
  ],
  "kernel_digest": "sha256:784e8fbbe151a2af772343ca7a7d86d69293ddf2fb54a58aeb41223f7c4394f4",
  "trust_label": "deferred -- deterministic source published, zkVM proof not yet generated",
  "data_vintage": "2026-07-10",
  "last_validated": "2026-07-10",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 34,
  "source_url": "https://ainumbers.co/chaingraph/art-194-digest-manifest-builder.html",
  "generated_at": "2026-07-25T20:02:55.601Z"
}
