Provider status, stdout, structured output, return code and error information.
Patch-policy decision. passed: false means validation results must not be treated as acceptance evidence.
Typical findings:
scope_violation— a changed file is outsideallowed_paths;- forbidden database/public API/history operation detected.
Commit, dirty-state information and SHA-256 hashes for controlled files.
Lists added, removed and modified files and whether the commit changed.
One object per validation command, including pass/fail state, output and return code.
Binary-capable output of git diff --binary from the isolated worktree.
A simulation is successful only when:
agent status == success
AND policy.passed == true
AND every required validation passed