Reference Demo: Structural Plugin v0.3.0
Rules Profile: SP-ARCH-1-D02
Audit Profile: SP-AUDIT-1-D02
Receipt Profile: SP-RECEIPT-2-D01
Verification Bundle Profile: SP-VERIFICATION-BUNDLE-1-D01
Frozen Vector Profile: SP-VECTORS-1-D01
Structural Plugin is a deterministic reference architecture for separating:
capability != visibility != task authority != security authorization != execution
The current reference uses two structural boundaries:
Boundary 1 -> capability surface
Boundary 2 -> action authority envelope
The main processing path is:
task declaration -> capability surface -> action proposal -> canonical action -> resolve context -> authority decision -> revalidation -> execute or withhold -> execution observation -> receipt -> verification bundle
Open:
demo/Structural_Plugin_Reference_Demo_v0_3_0.html
in a current desktop browser.
Then:
- Confirm the task says:
Read this email and prepare a polite reply. Do not send it. - Confirm the task capability surface shows
3 VISIBLE / 10 TOTAL. - Select Run Safe Task.
- Confirm
Drafts = 1andDRAFT v2 · NOT SENT. - Select Simulate Hidden Send Proposal.
- Confirm
SEND_EMAIL -> REFUSEDandExecution = NOT_DISPATCHED. - Select Demonstrate State Drift.
- Confirm the final
EDIT_DRAFTentry recordsADMITTED -> STALE -> STALE. - Open the browser console and run:
await SP_AUDIT.runAll()Expected current result:
87/87 PASS
Architecture overview:
docs/Structural-Plugin-Architecture-Diagram.png
Browser reference:
- current desktop browser;
- JavaScript enabled;
- local file access sufficient to open the HTML file;
- no server required;
- no database required;
- no external AI model required;
- no network connection required for ordinary local reference use.
Separate verifier:
- Python 3.9 or newer;
- no third-party Python package required.
A browser may display a local file: unique-origin warning when the HTML file is opened directly from disk.
That warning does not by itself indicate a Structural Plugin audit or verification failure.
Structural-Plugin/
├── LICENSE
├── README.md
│
├── demo/
│ └── Structural_Plugin_Reference_Demo_v0_3_0.html
│
├── docs/
│ ├── FAQ.md
│ ├── Quickstart.md
│ ├── REFERENCE_RESULTS.txt
│ ├── Structural-Plugin-Architecture-Diagram.png
│ ├── Structural_Plugin_Architecture_At_A_Glance_v1_0.md
│ ├── Structural_Plugin_v0_3_0_Console_Audit_Commands.txt
│ ├── VERIFY.md
│ └── specs/
│ ├── Structural_Plugin_Audit_and_Assurance_v0_3_0.txt
│ ├── Structural_Plugin_Conformance_v0_3_0.txt
│ └── Structural_Plugin_Core_Architecture_v0_3_0.txt
│
├── hashes/
│ └── SHA256SUMS.txt
│
├── schema/
│ ├── Structural_Plugin_Canonical_Action_Schema_v1_0.json
│ ├── Structural_Plugin_Frozen_Vector_Set_Schema_v1_0.json
│ ├── Structural_Plugin_Receipt_Schema_v2_0.json
│ ├── Structural_Plugin_Verification_Bundle_Schema_v1_0.json
│ └── Structural_Plugin_Verification_Entry_Schema_v1_0.json
│
├── vectors/
│ └── Structural_Plugin_Frozen_Test_Vectors_v0_3_0.json
│
└── verifier/
└── Structural_Plugin_Independent_Verifier_v0_3_0.py
The current reference task should show:
READ_THREAD = VISIBLE
CREATE_DRAFT = VISIBLE
EDIT_DRAFT = VISIBLE
SEND_EMAIL = DEFERRED
ADD_RECIPIENT = FORBIDDEN
FORWARD_ATTACHMENT = FORBIDDEN
DOWNLOAD_ATTACHMENT = DORMANT
UPLOAD_LOCAL_FILE = FORBIDDEN
DELETE_MESSAGE = FORBIDDEN
CHANGE_ACCOUNT_SETTINGS = DORMANT
This demonstrates:
capability existence != task visibility
Select:
Run Safe Task
Expected logical sequence:
READ_THREAD -> ADMITTED -> PASS -> OBSERVED_COMPLETED
CREATE_DRAFT -> ADMITTED -> PASS -> OBSERVED_COMPLETED
EDIT_DRAFT -> ADMITTED -> PASS -> OBSERVED_COMPLETED
Expected visible outcome:
Drafts = 1
DRAFT v2 · NOT SENT
3. Test a Hidden Send Proposal
Select:
Simulate Hidden Send Proposal
Expected:
SEND_EMAIL -> REFUSED
Reason = ACTION_EXPLICITLY_PROHIBITED
Execution = NOT_DISPATCHED
Expected authority delta:
DATA_EGRESS
SEND_COMMITMENT
This demonstrates:
hidden or out-of-surface proposal != execution authority
Use the unrestricted proposal controls.
Expected reference outcomes:
FORWARD_ATTACHMENT -> REFUSED
ADD_RECIPIENT -> REFUSED
DELETE_MESSAGE -> REFUSED
UPLOAD_LOCAL_FILE -> REFUSED
CHANGE_ACCOUNT_SETTINGS -> UNSUPPORTED
Select:
Demonstrate State Drift
Expected final action evidence:
action = EDIT_DRAFT
admission_state = ADMITTED
revalidation_state = STALE
observed_execution_state = STALE
This demonstrates:
admission at preview time != permanent execution authority
Run:
await SP_AUDIT.runAll()Current expected result:
87/87 PASS
Verify frozen vectors:
SP.verifyVectors()Expected:
14/14 PASS
Verify the current evidence bundle:
SP.verifyBundle(SP.verificationBundle())Expected for an untampered supported bundle:
status = PASS
Verify the frozen vectors:
python verifier/Structural_Plugin_Independent_Verifier_v0_3_0.py --vectors vectors/Structural_Plugin_Frozen_Test_Vectors_v0_3_0.json
Expected:
Verification Result: PASS
Vectors: 14/14 PASS
Export a browser verification bundle and run:
python verifier/Structural_Plugin_Independent_Verifier_v0_3_0.py --bundle Structural_Plugin_Verification_Bundle_v0_3_0.json
Expected for an untampered supported bundle:
Verification Result: PASS
Safe task bundle:
bundle_77732628ebaa7306b94e4b33
Result:
browser verification PASS
separate Python verification PASS
State-drift bundle:
bundle_57ad3c8ce0d12859488c85ef
Result:
browser verification PASS
separate Python verification PASS
Deliberately modified safe bundle:
Verification Result: FAIL
Confirmed failure classes:
BUNDLE_ROOT_MISMATCH
ENTRY_2_ENTRY_IDENTITY_MISMATCH
ENTRY_2_DECISION_RECONSTRUCTION_MISMATCH
ENTRY_2_REVALIDATION_STATE_MISMATCH
ENTRY_2_REVALIDATION_REASON_MISMATCH
The checksum manifest is:
hashes/SHA256SUMS.txt
It intentionally contains only the three verification-critical artifacts:
demo/Structural_Plugin_Reference_Demo_v0_3_0.html
verifier/Structural_Plugin_Independent_Verifier_v0_3_0.py
vectors/Structural_Plugin_Frozen_Test_Vectors_v0_3_0.json
Generate the final three SHA-256 values only after these files are frozen.
Documentation and schema changes do not require the checksum manifest to change unless one of these three verification-critical artifacts also changes.
README.mddocs/Quickstart.mddocs/Structural_Plugin_Architecture_At_A_Glance_v1_0.mddocs/specs/Structural_Plugin_Core_Architecture_v0_3_0.txtdocs/specs/Structural_Plugin_Conformance_v0_3_0.txtdocs/specs/Structural_Plugin_Audit_and_Assurance_v0_3_0.txtdocs/FAQ.mddocs/VERIFY.mddocs/REFERENCE_RESULTS.txtdocs/Structural_Plugin_v0_3_0_Console_Audit_Commands.txt
The reference demonstrates:
capability existence without automatic visibility
visibility without unrestricted action authority
admission without permanent execution authority
valid refusal and stale outcomes as verifiable evidence
tampered evidence as verification failure
The central rule remains:
capability != visibility != task authority != security authorization != execution