Problem / motivation
A cleaned result must be verified before any bytes are saved, with honest bounded claims.
Scope
Run verifyMetadata immediately after cleaning, model actual checks/diagnostics, and fail closed before writes for invalid, truncated, incomplete, or unsafe output.
Non-goals
No claims of complete privacy, exhaustive metadata removal, provenance, pixel privacy, steganography detection, malware safety, or anonymity.
Acceptance criteria
- State transition is clean → verify → success → save.
- Only an actual v0.1.0 valid result can be written/downloaded.
- Failure leaves the inspected source intact and writes no output.
- Success copy states only that targeted supported categories were checked.
Problem / motivation
A cleaned result must be verified before any bytes are saved, with honest bounded claims.
Scope
Run verifyMetadata immediately after cleaning, model actual checks/diagnostics, and fail closed before writes for invalid, truncated, incomplete, or unsafe output.
Non-goals
No claims of complete privacy, exhaustive metadata removal, provenance, pixel privacy, steganography detection, malware safety, or anonymity.
Acceptance criteria