Problem / motivation
Cleaning must be verified fail-closed before a result can be saved.
Scope
Run verifyMetadata immediately after cleaning, use its actual v0.1.0 success semantics, block unsafe/incomplete results, and present bounded removed/preserved/repaired and verification evidence.
Non-goals
No truthy-object shortcut, save-before-verify flow, anonymity claim, exhaustive metadata claim, malware or pixel-privacy claim.
Acceptance criteria
- Only a documented successful verification state enables writing/downloading output.
- Invalid, truncated, incomplete, fail-closed, unsafe, or thrown verification states do not save.
- Verification copy states that targeted categories were checked under supported semantics.
- Tests cover success and blocking verification paths.
Problem / motivation
Cleaning must be verified fail-closed before a result can be saved.
Scope
Run verifyMetadata immediately after cleaning, use its actual v0.1.0 success semantics, block unsafe/incomplete results, and present bounded removed/preserved/repaired and verification evidence.
Non-goals
No truthy-object shortcut, save-before-verify flow, anonymity claim, exhaustive metadata claim, malware or pixel-privacy claim.
Acceptance criteria