Pluribus is an evidence layer for agent context boundaries. The strongest support for that direction is not another document in this repository; it is a falsifiable boundary that an independent maintainer ships or protects in tests.
Evidence, not an adoption claim.
This ledger separates maintainer-shipped outcomes, independently reviewed contributions, and directory distribution. They prove that specific boundary checks affected inspectable external systems. They do not prove Pluribus installs, active users, or runtime consumption.
Maintainer-shipped from a falsifier
MCP trace privacy · shipped and protected 2026-07-12
Local storage ≠ agent-visible replay
A synthetic canary showed that Observer returned raw historical tool arguments to the agent and created a world-readable database. The maintainer shipped metadata-only, session-scoped defaults, raw opt-in, pre-store redaction, and 0600 storage; then requested and merged the hermetic regression suite.
A failover test asked whether backup agent B inspects work left by quota-limited agent A. Usher's maintainer turned that first external feedback into a default continuation guard, machine-readable marker, opt-out, end-to-end test, and tagged release in 37 minutes. The remaining boundary is explicit: warning delivered does not prove workspace inspected.
agent-context-economy accepted metadata that makes a generated repository map's staleness inspectable instead of treating existence as current authority.
promptblock accepted hidden-comment indexes in warnings, making invisible instruction locations reviewable instead of reporting only a generic finding.
gaia-skill-tree accepted the privacy-safe evidence-attestation recipe into its named registry. After an unrelated staging branch contaminated the first attribution patch, the maintainer recreated it as a one-commit, one-file change with all checks green. This proves independent curation and accurate contribution provenance—not installs or runtime use.
The browser demo shows the narrowest useful Pluribus workflow: one reviewed source, native agent-file previews, and hashes for what was generated. The receipt remains honest that generation does not prove a client loaded the output.