Provenance tag identifying which agent and run produced this report —
NOT a cryptographic signature. It is a plain identity:<agentId>:<ts>
string with no key involved and nothing to verify against, so it cannot
establish authenticity. Use src/crypto/signing for real signing.
Provenance tag identifying which agent and run produced this report — NOT a cryptographic signature. It is a plain
identity:<agentId>:<ts>string with no key involved and nothing to verify against, so it cannot establish authenticity. Use src/crypto/signing for real signing.