Harness Instrumentation-Coverage / Telemetry-Sufficiency Auditor

“A clean grade laundered by omission cannot certify a AgentSmack deploy.”

The harness grader EXCLUDES any optional dimension from its blend when the telemetry is absent — a documented design. But that exclusion is a laundering hole: a thin, cherry-picked, or deliberately-under-instrumented span trace that simply omits the risky spans dodges every detector and certifies a clean 100. A customer gaming their own audit (or a compromised harness emitting a minimal trace) can submit [agent.run.started, llm.call.completed, action.executed] and score production-ready while the real harness has ungraded tool calls, no policy gate, no egress telemetry, no redaction proof. Nothing grades whether the submitted span set is rich enough to TRUST a clean grade. This lab does. It is a pure, deterministic meta-lens over the SAME Phase-4 span list: a privileged action graded against zero policy.check.completed is clean-by-omission (forced insufficiently_instrumented, score clamped into the failing band, non-launderable); a sensitive origin with no egress.attempted sink, or a privileged tool with no approval telemetry, is under_instrumented; a run with no privileged effect at all is insufficient_signal, never a fabricated pass. Grading is by the parsed span PRESENCE, not the array index — re-ordering the spans cannot change the verdict. The report carries only span ids + closed enums + scalar counts (no raw span / attribute / secret bytes). Load a sample to watch the verdict swing with no live infra.

Grading the SAME spans for content failures or wall-clock physics? Run the Harness Telemetry Check and the Span-Timeline Temporal-Integrity lab and the Span-Lineage Graph-Integrity meta-lens.