Executive summary
Reconciled Hiro's extensive existing working state into a clean, recoverable baseline commit and added local annotated pins for both the pre-observation baseline and the completed observation implementation.
Implemented a disabled-by-default, exact-host, HTTPS-only observation client that supports only GET and HEAD, pins connections to prevalidated public IP addresses, revalidates every redirect, and enforces cumulative request, time, byte, redirect, port, query, and content limits.
Implemented active-content removal, credential-shaped redaction, prompt-injection boundary handling, timestamped tamper-evident snapshot packets, mandatory human review before case creation, and paired baseline/candidate replay bound to the same frozen snapshot hash.
The focused offline safety suite passed 62 tests and the complete Hiro suite passed all 374 tests. The implementation remains inactive with an empty allowlist, disabled policy, local observation DISABLED sentinel, zero snapshots, no promotion authority, and Stage 6 still disabled.