pask-wire-cli 0.1.0

Command-line conformance tool: produce, verify, and emit canonical Pask receipts
# pask-wire-cli

Apache-2.0 command-line producer and supplied-key verifier for Pask statements.
The executable is `pask-wire-cli`. It supports implemented processing for
`wilder.pser/0.5` and `wilder.pser/0.6`, not complete profile certification.

## Current source evaluation

From a checkout of the reviewed source, with Rust stable (declared minimum 1.88):

```sh
cargo run --locked -p pask-wire-cli -- --help
cargo run --locked -p pask-wire-cli -- canonical-example
cargo install --locked --path crates/pask-wire-cli --root ./local-install
./local-install/bin/pask-wire-cli --help
```

Registry installation is prospective, only after an authorized publication:

```sh
cargo install pask-wire-cli --version 0.1.0 --locked
```

## Commands and formats

```text
pask-wire-cli canonical-example
pask-wire-cli produce --input payload.json --private-key private.pem --output statement.cbor
pask-wire-cli verify --input statement.cbor --public-key public.pem --output payload.json
```

The private key is an Ed25519 PKCS#8 PEM (`PRIVATE KEY`). The public key is
Ed25519 SubjectPublicKeyInfo PEM (`PUBLIC KEY`), not an SSH public-key line.
`verify` writes canonical verified payload JSON to stdout or `--output`.
It does not output the full recipient coordinator report, automatically verify
attached SCITT Receipts, or establish a presented chain's contiguity.

`canonical-example` deliberately emits the legacy 0.5 example. The posted
-04/0.6 figure is generated by `pask_wire::canonical_example_06()` and guarded
by a separate workspace document test. No profile-selection option is provided.

## Verification boundary

Success checks the statement signature under the caller-supplied Ed25519 key
and the implemented payload checks. It does not authenticate the named
organization or actor, establish physical truth, key hardware custody, or
Transparency Service independence. The library's layered Receipt-validation
APIs are separate from this CLI path. Legacy outer-subject typing and other
known conformance limits remain disclosed in the repository's
[KNOWN-LIMITATIONS](https://github.com/wilder-robotics/pask-workspace/blob/main/KNOWN-LIMITATIONS.md).

Crate semver, supported profile identifiers and draft revision are separate.
The [posted -04 draft](https://datatracker.ietf.org/doc/draft-wilder-scitt-physical-site-engage-receipt/04/)
is an Internet-Draft, not an IETF standard or endorsement.

## License

Apache-2.0. The separate `pask-adapt` operational binary remains AGPL-3.0-only.