Submit any attack intent. NEXUS blocks it at the governance boundary — not because another model says it looks dangerous, but because the capability doesn't exist.
AI can propose. AI can attack. AI cannot authorize itself. And NEXUS can prove it.
Escalated sessions can be verified against their persisted incident data and a Merkle root retrieved from the public GitHub anchor repository. The client never supplies the trusted root.
Anchors are retrieved from
github.com/dixsystem/nexus-agentic-proof-anchor.
Verification returns MATCH, TAMPER_DETECTED, or NOT_FOUND. It fails closed when persistence or the external anchor is unavailable.
gemini_fell and nexus_blocked are computed independently. Gemini can construct the attack — and often does. NEXUS blocks it anyway, because the block comes from the capability registry, not from Gemini's self-assessment.
We don't make the AI trustworthy. We make trust unnecessary for authority.