# Evidence: single-react-mysql-readonly-tool ## Static verification - `git diff --check`: passed before archive. - Security scan confirms the query helper has no default external host/port/root user and no `commit()` write path. - New MySQL Harness code receives only injected logical DataSources and does not reference `spring.datasource` or the application persistence datasource. - OpenSpec strict validation passed for `single-react-mysql-readonly-tool`. ## Script/build verification - `mvn -q -DskipTests compile`: passed. - Focused suite passed: `MysqlSqlValidatorTest`, `MysqlResultProjectorTest`, `JdbcMysqlReadOnlyExecutorTest`, `MysqlToolAdapterTest`, `MysqlToolContractTest`, `ToolBoundaryTest`, `CanonicalInvocationStoreTest`. - Python syntax compilation passed for `scripts/query_mysql.py`. - Missing connection environment variables exit before connection with code 2. - A write SQL invocation is rejected before connection with code 3. ## Security coverage - Allowed: explicit allowlisted SELECT, parameter placeholders, qualified INNER JOIN and `COUNT(*)`. - Rejected: write, WITH, subquery, UNION, wildcard projection, unknown table/column, ambiguous column, dangerous function, inline literal, CASE, FOR UPDATE, multi-statement and placeholder mismatch. - JDBC controls verified: `setReadOnly(true)`, `PreparedStatement`, `setQueryTimeout`, `setMaxRows`, ordered parameter binding and cancellation-before-execution. - Projection controls verified: max rows, max cell chars, total UTF-8 bytes, sensitive-column redaction, valid bounded JSON and `NO_EVIDENCE`. ## Not verified in this stage - No live production business datasource was provisioned or queried; ISS-014 explicitly assigns live E2E to a later issue/stage. - No public Diagnosis Agent/Chat integration was performed; stage 4 will consume the adapter internally. - JDBC driver timeout/cancel behavior against a real remote MySQL server remains an operational integration risk.