For agent-verification builders: we reproduced two public JSON comparison suites and a signed-root count control. In a dated 305-leaf CSOAI root, duplicating the last leaf left the Merkle root unchanged; verification rejected the 306-leaf presentation because the count was signed. We also link the correction that domain-separation prefixes alone do not remove this collision.
This tests byte encoding and count binding, not agent identity or protocol conformance. What profile fields should a verifier require before treating two records as the same claim?