Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md). Findings are hypotheses until reproduced on current main (WO-00).
Finding: DCP consumed a fetched passport's aggregate scores without checking tenant/domain/path binding or seal; a foreign, invalidly sealed passport yielded a signed Stage-4 authorization [R3].
Files: services/service-decision-control-plane/main.py, decision_meter.py.
Fix: resolve passports as immutable records; verify seal; bind tenant, action fingerprint, model version, horizon, validity window into the signed authorization payload.
Acceptance: tests: foreign-tenant passport, stale passport, altered-body passport, wrong-action passport → each refused with a distinct reason code. Authorization signature covers the binding fields.
Depends on: WO-00.