T09 verification-only package

Pin t09-trust-pin.json before receiving a proof. The public authority hash is
6ce61325a56a34942285f80cfee27c175a0715d7d3b04621c927fb3e5f9763f0.

Run: python t09-verify-signature.py PRIVATE-proof.json --trusted-pin t09-trust-pin.json
Dependency: cryptography (not bundled).

This verifies the Ed25519 signing authority, integrity, commitment/evidence
bindings and bounded scope. It does NOT re-execute the private frozen Judge,
execute a candidate, certify a physical sandbox, or establish independent
third-party reproduction. The public API additionally recomputes the frozen
Judge and transport checks. A private proof contains the caller's own holdout
labels; keep that proof private. This ZIP contains no proof, holdout, candidate
implementation, signing key, Resident memory or arbitrary shell hook.
