Check the seal.

Paste a provenance manifest. We recompute its canonical SHA-256 and every declared output hash — nothing needs to be trusted, only checked.