First-principles proof recipes for this dotfiles repo -- prove a symlink chain, a plugin install, a git identity resolution, an SSH key selection, a hook firing, a settings merge, a cloud snapshot, or worktree hydration, instead of trusting an exit code or an install log. Load when asked "prove it", "is it actually installed/linked/registered", "which identity/key does this repo use", "did the hook fire", "did the snapshot carry", or before claiming any install/link/config step succeeded. For interpreting a FAILED proof use dotfiles-debugging-playbook; for the packaged doctors and test runner use dotfiles-diagnostics-and-tooling.