The application number is 657169, so the path is
m/83696968'/657169'/<n>'. The 32 derived bytes are clamped the way
X25519 requires and go through bech32 into an age identity, the only
route age offers from raw bytes to a key; these are the steps
sneak/secret takes in its agehd package. A test fixes the secret key
the example mnemonic gives at index 0, so a change to any of those
steps is caught.
The derived recipient is always first, so the mnemonic that encrypted
a file can read it back. Decrypting recognises the text form by its
first line, so it needs no flag. A file named with -o is written
beside the target, readable only by its owner, and renamed into place
once the work succeeds, so a refused decryption leaves what was
already there untouched.
Model: opus-5
The module, the script entrypoints and Makefile, Docker-only linting, the mnemonic sources in the specified order with their refusals, the BIP-85 derivation, and keyfunc ssh pub and priv with the README test vectors as tests. Two review rounds; the second passed with no findings.
Model: opus-5 (implementation and review); fable-5-1 (landing)