The adversarial test is public and runnable in 5 minutes:
git clone https://github.com/Lama999901/metagenesis-core-public
python demos/open_data_demo_01/run_demo.py
If output isn't PASS/PASS on your machine, I want to know.
If the protocol design is flawed, I want to know where specifically.Known limitations are machine-readable: reports/known_faults.yaml
A more sophisticated attacker could plausibly extract key material from the TPM itself via sidechannels, and sign their own attestations.