Buyer-mandate public delivery

The version is experiments/buyer-mandate-20260930/package.json. This experiment
packages that adapter and the minimum files it imports, including the
caller-supplied prepared-request contract. It does not add a signer, a wallet
ledger, a mandate kernel, or a paid page. A prepared-request match does not
execute a payment or recover a durable spend, and it is not the private buyer.

Reused, not rewritten:
- scripts/record-lab projectLocalRecords and the c29 projection it calls
- packages/route-lock decide
- packages/release-gate evaluateRelease
- agent-payment-integrity parseX402Challenge at the pinned public archive
- agent-payment-policy createIntent, createPlan, normalizeRequest, validateOutput
  at the pinned public archive
- @x402/core decodePaymentResponseHeader and decodePaymentRequiredHeader
- packages/route-lock resourceBindsTarget for the default full URL match
- the admitted buyer-mandate and commerce-studio contract text

The public archive is a candidate. hostedAcquisitionVerified stays false until
Root reads the bytes back from the public origin. A loopback copy is not that
readback. A decision envelope is not permission to spend.
