The chain proves which piece. The operator publishes the hash of a secret before any pull, the contract refuses a secret whose hash is not that commitment, and it computes the piece from that secret, the 32 bytes your own browser drew, and the pull id, over the pieces still unclaimed. So for a seed that is yours, and that this page never reuses, nobody can NAME the piece your catch will yield, and nobody can choose it after the fact. Naming it and moving it are not the same thing: the piece is that hash modulo the pieces still in the machine, and every pull resolved in front of yours reshuffles what is left, so which piece you get can still be changed by how and when those pulls are resolved. Yours is fixed once every pull older than it is resolved. That condition is not decoration: whoever holds the chain knows the link your pull id will be fulfilled with, so anybody who took a seed from somebody else would be playing with a number that could have been ground against that link until it named a piece.
The server judges the grab, and you are trusting it. Whether the jaws closed on anything is computed by the arcade server from the intents you sent, exactly as the arena computes its collisions. The chain does not simulate the claw and this page will not pretend it does. A compromised server can grant a catch and it can deny one, and because it holds the link before it decides it can work out what each waiting pull would yield and report only the catches it likes: piece by piece that is a veto, and across a run it is a selection. What limits it is that a miss reveals its link too, so anyone holding the log can recompute the piece a denied catch would have produced and a pattern of denials is a public fact rather than a suspicion. That is the whole of the mitigation and this page will not write it up as anything stronger.
What stays trusted, said rather than buried: the operator sees your seed before it reveals, and could stall a pull it dislikes. Stalling blocks every player rather than one, is publicly visible, and a pull left unfulfilled past 300 EVM blocks is refundable by anyone at all. The chain's 250 ms EVM block interval is a scheduling target, so that delay is about seventy-five seconds rather than a promise. Past it the stall becomes a choice: refunding the pull at the head resolves it without spending its link, so that link can be passed to whoever is next. The skipped player loses only the wait, since the stake and the attempt both come back, and one public refund names them. Before the deadline pulls are fulfilled oldest first, and when the contract's own cursor falls behind, advance(steps) moves it and is open to anybody too.
How many attempts an address gets is read off the contract and is not known here yet. So one person with enough addresses can take the whole collection, and nothing in the contract can stop that on a public testnet. How many addresses that takes is this page's own arithmetic and it has not been told the numbers yet. Everyone gets a fair shot at the collection is not, and this page will not say it.
How it is decided sets out the same boundary at length, beside the arena's. Test PKL has no monetary value.