Feels appropriate for bugs in a formal proof system:

> Beware of bugs in the above code; I have only proved it correct, not tried it.

-Knuth, 1977