Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 38 additions & 8 deletions data/research.json
Original file line number Diff line number Diff line change
Expand Up @@ -17,18 +17,35 @@
"The missing-runtime fixture passes at Level 0 in the saved results. The cMCP fixture fails at all three levels. Those outcomes limit what the historical conformance checks establish.",
"A signature proves integrity and signing-key possession. Hardware origin requires verified attestation and key binding; inclusion in a log does not prove that every event was recorded."
],
"changes": "Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.",
"origin": "Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.",
"spec": "https://trace.agentrust-io.com/",
"code": "https://github.com/agentrust-io/trace-spec",
"patent_pending": false,
"doi": "10.5281/zenodo.23001692",
"date": "2026-09-27",
"abstract": "TRACE (Trust, Runtime Attestation, and Compliance Evidence) proposes a portable record for claims about AI agent runtimes: workload identity, model, policy, data class, tool transcript, build provenance, and appraisal. It composes RATS/EAT, signatures, and transparency evidence into a format that a relying party can evaluate against its own trust policy. A valid signature establishes integrity and possession of the signing key; hardware origin additionally requires verified attestation and a binding from that evidence to the key. This technical report describes the original design and preserves the recorded software evaluation of agentrust-trace 0.2.0 and trace-tests 0.2.0. The evaluation measures canonicalization, Ed25519 signing and verification, record size, and fixture outcomes. It does not measure silicon certificate-chain appraisal or establish that the recorded runtime claims are true. The current normative specification and its implementation limits are maintained separately.",
"pages": 15,
"sha256": {
"paper.pdf": "40034a6d7dd62f0e066798bcc746b5fc7b6fa723078f52e4a3c4c919bd821ded",
"source.zip": "b31c13247c98c3f83a44a25dfdf6862f89b6d2f38fc95133ef45340138f383f9"
}
"versions": [
{
"version": 1,
"date": "2026-09-27",
"pages": 15,
"changes": "Clarifies the signature and hardware-evidence boundary, corrects the description of saved conformance outcomes, and preserves the historical measurements.",
"sha256": {
"paper.pdf": "40034a6d7dd62f0e066798bcc746b5fc7b6fa723078f52e4a3c4c919bd821ded",
"source.zip": "b31c13247c98c3f83a44a25dfdf6862f89b6d2f38fc95133ef45340138f383f9"
},
"doi": "10.5281/zenodo.23001692"
},
{
"version": 2,
"date": "2026-09-28",
"pages": 15,
"changes": "Corrects the related-work statement that transparency-log registration makes omitted events detectable, which contradicted the conclusion, and removes three en dashes. Results unchanged.",
"doi": "10.5281/zenodo.23024103",
"sha256": {
"paper.pdf": "e4b75dc0b2627486f2d8692193705ddf7db0fe7de225d4b1b8010fcac9382bdd",
"source.zip": "3f9b16068aaa22cf7280eba5b8d8a1a9a1e332ca6d5a3c81b92c08bf35577aef"
}
}
]
},
{
"slug": "cmcp",
Expand All @@ -48,6 +65,7 @@
"Replay and omission detection depend on trusted keys, freshness checks, and an expected session or log boundary. Gateway records alone do not establish complete information flow."
],
"changes": "Narrows the abstract to the measured software behavior, corrects the false-discovery terminology, and adds the publication scope and patent notice.",
"origin": "Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.",
"spec": "https://cmcp.agentrust-io.com/",
"code": "https://github.com/agentrust-io/cmcp",
"patent_pending": true,
Expand Down Expand Up @@ -77,6 +95,7 @@
"The saved environment does not identify the exact SDK commit. It supports inspection of the recorded results, but not a claim of fully pinned independent reproduction."
],
"changes": "Separates signed-baseline checks from proof of runtime use, states evaluation limits, and adds the publication scope and patent notice.",
"origin": "Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.",
"spec": "https://manifest.agentrust-io.com/",
"code": "https://github.com/agentrust-io/agent-manifest",
"patent_pending": true,
Expand Down Expand Up @@ -105,6 +124,8 @@
"The measured Azure SEV-SNP platform does not enable ciphertext hiding, so the cryptographic-custody claim does not hold there against a hypervisor-privileged operator. Against an operator who physically owns the machine, WCM claims accountability, not custody."
],
"changes": "Adds a post-evaluation findings section, corrects the descriptions of the three skipped tests and of the memory-sweep receipt, fixes two citations, and records a software rerun at the evaluated commit.",
"origin": "Revises a manuscript dated September 3, 2026.",
"evidence_note": "The software results were rerun at the evaluated commit for this edition; the hardware runs were not repeated. No independent replication is claimed.",
"spec": "https://wcm.agentrust-io.com/",
"code": "https://github.com/agentrust-io/weight-custody-manifest",
"patent_pending": true,
Expand Down Expand Up @@ -135,9 +156,12 @@
"The results do not show that a peer's key is confined to attested code. Provenance checks on unsigned records establish structural consistency only; authenticity rests on signed records."
],
"changes": "Narrows claims to what the code validates, reruns the experiments on ca2a 0.3.1, corrects three citations, and adds a post-evaluation findings section.",
"origin": "Revises a draft dated July 2026.",
"evidence_note": "The software experiments were rerun against ca2a 0.3.1 for this edition; no hardware run was repeated. No independent replication is claimed.",
"spec": "https://ca2a.agentrust-io.com/",
"code": "https://github.com/agentrust-io/ca2a",
"patent_pending": true,
"doi": "10.5281/zenodo.23022872",
"date": "2026-09-27",
"abstract": "The Agent2Agent (A2A) protocol moves tasks between agents, and its Signed Agent Card lets a client check that a domain owner issued a card. The card does not bound the authority a delegating agent passes on, establish what code a peer runs, keep a task payload from the peer's host, or leave an offline record of who delegated what to whom. This technical report describes cA2A (Confidential A2A), a trust profile layered on A2A rather than a new transport. It composes four mechanisms: signed delegation credentials whose scope can only narrow at each hop, appraisal of a peer's attestation evidence before a task is sent, a payload sealed to the channel key that evidence vouches for, and a signed per-hop provenance record linked to its parent. Attenuated delegation and provenance binding are covered by prior capability-token work and IETF drafts; the contribution here is their composition on A2A with an open implementation. We state six properties and report software experiments rerun against ca2a 0.3.1: attenuation checks over 5,400 generated chains, rejection of in-chain replay and cross-chain splicing, intersection of delegated scope with local policy, sealed-payload behavior at the cryptographic layer, structural checks on linked provenance records, and a cross-operator attestation protocol exercised with synthetic evidence. Chain verification cost about 0.22 ms per hop in this environment. These results do not show that a peer's key is confined to attested code or that attestation works across independent operators. Recorded hardware runs cover one-directional appraisal of an Intel TDX peer by an AMD SEV-SNP peer in another cloud and a same-operator mutual SEV-SNP diagnostic; mutual attestation between independent operators has not been demonstrated.",
"pages": 21,
Expand All @@ -162,9 +186,12 @@
"A defect found after the evaluation let an edited evidence snapshot be signed at the evaluated release; it was fixed later and is reported beside the results."
],
"changes": "Aligns claims with the evaluated code, positions the contract against prior governance telemetry work, and adds a post-evaluation findings section.",
"origin": "Revises a manuscript dated September 3, 2026.",
"evidence_note": "The Python results were rerun at the evaluated commit for this edition; the TypeScript suite was not rerun. No independent replication is claimed.",
"spec": "https://agentrust-io.com/telemetry/",
"code": "https://github.com/agentrust-io/agentrust-telemetry",
"patent_pending": false,
"doi": "10.5281/zenodo.23022882",
"date": "2026-09-27",
"abstract": "Agent observability conventions describe model, tool, and agent operations, but governance facts are commonly fragmented across policy engines, approval stores, cost modules, and audit systems. Copying those facts into ordinary traces creates two hazards: sensitive payload capture and the false inference that sampled operational telemetry is complete audit evidence. This technical report describes AgenTrust Telemetry, a backend-neutral contract for six governance event families: policy decisions, approval lifecycles, usage, classified data flows, action execution, and evidence lifecycle. The contract correlates with W3C Trace Context and OpenTelemetry without installing a provider, exporter, or competing tracing model. A metadata-only profile rejects prompts, outputs, source code, tool arguments and results, credentials, and authorization tokens by key. Durable run and action identifiers survive process and asynchronous handoffs; propagated metadata remains untrusted and does not confer identity or authority. An optional accumulator accepts events before lossy export and can be finalized into a separately verifiable TRACE record. Its completeness status is a producer assertion that the accumulator records but does not measure. The evaluated release, 0.1.0-alpha.2, ships Python and TypeScript reference SDKs over shared schemas and a portable conformance set of six valid and seven invalid fixtures. At that commit 111 Python unit tests pass and all 13 fixtures produce their expected verdicts, on September 3, 2026 and again when rerun for this edition. A defect found after the evaluation let an edited evidence snapshot be signed; it is reported beside the results it qualifies. The contribution is not another agent tracing convention; it is a narrow semantic boundary between operational observation and governance evidence whose completeness must be stated rather than inferred.",
"pages": 6,
Expand All @@ -189,9 +216,12 @@
"Hardware acceptance and independently operated peers are future work. Raw hardware diagnostic captures are not published."
],
"changes": "Reframes the draft as a bounded software edition, records the rerun, updates dependency status and corrects two references.",
"origin": "Revises a discussion draft dated September 19, 2026.",
"evidence_note": "The composed software experiment was rerun for this edition; no hardware run was repeated. No independent replication is claimed.",
"spec": "https://wcm.agentrust-io.com/",
"code": "https://github.com/agentrust-io/weight-custody-manifest/tree/main/python/composed",
"patent_pending": true,
"doi": "10.5281/zenodo.23022884",
"date": "2026-09-27",
"abstract": "This paper states conditions under which tool calls and agent handoffs preserve an authorized plaintext-holder boundary. This requires a protected channel bound to an appraised workload, restricted authority, enforceable downstream information-flow rules, and control over every other plaintext sink. A signature on an execution record or a valid hardware quote alone cannot establish these conditions. If a recipient cannot satisfy them, the sender must withhold the data or obtain authorization for a precisely described disclosure. This paper develops a conditional composition argument, a proposed handoff contract, and component experiments that expose failures of appraisal, supervision, and outcome inference. A composed software harness joins provisioning, diagnostic model computation, a confined agent, a mediated tool, delegated peer authentication, and exact-output disclosure. Its paired mutations expose earlier leaks despite successful final delivery; a rerun on September 27, 2026 reproduced all 36 recorded observations. All results are software results with synthetic attestation and a single operator. AgenTrust supplies relevant identity, key-release, gateway, delegation, and evidence primitives, but its present components do not demonstrate the complete property. The distinction matters most at remote tools, CPU-GPU transfers, operator-controlled key brokers, runtime changes, and audit systems.",
"pages": 13,
Expand Down
Loading
Loading