{
  "schema": "cain42.evolution11.proof.v1",
  "title": "CAIN-42 EVOLUTION-11-PROOF -- Intent Integrity & Agent Communication Governance Fabric",
  "generated_at": "2026-09-28T23:09:03+00:00",
  "commit": "3106ea9e1626871a44d15b879d1a864ca6846e6e",
  "bundle_name": "e11-intent-governance-2026-09-28",
  "modules": {
    "e11_intent_governance": {
      "path": "cain45/l5/intent_governance.py",
      "sha256": "e313de56cddebf7ceb52a428b917b5b88d8ad59107ac59f828a5afcdfb429800"
    },
    "e11_action_intent_reuse": {
      "path": "cain45/l5/intent.py",
      "sha256": "603b74f5b3f00148dd1e6c1a7afabde4f301d4b45ba20fdd1cf910056564097a"
    },
    "e11_control_plane": {
      "path": "cain45/l5/__init__.py",
      "sha256": "64156f70c30ff27d6d150436f56ffbd8260f13caede908b4570d4281b96366c2"
    },
    "e11_cli": {
      "path": "scripts/cain45/cain_agent_cli.py",
      "sha256": "54928f453b739cc6f8388a42c6b969ba01351ef9543af1995dc91168774edac3"
    }
  },
  "tests": {
    "tests/test_cain42_e11_intent.py": "d7ed08629110c9748e3aedadb097fb001484c6229884fa922c6e1d637ded9780",
    "tests/test_cain42_e11_adversarial.py": "696cf66ce560cf67c246f09a478c7c2c5276ced4b5f7569ea40b41af47ceecdb",
    "tests/test_cain42_e11_end_to_end.py": "55fde48a7b2ca57312b4c8fcea6f3bfc1baed9ecd696d1d77435cfba7d0e3de4"
  },
  "test_run": {
    "command": "python3 -m pytest tests/test_cain42_e11_intent.py tests/test_cain42_e11_adversarial.py tests/test_cain42_e11_end_to_end.py -q",
    "summary": "============================== 36 passed in 0.67s ==============================",
    "passed": 36,
    "failed": 0,
    "returncode": 0,
    "transcript_tail": [
      "============================= test session starts ==============================",
      "collected 36 items",
      "",
      "tests/test_cain42_e11_intent.py ............................             [ 77%]",
      "tests/test_cain42_e11_adversarial.py ......                              [ 94%]",
      "tests/test_cain42_e11_end_to_end.py ..                                   [100%]",
      "",
      "============================== 36 passed in 0.67s =============================="
    ]
  },
  "invariants": {
    "evolution": 11,
    "fabric": "cain42.l5.intent_governance",
    "checks": [
      {
        "id": "I1",
        "invariant": "MESSAGE INTEGRITY IS CRYPTOGRAPHICALLY VERIFIABLE",
        "holds": true,
        "detail": "message signature verifies"
      },
      {
        "id": "I2",
        "invariant": "MESSAGE PROVENANCE IS PRESERVED",
        "holds": true,
        "detail": {
          "schema": "cain42.e11.message-provenance.v1",
          "origin": "external",
          "sender": "agent:A",
          "source_kind": "EXTERNAL",
          "intermediaries": [
            "agent:B"
          ],
          "transformations": [
            "summarize"
          ],
          "tool_source": "",
          "mcp_source": "",
          "external_source": "",
          "memory_source": "",
          "human_source": "",
          "model_source": "",
          "timestamp": 1.0,
          "integrity_status": "UNKNOWN",
          "authority": "NONE"
        }
      },
      {
        "id": "I3",
        "invariant": "INFORMATION DOES NOT AUTOMATICALLY CREATE AUTHORITY",
        "holds": true,
        "detail": {
          "schema": "cain42.e11.tool-output-evidence.v1",
          "output_digest": "e49ffd992ed7303ed0dea06ae1a0d9299024a8240663cf60a15ecf28a3c4da27",
          "elements": {
            "FACT": false,
            "CLAIM": false,
            "INSTRUCTION": true,
            "EXECUTABLE": false,
            "POLICY_LOOKING": true,
            "AUTHORIZATION_LOOKING": false
          },
          "treated_as": "DATA",
          "promotes_to_policy": false,
          "promotes_to_authority": false,
          "known_injection": true,
          "authority": "NONE"
        }
      },
      {
        "id": "I4",
        "invariant": "TOOL OUTPUT CANNOT MODIFY POLICY AUTOMATICALLY",
        "holds": true,
        "detail": {
          "schema": "cain42.e11.tool-output-evidence.v1",
          "output_digest": "2bd4fbbed34ee1ef390438079c9d1390575ad14a6782f78262a817b70248e24e",
          "elements": {
            "FACT": false,
            "CLAIM": false,
            "INSTRUCTION": false,
            "EXECUTABLE": false,
            "POLICY_LOOKING": true,
            "AUTHORIZATION_LOOKING": false
          },
          "treated_as": "DATA",
          "promotes_to_policy": false,
          "promotes_to_authority": false,
          "known_injection": false,
          "authority": "NONE"
        }
      },
      {
        "id": "I5",
        "invariant": "MEMORY CANNOT CREATE AUTHORITY",
        "holds": true,
        "detail": "AUTHORITY_CLAIM_UNTRUSTED"
      },
      {
        "id": "I6",
        "invariant": "DELEGATION REQUIRES INDEPENDENTLY VERIFIABLE AUTHORITY",
        "holds": true,
        "detail": "unsigned delegation refused"
      },
      {
        "id": "I7",
        "invariant": "MATERIAL INTENT MUTATION INVALIDATES AUTHORIZATION",
        "holds": true,
        "detail": "material mutation changes the intent digest"
      },
      {
        "id": "I8",
        "invariant": "LOWER-TRUST CONTENT CANNOT SILENTLY OVERRIDE HIGHER-TRUST GOVERNANCE",
        "holds": true,
        "detail": {
          "override": false,
          "reason": "LOW_TRUST_CANNOT_OVERRIDE_HIGH_TRUST",
          "acting": "top",
          "authority": "NONE"
        }
      },
      {
        "id": "I9",
        "invariant": "CONSENSUS DOES NOT EQUAL AUTHORIZATION",
        "holds": true,
        "detail": "CONSENSUS_REACHED"
      },
      {
        "id": "I10",
        "invariant": "TAINT PROPAGATES THROUGH DERIVED INTENT",
        "holds": true,
        "detail": {
          "flags": [
            "untrusted_external_content"
          ],
          "tainted": true,
          "sensitivity": "MEDIUM",
          "requires_additional_governance": true,
          "authority": "NONE",
          "note": "taint is provenance risk, not proof of malicious intent"
        }
      },
      {
        "id": "I11",
        "invariant": "UNKNOWN PROVENANCE REMAINS UNKNOWN",
        "holds": true,
        "detail": {
          "boundary": "agent-boundary",
          "source_class": "UNKNOWN",
          "dest_trust": "TRUSTED",
          "effective_class": "UNKNOWN",
          "upgraded": false,
          "permitted": true,
          "reasons": [],
          "authority": "NONE"
        }
      },
      {
        "id": "I12",
        "invariant": "REPLAY PROTECTION IS MANDATORY FOR GOVERNED MESSAGES",
        "holds": true,
        "detail": [
          "MESSAGE_NO_NONCE"
        ]
      },
      {
        "id": "I13",
        "invariant": "CONFUSED-DEPUTY EXECUTION IS REJECTED",
        "holds": true,
        "detail": [
          "INTENT_TO_ACTION_MISMATCH",
          "REQUESTER_AUTHORITY_NOT_VERIFIED",
          "CONFUSED_DEPUTY_SUSPECTED"
        ]
      },
      {
        "id": "I14",
        "invariant": "CROSS-COLLECTIVE AUTHORITY IS NEVER IMPLICIT",
        "holds": true,
        "detail": {
          "source_collective": "A",
          "dest_collective": "B",
          "message_id": "msg_66aac70b09d5923ccde3",
          "accepted": true,
          "reasons": [],
          "inherited_authority": "NONE",
          "authority": "NONE"
        }
      },
      {
        "id": "I15",
        "invariant": "COLLECTIVE INTENT REMAINS ATTRIBUTABLE TO CONTRIBUTING AGENTS",
        "holds": true,
        "detail": [
          {
            "src": "msg_1",
            "relation": "DIRECT_SOURCE",
            "dst": "agent:A"
          }
        ]
      },
      {
        "id": "I16",
        "invariant": "INTENT DRIFT CAN INVALIDATE AUTHORITY",
        "holds": true,
        "detail": {
          "original_objective": "o1",
          "current_objective": "o2",
          "intermediate": [],
          "drift": 1.0,
          "within_envelope": false,
          "requires_reauthorization": true,
          "authority": "NONE"
        }
      },
      {
        "id": "I17",
        "invariant": "GOVERNANCE DECISIONS BIND TO CANONICAL INTENT",
        "holds": true,
        "detail": [
          "TARGET_MISMATCH"
        ]
      },
      {
        "id": "I18",
        "invariant": "EVIDENCE RECORDS THE CONTEXT USED FOR AUTHORIZATION",
        "holds": true,
        "detail": "1e4decd5babb102246a928ffbb64606b5895608e7fd0bd9a3a1735eaaa08a9ea"
      },
      {
        "id": "I19",
        "invariant": "QUARANTINED COMMUNICATION CANNOT SILENTLY BECOME TRUSTED INPUT",
        "holds": true,
        "detail": {
          "message_id": "msg_d4a5ec001134075d5b31",
          "action": "QUARANTINE",
          "preserved": true,
          "message_digest": "494aaaadf2d4c8cf9aa8f70bce5277f2351e9752a6de37504ae5efa341b28c6b",
          "authority": "NONE",
          "note": "security-relevant communication is preserved, never discarded"
        }
      },
      {
        "id": "I20",
        "invariant": "AN AGENT CANNOT AUTHORIZE ITSELF THROUGH COMMUNICATION WITH ANOTHER AGENT",
        "holds": true,
        "detail": {
          "verify": "PASS",
          "deputy": [
            "REQUESTER_AUTHORITY_NOT_VERIFIED",
            "CONFUSED_DEPUTY_SUSPECTED"
          ]
        }
      }
    ],
    "failed": [],
    "all_hold": true,
    "checked": 20
  },
  "attack_bench": {
    "bench": "CAIN-Agent-Intent-Bench",
    "attacks": {
      "direct_prompt_injection": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "schema": "cain42.e11.tool-output-evidence.v1",
          "output_digest": "d9d2fd52b85ec9fdf27909a0682847e380925153ee6c282e19e7bba2871009be",
          "elements": {
            "FACT": false,
            "CLAIM": false,
            "INSTRUCTION": true,
            "EXECUTABLE": false,
            "POLICY_LOOKING": false,
            "AUTHORIZATION_LOOKING": false
          },
          "treated_as": "DATA",
          "promotes_to_policy": false,
          "promotes_to_authority": false,
          "known_injection": true,
          "authority": "NONE"
        }
      },
      "indirect_prompt_injection": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "schema": "cain42.e11.tool-output-evidence.v1",
          "output_digest": "e6b7e2c63819426e1618ffd739a8b7446e956e2161a62659dc87a99f4269304d",
          "elements": {
            "FACT": false,
            "CLAIM": false,
            "INSTRUCTION": true,
            "EXECUTABLE": false,
            "POLICY_LOOKING": true,
            "AUTHORIZATION_LOOKING": true
          },
          "treated_as": "DATA",
          "promotes_to_policy": false,
          "promotes_to_authority": false,
          "known_injection": true,
          "authority": "NONE"
        }
      },
      "malicious_tool_output": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "schema": "cain42.e11.tool-output-evidence.v1",
          "output_digest": "d9d2fd52b85ec9fdf27909a0682847e380925153ee6c282e19e7bba2871009be",
          "elements": {
            "FACT": false,
            "CLAIM": false,
            "INSTRUCTION": true,
            "EXECUTABLE": false,
            "POLICY_LOOKING": false,
            "AUTHORIZATION_LOOKING": false
          },
          "treated_as": "DATA",
          "promotes_to_policy": false,
          "promotes_to_authority": false,
          "known_injection": true,
          "authority": "NONE"
        }
      },
      "malicious_mcp_output": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "schema": "cain42.e11.tool-output-evidence.v1",
          "output_digest": "cb6f0255631ae9f74dbec4f7d23af20eeb0227ae0f1c29ff1de7d1be46733a0f",
          "elements": {
            "FACT": false,
            "CLAIM": false,
            "INSTRUCTION": false,
            "EXECUTABLE": false,
            "POLICY_LOOKING": true,
            "AUTHORIZATION_LOOKING": false
          },
          "treated_as": "DATA",
          "promotes_to_policy": false,
          "promotes_to_authority": false,
          "known_injection": false,
          "authority": "NONE"
        }
      },
      "malicious_a2a_message": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": "a valid signature proves who sent it, never authority"
      },
      "forged_delegation": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": [
          "link 0: unsigned link"
        ]
      },
      "replayed_delegation": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": [
          "link 0: delegated authority expired"
        ]
      },
      "stale_intent": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "expiration": 10.0
        }
      },
      "intent_substitution": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "a": "f3a2497d071187ace2809dff52d0e35f9d049cb54711937307273e126d2011f9",
          "b": "cbf3ab980e79987eaf26065bc224151187e5c6288261ce9d09be4f4c28bd3964"
        }
      },
      "context_substitution": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "override": false,
          "reason": "LOW_TRUST_CANNOT_OVERRIDE_HIGH_TRUST",
          "acting": "top",
          "authority": "NONE"
        }
      },
      "memory_authority_laundering": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "claim": {
            "authority_source_event": "fabricated"
          },
          "memory_state": "VERIFIED",
          "authority": "NONE",
          "status": "AUTHORITY_CLAIM_UNTRUSTED",
          "reason": "named source event cannot be resolved"
        }
      },
      "confused_deputy": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "allowed": false,
          "reasons": [
            "REQUESTER_AUTHORITY_NOT_VERIFIED",
            "CONFUSED_DEPUTY_SUSPECTED"
          ],
          "binding": {
            "principal": "org:1",
            "acting_agent": "agent:B",
            "target": "acct",
            "capability": "PAY",
            "intent": "i1"
          },
          "authority": "NONE"
        }
      },
      "collective_manipulation": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "flags": [
            "untrusted_external_content"
          ],
          "tainted": true,
          "sensitivity": "MEDIUM",
          "requires_additional_governance": true,
          "authority": "NONE",
          "note": "taint is provenance risk, not proof of malicious intent"
        }
      },
      "cross_domain_trust_abuse": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "source_collective": "A",
          "dest_collective": "B",
          "message_id": "msg_eb568d6810d0d619eb23",
          "accepted": false,
          "reasons": [
            "TRUST_DOMAIN_NOT_ESTABLISHED",
            "CAPABILITY_UNVERIFIED",
            "DELEGATION_UNVERIFIED"
          ],
          "inherited_authority": "NONE",
          "authority": "NONE"
        }
      },
      "role_confusion": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": "role carries responsibility only"
      },
      "provenance_stripping": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": "lineage preserved by construction"
      },
      "taint_laundering": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "flags": [
            "stale_memory",
            "untrusted_external_content"
          ],
          "tainted": true,
          "sensitivity": "MEDIUM",
          "requires_additional_governance": true,
          "authority": "NONE",
          "note": "taint is provenance risk, not proof of malicious intent"
        }
      },
      "objective_drift": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "original_objective": "migrate customers",
          "current_objective": "exfiltrate payroll",
          "intermediate": [],
          "drift": 1.0,
          "within_envelope": false,
          "requires_reauthorization": true,
          "authority": "NONE"
        }
      },
      "consensus_laundering": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "mode": "QUORUM",
          "votes": {
            "a": "APPROVE",
            "b": "APPROVE",
            "c": "APPROVE"
          },
          "required": 3,
          "outcome": "CONSENSUS_REACHED",
          "authorized": false,
          "authority": "NONE",
          "note": "consensus is evidence for the governance step, never authorization by itself",
          "constraints_satisfied": true,
          "requires_governance_authorization": true
        }
      },
      "coordinated_communication_attack": {
        "blocked": true,
        "state": "BLOCKED",
        "evidence": {
          "schema": "cain42.e11.deception-evidence.v1",
          "state": "HIGH_RISK",
          "signals": {
            "fabricated_authority_refs": 3,
            "unexplained_capability_claims": 2,
            "repeated_policy_override_requests": 4,
            "unusual_delegation_chains": 1,
            "provenance_inconsistencies": 2,
            "contradictory_claims": 2
          },
          "authority": "NONE",
          "note": "evidence of suspicious communication, not a determination of conscious deception"
        }
      }
    },
    "blocked": 20,
    "total": 20,
    "all_blocked": true,
    "authority": "NONE",
    "note": "deterministic, machine-readable results; taint is a signal, not proof of malice"
  },
  "schemas": {
    "AgentMessage": {
      "fields": [
        "message_id",
        "sender_agent_id",
        "recipient_agent_id",
        "message_type",
        "content",
        "sender_passport_digest",
        "timestamp",
        "expiration",
        "provenance",
        "parent_message",
        "session",
        "collective",
        "delegation_context",
        "trust_context",
        "policy_context",
        "nonce",
        "source_kind",
        "signature_b64",
        "signer_public_key_b64",
        "verification_state"
      ],
      "canonical": true
    },
    "MessageProvenance": {
      "fields": [
        "origin",
        "sender",
        "source_kind",
        "intermediaries",
        "transformations",
        "tool_source",
        "mcp_source",
        "external_source",
        "memory_source",
        "human_source",
        "model_source",
        "timestamp",
        "integrity_status"
      ],
      "canonical": true
    },
    "AgentIntent": {
      "fields": [
        "intent_id",
        "originating_agent",
        "objective",
        "requested_action",
        "target",
        "resource",
        "purpose",
        "constraints",
        "expected_consequence",
        "evidence_references",
        "source_messages",
        "trajectory",
        "collective_context",
        "authority_context",
        "confidence",
        "uncertainty",
        "expiration",
        "taint",
        "interpretation",
        "authority"
      ],
      "canonical": true
    },
    "ContextElement": {
      "fields": [
        "element_id",
        "kind",
        "source",
        "trust_level",
        "provenance",
        "timestamp",
        "integrity_status",
        "content_digest",
        "taint"
      ],
      "canonical": true
    },
    "IntentCheckpoint": {
      "fields": [
        "checkpoint_id",
        "intent_id",
        "context_root",
        "message_root",
        "provenance_root",
        "memory_root",
        "collective_root",
        "trajectory_root",
        "world_state_root",
        "authority_root",
        "at"
      ],
      "canonical": true
    }
  },
  "limitations": [
    "TESTED library: the intent/communication fabric is part of the L5 kernel library on the operator host; it is not a hosted service and it runs no agents or message bus.",
    "Prompt-injection detection is pattern-based, not perfect semantic detection; a novel phrasing may not be flagged, and a flagged phrase is not proof of malice.",
    "Intent influence and provenance graphs are attribution EVIDENCE, not perfect causal explanations.",
    "Taint is a governance signal (provenance risk), never proof of malicious intent.",
    "Attestation is over software/configuration digests and supplied measurements, NOT hardware attestation.",
    "Cross-domain trust is not automatically established; it requires an explicit trust root and policy.",
    "Transaction guarantees cover the governed evidence/state layer only; external systems are not claimed to support rollback.",
    "No framework adapter is published, so none is described as supported.",
    "No third party has reviewed this bundle; the clean-room verifier shares no CAIN imports but was written by the same operator.",
    "Performance numbers are a single in-process run on the build host with the stated workload."
  ],
  "performance": {
    "conditions": {
      "host": "vultr",
      "machine": "x86_64",
      "processor": "",
      "cpu_count": 2,
      "python": "3.14.4",
      "os": "Linux-7.0.0-30-generic-x86_64-with-glibc2.43",
      "topology": "single process, in-process library calls",
      "warm_state": "warm (objects pre-built once, timed in a loop)",
      "concurrency": 1,
      "workload": {
        "canonicalize_message": "message body digest",
        "verify_message": "signature+ expiry+nonce/session",
        "build_intent": "AgentIntent digest",
        "taint_propagate": "derive_taint of 1 flag",
        "provenance_traverse": "IntentProvenanceGraph.all_influences",
        "conflict_detect": "2-claim conflict",
        "authorization_binding": "objective->intent->action binding",
        "tool_output_classify": "regex classification of a 1-line output"
      },
      "samples_per_case": 2000,
      "unit": "microseconds"
    },
    "results": {
      "message_canonicalization": {
        "p50_us": 15.563,
        "p95_us": 28.421,
        "p99_us": 184.95,
        "max_us": 2595.641,
        "mean_us": 25.761,
        "samples": 2000
      },
      "message_verification": {
        "p50_us": 170.77,
        "p95_us": 340.724,
        "p99_us": 2086.718,
        "max_us": 8438.622,
        "mean_us": 236.145,
        "samples": 2000
      },
      "intent_construction": {
        "p50_us": 11.859,
        "p95_us": 19.822,
        "p99_us": 38.664,
        "max_us": 358.904,
        "mean_us": 13.495,
        "samples": 2000
      },
      "taint_propagation": {
        "p50_us": 1.405,
        "p95_us": 2.344,
        "p99_us": 3.093,
        "max_us": 50.481,
        "mean_us": 1.592,
        "samples": 2000
      },
      "intent_graph_traversal": {
        "p50_us": 0.707,
        "p95_us": 1.036,
        "p99_us": 1.309,
        "max_us": 20.103,
        "mean_us": 0.773,
        "samples": 2000
      },
      "conflict_detection": {
        "p50_us": 2.319,
        "p95_us": 3.738,
        "p99_us": 10.263,
        "max_us": 1933.675,
        "mean_us": 4.27,
        "samples": 2000
      },
      "authorization_binding": {
        "p50_us": 35.972,
        "p95_us": 131.714,
        "p99_us": 429.208,
        "max_us": 2231.825,
        "mean_us": 60.049,
        "samples": 2000
      },
      "tool_output_classify": {
        "p50_us": 16.775,
        "p95_us": 26.718,
        "p99_us": 51.621,
        "max_us": 843.573,
        "mean_us": 19.413,
        "samples": 2000
      }
    },
    "note": "single host, single operator, in-process, warm; not a production benchmark; no extrapolation"
  },
  "environment_class": "operator host, single process, pre-production",
  "laws": [
    "INFORMATION IS NOT AUTHORITY",
    "A MESSAGE IS NOT AUTHORIZATION",
    "A TOOL OUTPUT IS NOT POLICY",
    "MEMORY IS NOT AUTHORITY",
    "CONSENSUS IS NOT AUTHORIZATION",
    "PROVENANCE MUST SURVIVE TRANSFORMATION",
    "TAINT MUST SURVIVE DERIVATION",
    "MATERIAL INTENT MUTATION INVALIDATES AUTHORIZATION",
    "UNKNOWN MUST REMAIN UNKNOWN"
  ],
  "evidence_level": "TESTED",
  "signer_public_key_b64": "mljgD5i0E80tTBalszMCIKvTlSzUcIpOGRYwiFyEAqY=",
  "signature_b64": "xtww9SCW776o615crMuFCAvyj88dHdgGfV93a9NSS0BSLx+Bm2qx49c/s+EiVTVg+TOPStm+ju63YWvSZvqSAw=="
}
