TESTED PRE-PRODUCTION no third-party review
Governs the information channel: messages, context, tool/MCP output, memory and external content, and the intent an agent derives from them. INFORMATION IS NOT AUTHORITY. A MESSAGE IS NOT AUTHORIZATION. A TOOL OUTPUT IS NOT POLICY. MEMORY IS NOT AUTHORITY. TAINT MUST SURVIVE DERIVATION.
============================== 36 passed in 0.67s ==============================.| # | Invariant | Result |
|---|---|---|
| I1 | MESSAGE INTEGRITY IS CRYPTOGRAPHICALLY VERIFIABLE | HOLDS |
| I2 | MESSAGE PROVENANCE IS PRESERVED | HOLDS |
| I3 | INFORMATION DOES NOT AUTOMATICALLY CREATE AUTHORITY | HOLDS |
| I4 | TOOL OUTPUT CANNOT MODIFY POLICY AUTOMATICALLY | HOLDS |
| I5 | MEMORY CANNOT CREATE AUTHORITY | HOLDS |
| I6 | DELEGATION REQUIRES INDEPENDENTLY VERIFIABLE AUTHORITY | HOLDS |
| I7 | MATERIAL INTENT MUTATION INVALIDATES AUTHORIZATION | HOLDS |
| I8 | LOWER-TRUST CONTENT CANNOT SILENTLY OVERRIDE HIGHER-TRUST GOVERNANCE | HOLDS |
| I9 | CONSENSUS DOES NOT EQUAL AUTHORIZATION | HOLDS |
| I10 | TAINT PROPAGATES THROUGH DERIVED INTENT | HOLDS |
| I11 | UNKNOWN PROVENANCE REMAINS UNKNOWN | HOLDS |
| I12 | REPLAY PROTECTION IS MANDATORY FOR GOVERNED MESSAGES | HOLDS |
| I13 | CONFUSED-DEPUTY EXECUTION IS REJECTED | HOLDS |
| I14 | CROSS-COLLECTIVE AUTHORITY IS NEVER IMPLICIT | HOLDS |
| I15 | COLLECTIVE INTENT REMAINS ATTRIBUTABLE TO CONTRIBUTING AGENTS | HOLDS |
| I16 | INTENT DRIFT CAN INVALIDATE AUTHORITY | HOLDS |
| I17 | GOVERNANCE DECISIONS BIND TO CANONICAL INTENT | HOLDS |
| I18 | EVIDENCE RECORDS THE CONTEXT USED FOR AUTHORIZATION | HOLDS |
| I19 | QUARANTINED COMMUNICATION CANNOT SILENTLY BECOME TRUSTED INPUT | HOLDS |
| I20 | AN AGENT CANNOT AUTHORIZE ITSELF THROUGH COMMUNICATION WITH ANOTHER AGENT | HOLDS |
| Attack | Result |
|---|---|
| direct_prompt_injection | BLOCKED |
| indirect_prompt_injection | BLOCKED |
| malicious_tool_output | BLOCKED |
| malicious_mcp_output | BLOCKED |
| malicious_a2a_message | BLOCKED |
| forged_delegation | BLOCKED |
| replayed_delegation | BLOCKED |
| stale_intent | BLOCKED |
| intent_substitution | BLOCKED |
| context_substitution | BLOCKED |
| memory_authority_laundering | BLOCKED |
| confused_deputy | BLOCKED |
| collective_manipulation | BLOCKED |
| cross_domain_trust_abuse | BLOCKED |
| role_confusion | BLOCKED |
| provenance_stripping | BLOCKED |
| taint_laundering | BLOCKED |
| objective_drift | BLOCKED |
| consensus_laundering | BLOCKED |
| coordinated_communication_attack | BLOCKED |
What this does not show: perfect semantic prompt-injection detection (it is pattern-based); perfect causal attribution (influence graphs are evidence); proof of malicious intent (taint is a signal); hardware attestation; automatic cross-domain trust; or any third-party review.
Signer (ephemeral): mljgD5i0E80tTBalszMCIKvTlSzUcIpOGRYwiFyEAqY=