TESTED PRE-PRODUCTION no third-party review ephemeral signing key
Tools, skills, plugins, connectors, models and subagents are governed objects. A capability is identified by its artifact, admitted only with a publisher-signed provenance chain, granted only within its issuer's authority, used only under a short-lived signed lease bound to the decision, policy, authority, risk, evidence, sandbox and credential, and verified again at the E8 commit boundary. A CAPABILITY IS NOT AUTHORITY. DISCOVERY ≠ TRUST ≠ AUTHORITY ≠ AUTHORIZATION. UNVERIFIED POWER MUST NOT EXECUTE.
============================= 174 passed in 5.90s ==============================.E9 identity → E10 collective → E11 intent → E12 evidence → E13 decision → E14 capability
→ E7 consequence → E8 commit boundary → governance token → MCPGate → execution → evidence
| # | Invariant | Result |
|---|---|---|
| C1 | CAPABILITY IDENTITY IS DETERMINISTIC | HOLDS |
| C2 | CAPABILITY IDENTITY BINDS TO ITS ARTIFACT | HOLDS |
| C3 | CAPABILITY DISCOVERY DOES NOT AUTHORIZE EXECUTION | HOLDS |
| C4 | TOOL TRUST DOES NOT EQUAL AUTHORITY | HOLDS |
| C5 | SKILL TRUST DOES NOT EQUAL AUTHORITY | HOLDS |
| C6 | PLUGIN TRUST DOES NOT EQUAL AUTHORITY | HOLDS |
| C7 | CAPABILITY GRANTS CANNOT EXCEED ISSUER AUTHORITY | HOLDS |
| C8 | DELEGATED CAPABILITY CANNOT EXCEED PARENT CAPABILITY | HOLDS |
| C9 | CAPABILITY INTERSECTION CANNOT INCREASE AUTHORITY | HOLDS |
| C10 | CAPABILITY LEASE IS BOUNDED IN TIME | HOLDS |
| C11 | CAPABILITY LEASE IS CRYPTOGRAPHICALLY BOUND | HOLDS |
| C12 | MATERIAL CAPABILITY MUTATION INVALIDATES AFFECTED AUTHORIZATION | HOLDS |
| C13 | REVOKED CAPABILITY CANNOT AUTHORIZE EXECUTION | HOLDS |
| C14 | EXPIRED CAPABILITY CANNOT AUTHORIZE EXECUTION | HOLDS |
| C15 | UNKNOWN CAPABILITY STATE CANNOT AUTHORIZE EXECUTION | HOLDS |
| C16 | CAPABILITY COMPOSITION CANNOT SILENTLY BYPASS RISK GOVERNANCE | HOLDS |
| C17 | CAPABILITY CONSEQUENCES ENTER E7 | HOLDS |
| C18 | CAPABILITY DECISIONS ENTER E13 | HOLDS |
| C19 | CAPABILITY EXECUTION ENTERS E8 | HOLDS |
| C20 | CREDENTIALS CANNOT MINT AUTHORITY | HOLDS |
| C21 | SUBAGENTS CANNOT INHERIT UNLIMITED CAPABILITIES | HOLDS |
| C22 | COLLECTIVE CONSENSUS CANNOT CREATE CAPABILITY AUTHORITY | HOLDS |
| C23 | MEMORY CANNOT CREATE CAPABILITY AUTHORITY | HOLDS |
| C24 | MODEL OUTPUT CANNOT CREATE CAPABILITY AUTHORITY | HOLDS |
| C25 | TOOL OUTPUT CANNOT CREATE CAPABILITY AUTHORITY | HOLDS |
| C26 | PLUGIN UPDATES REQUIRE REVALIDATION | HOLDS |
| C27 | DEPENDENCY CHANGES CAN INVALIDATE CAPABILITY TRUST | HOLDS |
| C28 | CAPABILITY-TO-ACTION BINDING IS TAMPER RESISTANT | HOLDS |
| C29 | REPLAYED CAPABILITY AUTHORIZATION IS REJECTED | HOLDS |
| C30 | GOVERNANCE FAILURE FAILS CLOSED | HOLDS |
| Attack | Result |
|---|---|
| fake_tool_identity | CONTAINED |
| fake_skill_identity | CONTAINED |
| fake_plugin_publisher | CONTAINED |
| unsigned_capability | CONTAINED |
| provenance_discontinuity | CONTAINED |
| publisher_substitution | CONTAINED |
| artifact_substitution | CONTAINED |
| manifest_substitution | CONTAINED |
| dependency_substitution | CONTAINED |
| malicious_upgrade | CONTAINED |
| downgrade_attack | CONTAINED |
| hidden_dependency | CONTAINED |
| replayed_capability_lease | CONTAINED |
| expired_lease | CONTAINED |
| revoked_lease | CONTAINED |
| capability_drift | CONTAINED |
| authority_escalation | CONTAINED |
| delegated_privilege_escalation | CONTAINED |
| subagent_privilege_escalation | CONTAINED |
| collective_privilege_laundering | CONTAINED |
| tool_output_privilege_injection | CONTAINED |
| model_generated_privilege_request | CONTAINED |
| memory_based_privilege_escalation | CONTAINED |
| credential_laundering | CONTAINED |
| secret_to_authority_escalation | CONTAINED |
| composition_attack | CONTAINED |
| capability_chaining | CONTAINED |
| cross_tenant_capability_leakage | CONTAINED |
| sandbox_escape_attempt | CONTAINED |
| network_scope_violation | CONTAINED |
| filesystem_scope_violation | CONTAINED |
| credential_scope_violation | CONTAINED |
| stale_capability_decision | CONTAINED |
| stale_policy | CONTAINED |
| stale_authority | CONTAINED |
| stale_evidence | CONTAINED |
| decision_capability_substitution | CONTAINED |
| capability_action_substitution | CONTAINED |
| capability_credential_substitution | CONTAINED |
| emergency_revocation_race | CONTAINED |
| toctou_capability_mutation | CONTAINED |
| confused_deputy_attack | CONTAINED |
| unknown_to_allow_escalation | CONTAINED |
| hardware_attestation_claim | CONTAINED |
Intel Xeon Processor (Cascadelake), 2 logical CPUs, 3474344 kB RAM; Linux-7.0.0-30-generic-x86_64-with-glibc2.43; Python 3.14.4; concurrency 1. Not a production benchmark.
| Operation | p50 | p95 | p99 |
|---|---|---|---|
| capability_registration_cold_fabric | 1426.52 | 7500.98 | 17605.09 |
| manifest_canonicalization | 41.67 | 59.66 | 244.4 |
| provenance_validation | 152.67 | 1339.36 | 3779.41 |
| dependency_graph_lookup | 397.81 | 2714.22 | 6861.22 |
| grant_evaluation | 145.73 | 609.36 | 3047.84 |
| lease_issuance | 424.91 | 2813.12 | 5850.45 |
| lease_validation | 577.38 | 2768.73 | 5112.8 |
| revocation_lookup | 0.28 | 0.3 | 0.33 |
| capability_composition_10_caps | 6.42 | 6.8 | 13.59 |
| capability_drift_detection | 5.37 | 6.06 | 13.26 |
| sandbox_policy_evaluation | 2.07 | 2.2 | 2.45 |
| capability_action_binding_18_checks | 1815.85 | 4692.29 | 8300.11 |
| replay_verification | 716.65 | 3830.6 | 7899.17 |
| Limitation | Status | Note |
|---|---|---|
| TESTED LIBRARY, NOT HOSTED SERVICE | INTERFACE READY | HOSTED_SERVICE = NOT_IMPLEMENTED: E14 is not wired into the hosted gateway on the three sites |
| NO FRAMEWORK ADAPTER | REDUCED | A2A, LangGraph, AutoGen, CrewAI, OpenAI Agents SDK adapters: NOT_IMPLEMENTED |
| HARDWARE ATTESTATION | INTERFACE READY | HARDWARE_ATTESTATION = UNKNOWN (no hardware root of trust has been tested) |
| MULTI-HOST / SCALE | STILL UNKNOWN | MULTI_HOST_SCALE = UNVERIFIED; no multi-host run of E14 exists |
| THIRD-PARTY REPRODUCTION | INSTRUMENTED | no independent party has reproduced it |
| SEMANTIC TRUTH | STILL UNKNOWN | E12 corroboration remains the only source-independence mechanism |
| E13 BENCH: 2 of 36 scenarios were forced true ('... or True') | ELIMINATED | found by the E14 audit; the E13 bundle is rebuilt with the fix |
| E13 TEST VECTOR 'unknown_cannot_be_allowed' was a constant True | ELIMINATED | found by E14 audit |
| E8 token bindings for E9-E13 digests pass when the live value is absent (lenient) | REDUCED | E9-E13 fields: unchanged |
| E13 DecisionTrace includes every transition the fabric recorded ('... or True' filter) | STILL UNKNOWN | not changed in E14 (low severity; changing it alters E13 trace digests) |
| SANDBOX PROFILE ENFORCEMENT | INSTRUMENTED | not an OS sandbox by itself |
| VULNERABILITY INTELLIGENCE | STILL UNKNOWN | - |
| POLICY CONFLICTS / COUNTERFACTUALS / PRIVATE REASONING (from E13) | STILL UNKNOWN | out of E14 scope |
What this does not show: a hosted E14 service (NOT_IMPLEMENTED), hardware attestation (UNKNOWN), vulnerability intelligence (UNKNOWN), multi-host scale (UNVERIFIED), third-party reproduction (not performed), or that a tool behaves as its manifest says (hash integrity is not semantic truth). Systems outside CAIN-42's enforcement boundary remain UNCONTROLLED / UNVERIFIED / UNKNOWN.
Signer (ephemeral, this build only): GGgbKjgMkklw7dEcvdEK9c7wmgu7qsNFz9RPYJ4ko50=