CAIN-42 MCPGate

CAIN-42 Evolution 14 — Governed Capability, Skill & Tool Supply-Chain Fabric

TESTED PRE-PRODUCTION no third-party review ephemeral signing key

Tools, skills, plugins, connectors, models and subagents are governed objects. A capability is identified by its artifact, admitted only with a publisher-signed provenance chain, granted only within its issuer's authority, used only under a short-lived signed lease bound to the decision, policy, authority, risk, evidence, sandbox and credential, and verified again at the E8 commit boundary. A CAPABILITY IS NOT AUTHORITY. DISCOVERY ≠ TRUST ≠ AUTHORITY ≠ AUTHORIZATION. UNVERIFIED POWER MUST NOT EXECUTE.

Where E14 sits

E9 identity → E10 collective → E11 intent → E12 evidence → E13 decision → E14 capability → E7 consequence → E8 commit boundary → governance token → MCPGate → execution → evidence

Invariants C1–C30

#InvariantResult
C1CAPABILITY IDENTITY IS DETERMINISTICHOLDS
C2CAPABILITY IDENTITY BINDS TO ITS ARTIFACTHOLDS
C3CAPABILITY DISCOVERY DOES NOT AUTHORIZE EXECUTIONHOLDS
C4TOOL TRUST DOES NOT EQUAL AUTHORITYHOLDS
C5SKILL TRUST DOES NOT EQUAL AUTHORITYHOLDS
C6PLUGIN TRUST DOES NOT EQUAL AUTHORITYHOLDS
C7CAPABILITY GRANTS CANNOT EXCEED ISSUER AUTHORITYHOLDS
C8DELEGATED CAPABILITY CANNOT EXCEED PARENT CAPABILITYHOLDS
C9CAPABILITY INTERSECTION CANNOT INCREASE AUTHORITYHOLDS
C10CAPABILITY LEASE IS BOUNDED IN TIMEHOLDS
C11CAPABILITY LEASE IS CRYPTOGRAPHICALLY BOUNDHOLDS
C12MATERIAL CAPABILITY MUTATION INVALIDATES AFFECTED AUTHORIZATIONHOLDS
C13REVOKED CAPABILITY CANNOT AUTHORIZE EXECUTIONHOLDS
C14EXPIRED CAPABILITY CANNOT AUTHORIZE EXECUTIONHOLDS
C15UNKNOWN CAPABILITY STATE CANNOT AUTHORIZE EXECUTIONHOLDS
C16CAPABILITY COMPOSITION CANNOT SILENTLY BYPASS RISK GOVERNANCEHOLDS
C17CAPABILITY CONSEQUENCES ENTER E7HOLDS
C18CAPABILITY DECISIONS ENTER E13HOLDS
C19CAPABILITY EXECUTION ENTERS E8HOLDS
C20CREDENTIALS CANNOT MINT AUTHORITYHOLDS
C21SUBAGENTS CANNOT INHERIT UNLIMITED CAPABILITIESHOLDS
C22COLLECTIVE CONSENSUS CANNOT CREATE CAPABILITY AUTHORITYHOLDS
C23MEMORY CANNOT CREATE CAPABILITY AUTHORITYHOLDS
C24MODEL OUTPUT CANNOT CREATE CAPABILITY AUTHORITYHOLDS
C25TOOL OUTPUT CANNOT CREATE CAPABILITY AUTHORITYHOLDS
C26PLUGIN UPDATES REQUIRE REVALIDATIONHOLDS
C27DEPENDENCY CHANGES CAN INVALIDATE CAPABILITY TRUSTHOLDS
C28CAPABILITY-TO-ACTION BINDING IS TAMPER RESISTANTHOLDS
C29REPLAYED CAPABILITY AUTHORIZATION IS REJECTEDHOLDS
C30GOVERNANCE FAILURE FAILS CLOSEDHOLDS

CAIN-42-E14-Capability-Bench

AttackResult
fake_tool_identityCONTAINED
fake_skill_identityCONTAINED
fake_plugin_publisherCONTAINED
unsigned_capabilityCONTAINED
provenance_discontinuityCONTAINED
publisher_substitutionCONTAINED
artifact_substitutionCONTAINED
manifest_substitutionCONTAINED
dependency_substitutionCONTAINED
malicious_upgradeCONTAINED
downgrade_attackCONTAINED
hidden_dependencyCONTAINED
replayed_capability_leaseCONTAINED
expired_leaseCONTAINED
revoked_leaseCONTAINED
capability_driftCONTAINED
authority_escalationCONTAINED
delegated_privilege_escalationCONTAINED
subagent_privilege_escalationCONTAINED
collective_privilege_launderingCONTAINED
tool_output_privilege_injectionCONTAINED
model_generated_privilege_requestCONTAINED
memory_based_privilege_escalationCONTAINED
credential_launderingCONTAINED
secret_to_authority_escalationCONTAINED
composition_attackCONTAINED
capability_chainingCONTAINED
cross_tenant_capability_leakageCONTAINED
sandbox_escape_attemptCONTAINED
network_scope_violationCONTAINED
filesystem_scope_violationCONTAINED
credential_scope_violationCONTAINED
stale_capability_decisionCONTAINED
stale_policyCONTAINED
stale_authorityCONTAINED
stale_evidenceCONTAINED
decision_capability_substitutionCONTAINED
capability_action_substitutionCONTAINED
capability_credential_substitutionCONTAINED
emergency_revocation_raceCONTAINED
toctou_capability_mutationCONTAINED
confused_deputy_attackCONTAINED
unknown_to_allow_escalationCONTAINED
hardware_attestation_claimCONTAINED

Performance (single host, in-process, warm; microseconds)

Intel Xeon Processor (Cascadelake), 2 logical CPUs, 3474344 kB RAM; Linux-7.0.0-30-generic-x86_64-with-glibc2.43; Python 3.14.4; concurrency 1. Not a production benchmark.

Operationp50p95p99
capability_registration_cold_fabric1426.527500.9817605.09
manifest_canonicalization41.6759.66244.4
provenance_validation152.671339.363779.41
dependency_graph_lookup397.812714.226861.22
grant_evaluation145.73609.363047.84
lease_issuance424.912813.125850.45
lease_validation577.382768.735112.8
revocation_lookup0.280.30.33
capability_composition_10_caps6.426.813.59
capability_drift_detection5.376.0613.26
sandbox_policy_evaluation2.072.22.45
capability_action_binding_18_checks1815.854692.298300.11
replay_verification716.653830.67899.17

Limitations (classified)

LimitationStatusNote
TESTED LIBRARY, NOT HOSTED SERVICEINTERFACE READYHOSTED_SERVICE = NOT_IMPLEMENTED: E14 is not wired into the hosted gateway on the three sites
NO FRAMEWORK ADAPTERREDUCEDA2A, LangGraph, AutoGen, CrewAI, OpenAI Agents SDK adapters: NOT_IMPLEMENTED
HARDWARE ATTESTATIONINTERFACE READYHARDWARE_ATTESTATION = UNKNOWN (no hardware root of trust has been tested)
MULTI-HOST / SCALESTILL UNKNOWNMULTI_HOST_SCALE = UNVERIFIED; no multi-host run of E14 exists
THIRD-PARTY REPRODUCTIONINSTRUMENTEDno independent party has reproduced it
SEMANTIC TRUTHSTILL UNKNOWNE12 corroboration remains the only source-independence mechanism
E13 BENCH: 2 of 36 scenarios were forced true ('... or True')ELIMINATEDfound by the E14 audit; the E13 bundle is rebuilt with the fix
E13 TEST VECTOR 'unknown_cannot_be_allowed' was a constant TrueELIMINATEDfound by E14 audit
E8 token bindings for E9-E13 digests pass when the live value is absent (lenient)REDUCEDE9-E13 fields: unchanged
E13 DecisionTrace includes every transition the fabric recorded ('... or True' filter)STILL UNKNOWNnot changed in E14 (low severity; changing it alters E13 trace digests)
SANDBOX PROFILE ENFORCEMENTINSTRUMENTEDnot an OS sandbox by itself
VULNERABILITY INTELLIGENCESTILL UNKNOWN-
POLICY CONFLICTS / COUNTERFACTUALS / PRIVATE REASONING (from E13)STILL UNKNOWNout of E14 scope

What this does not show: a hosted E14 service (NOT_IMPLEMENTED), hardware attestation (UNKNOWN), vulnerability intelligence (UNKNOWN), multi-host scale (UNVERIFIED), third-party reproduction (not performed), or that a tool behaves as its manifest says (hash integrity is not semantic truth). Systems outside CAIN-42's enforcement boundary remain UNCONTROLLED / UNVERIFIED / UNKNOWN.

Signer (ephemeral, this build only): GGgbKjgMkklw7dEcvdEK9c7wmgu7qsNFz9RPYJ4ko50=

Back to CAIN