CAIN-42 trust integrity, live on the production gateway (2026-09-28T23:18:36.531007+00:00, commit b5226ab) ============================================================================================== Save verify_trust_integrity_run.py.txt as .py (Python 3 standard library only; imports nothing from CAIN): python3 verify_trust_integrity_run.py CAIN42_TRUST_INTEGRITY_LIVE_RUN.json # offline: every case has the promised outcome python3 verify_trust_integrity_run.py CAIN42_TRUST_INTEGRITY_LIVE_RUN.json --live # + each of the 48 decisions against the PBFT cluster's OWN public record (/api/v1/live-cluster/qc/{sequence}): same decision id, same verdict, same commitment, a 3-of-4 commit certificate The fix. An outside-in audit on 2026-09-28 found that a new account which sent two prompt injections (both BLOCKED) was then ALLOWED to transfer $250,000, run `rm -rf /` and DROP TABLE: its trust fell from UNKNOWN to DEGRADED, and DEGRADED was answered more permissively than UNKNOWN. What the run shows, on cainstudio.online, mcpgate.online and clawx.click, each with a fresh free account: T1 a new agent's first action is held AND queued for approval (it has an approval id you can approve) T2 two prompt injections are BLOCKED T3 after T2, the $250,000 transfer, `rm -rf /` and DROP TABLE are held for a human, not ALLOWED T4 the action itself is scored: all three are critical, not `low` T5 a deny rule on /tools/send_email blocks /tools/Send_Email, /tools/send_email/, /tools//send_email and /tools/send%5Femail too T6 a brand-new agent label cannot escape its key's record (per-agent trust, capped by the key) T7 the no-account demo states that it enforces, and whether each stage ran T8 a solo developer creates an agent key; the agent is held, cannot approve itself, the owner approves, the retry runs, its next low-risk call runs with no approval, and a critical action is still held Try it (no account): curl -s -X POST 'https://cainstudio.online/fabric/try?scenario=prompt-injection' -> "verdict": "BLOCKED", "enforcing": true, "mode": "enforce" What this is NOT: a third-party review or pen test, a customer deployment, or a latency fix (decisions in this run took 1176-7763 ms). Action risk reads the tool name and arguments the agent declares; a tool whose name hides what it does is scored on its arguments only. PRE-PRODUCTION.