Skip to content

docs: add tomevault-io/ai-catalog-reference to implementations#90

Open
olijboyd wants to merge 1 commit into
Agent-Card:mainfrom
olijboyd:docs/add-tomevault-implementation
Open

docs: add tomevault-io/ai-catalog-reference to implementations#90
olijboyd wants to merge 1 commit into
Agent-Card:mainfrom
olijboyd:docs/add-tomevault-implementation

Conversation

@olijboyd

Copy link
Copy Markdown

Adds TomeVault's implementation to the list.

Apache-2.0, Python, covering the Trust Manifest layer: detached EdDSA JWS over JCS, subject binding, identity anchoring, freshness, and SSRF-safe fetch. It also ships a vector suite that runs the ADR-0009 substitution attack both ways, so the subject binding can be checked against running code rather than read in prose.

Disclosure: I work on TomeVault, where we find what has gone wrong in a team's AI instruction files, sign the corrected version, and keep watching for the next time it drifts. We do that across every tool and format, since no vendor checks another's, which is why a shared trust layer matters to us and why this exists.

Docs only, no specification text changed.

Signed-off-by: Oli Boyd <oli@tomevault.io>
@olijboyd
olijboyd requested a review from a team as a code owner July 23, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant