Skip to content

docs: define Agent Trust Kernel contract (DSE-714)#85

Merged
ernestprovo23 merged 2 commits into
mainfrom
codex/dse-714-agent-trust-kernel
Jul 19, 2026
Merged

docs: define Agent Trust Kernel contract (DSE-714)#85
ernestprovo23 merged 2 commits into
mainfrom
codex/dse-714-agent-trust-kernel

Conversation

@ernestprovo23

@ernestprovo23 ernestprovo23 commented Jul 18, 2026

Copy link
Copy Markdown
Member

Summary

  • define the normative Agent Trust Kernel contract and twelve testable invariants
  • inventory protected assets, authoritative identities, threat classes, fail-closed outcomes, and non-overridable critical classes
  • bind DSE-715 through DSE-717 to the contract and add explicit conformance gates
  • cross-link the contract from the documentation index, system context, and shipped threat models

Product boundary

This is a design contract for DSE-714. MCP-Warden v1.1 remains explicitly nonconformant until DSE-715 through DSE-717 implement and verify the required runtime behavior.

Adversarial review

  • four Conclave adversarial passes, culminating in SHIP (08f29532471e43afbef843e2b4db8d48)
  • final independent CSO review: SHIP
  • all 15 binding findings resolved; no fail-open, authority, contradiction, or testability blocker remains

Verification

  • Ruff: passed
  • strict MkDocs build with CI-pinned Material 9.7.6: passed
  • relative Markdown links: passed
  • Mermaid rendering for the ATK contract and system context: passed
  • deterministic property-fuzz suite (--hypothesis-seed=0): 35 passed
  • repository suite: 603 passed, 2 skipped; the one sandbox-denied process-table test passed separately outside the sandbox (1 passed)
  • git diff --check: passed
  • required GitHub checks on commit 460c8c5: pending

Linear: DSE-714

@ernestprovo23
ernestprovo23 marked this pull request as ready for review July 19, 2026 00:25
@ernestprovo23
ernestprovo23 merged commit 80831ab into main Jul 19, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant