{
  "claimBoundary": "CapitalGuard Agent Intent Firewall 0.1 enforces only operations routed through its owned callback against a finite threshold-signed, actor-bound, task-bound, session-bound execution graph. It deterministically verifies step order, exact operation selectors, use limits, replay state, and atomic pre-invocation reservations. It does not infer semantic intent from prose, prove approver understanding, inspect bypassed operations, reverse completed actions, reconcile uncertain outcomes automatically, resist host or threshold-authority compromise, or detect coordinated rollback of both state and its external anchor.",
  "digestAlgorithm": "SHA-256",
  "id": "CG-AGENT-INTENT-FIREWALL-0.1.0-RELEASE",
  "licensedArtifacts": [
    {
      "bytes": 105906,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-agent-intent-firewall.cjs",
      "id": "agent-intent-firewall-library",
      "sha256": "ad10b2422f918934dc6131bf9edb026bd6a613976456f78b3ecbadaa9d76c70d"
    },
    {
      "bytes": 113667,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-agent-intent-firewall-cli.cjs",
      "id": "agent-intent-firewall-cli",
      "sha256": "5b46a8abb1978c9a3737cdc47288dd4db409557ce1f75af89d48b2b258f16b8b"
    },
    {
      "bytes": 4817,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-agent-intent-firewall-guide.md",
      "id": "agent-intent-firewall-guide",
      "sha256": "a066c46d325dbd5d7c8a5147347e3b63bc07feec7338b8aee5a5b9bb21b9e030"
    }
  ],
  "publicArtifacts": [
    {
      "bytes": 1940,
      "filename": "anchor.schema.json",
      "sha256": "798bafc6d820f8d2959e640a478319689aefa79d29663eab235a2e84dded6c39"
    },
    {
      "bytes": 20870,
      "filename": "contract.schema.json",
      "sha256": "1c398f7acb44fdc49a55195d62db423f377f7bbd9c3924c3b75c003c4cbfb4a3"
    },
    {
      "bytes": 3161,
      "filename": "invocation-evidence.schema.json",
      "sha256": "e7f9428211fffd1042f4ee8c85f14a09d576b7c07116db24d8d70b73708381ad"
    },
    {
      "bytes": 2959,
      "filename": "methodology.json",
      "sha256": "73a85b15921f6e749a047fe43de23376f1190ac171db748bf8183c1f685f8258"
    },
    {
      "bytes": 5175,
      "filename": "receipt.schema.json",
      "sha256": "4d0fa1a57374ae73889717b03bc27121b532983a641771348f8c780203fefbbb"
    },
    {
      "bytes": 5811,
      "filename": "state.schema.json",
      "sha256": "b0c3a8f06d25babd6d6eabd2ee69d276b7fdd6f98f551e32bb767395ab7dc452"
    },
    {
      "bytes": 3747,
      "filename": "support-matrix.json",
      "sha256": "af210a56e31aa41d0605e45950360b99d76a8253ced974d0b280be7fe3827f30"
    },
    {
      "bytes": 3448,
      "filename": "test-vectors.json",
      "sha256": "c6e063063d7ab27cdabfdbf3c82940f3bae755f01f89c9f7ea893f03188c9557"
    },
    {
      "bytes": 2118,
      "filename": "threat-model.json",
      "sha256": "807ad6544607be8fb70efa607a7488400e4d877ff3ef5eecbbdeb146a0ebdd11"
    }
  ],
  "releaseDigestSha256": "2d94a1c4341dc878dff34d18022df50c74402af4c4780c59e595437361019a3e",
  "releasedAt": "2026-07-19T21:00:00.000Z",
  "runtimeStackClaimBoundary": "CapitalGuard Agent Intent Runtime Stack 0.1 owns the only configured downstream callback and invokes it only after Agent Intent Firewall reserves a matching signed graph step. It binds the intent evidence digest to the downstream trust-chain receipt digest. CapitalGuard Agent Intent Firewall 0.1 enforces only operations routed through its owned callback against a finite threshold-signed, actor-bound, task-bound, session-bound execution graph. It deterministically verifies step order, exact operation selectors, use limits, replay state, and atomic pre-invocation reservations. It does not infer semantic intent from prose, prove approver understanding, inspect bypassed operations, reverse completed actions, reconcile uncertain outcomes automatically, resist host or threshold-authority compromise, or detect coordinated rollback of both state and its external anchor.",
  "runtimeStackVersion": "0.1.0",
  "status": "stable",
  "version": "0.1.0"
}
