License verification benchmark 0.1

One valid chain. Eight attacks rejected.

The published verifier accepted the intact signed AI-agent license chain and rejected every declared authority, scope, expiry, revocation, session, binding, and schema mutation.

This is a synthetic publisher-run benchmark. It tests these exact fixtures only; it does not inspect a customer environment, prove private-key custody, or guarantee that an agent is secure.

CapitalGuard Security Research · Version 0.1.0 · Tested July 24, 2026

Case-level evidence

Each result names the trust stage and exact observed decision.

CaseConditionTrust stageExpectedObservedResult
CGAI-TV-001Valid signed license and exact-session proofcomplete chainacceptedaccepted Match
CGAI-TV-101Authority trust domain changed after signingauthorityrejectedrejected Match
CGAI-TV-102Enrollment selector widened with a wildcardenrollmentrejectedrejected Match
CGAI-TV-103License evaluated after its expirylicenserejectedrejected Match
CGAI-TV-104Revocation event changed after signingrevocation ledgerrejectedrejected Match
CGAI-TV-105Signed anchor no longer matches the ledger headrevocation anchorrejectedrejected Match
CGAI-TV-106Session proof evaluated after expirysession proofrejectedrejected Match
CGAI-TV-107Expected policy binding substitutedsession bindingrejectedrejected Match
CGAI-TV-108Unknown field added to signed proofstrict schemarejectedrejected Match

Reproducible release

Inspect, rerun, and hash the same evidence.

The release includes deterministic signed vectors, a dependency-free Node.js verifier, case results, methodology, and a manifest binding each file to its byte count and SHA-256 digest.

Run digest: d6f6df3393c4ccf8d667a6b4e61779a6e826792c53a381935313e42a3fe266b9

Limits are part of the result

The fixtures are synthetic and contain no customer repositories, credentials, agent traffic, or production keys.

The benchmark covers nine declared cases, not the complete input space of every schema or cryptographic implementation.

A valid signature proves integrity under the referenced key; it does not prove the human or legal identity behind that key.

Current revocation status still depends on retrieving and protecting the latest signed ledger and anchor.

Runtime controls outside the authenticated CapitalGuard path remain outside this verification result.

Primary sources checked July 24, 2026

Apply the evidence

Verify the authority, status, revocation head, and exact session before trust.

Open Integration Guide