License verification benchmark 0.1
One valid chain. Eight attacks rejected.
The published verifier accepted the intact signed AI-agent license chain and rejected every declared authority, scope, expiry, revocation, session, binding, and schema mutation.
This is a synthetic publisher-run benchmark. It tests these exact fixtures only; it does not inspect a customer environment, prove private-key custody, or guarantee that an agent is secure.
CapitalGuard Security Research · Version 0.1.0 · Tested July 24, 2026
Case-level evidence
Each result names the trust stage and exact observed decision.
| Case | Condition | Trust stage | Expected | Observed | Result |
|---|---|---|---|---|---|
| CGAI-TV-001 | Valid signed license and exact-session proof | complete chain | accepted | accepted | Match |
| CGAI-TV-101 | Authority trust domain changed after signing | authority | rejected | rejected | Match |
| CGAI-TV-102 | Enrollment selector widened with a wildcard | enrollment | rejected | rejected | Match |
| CGAI-TV-103 | License evaluated after its expiry | license | rejected | rejected | Match |
| CGAI-TV-104 | Revocation event changed after signing | revocation ledger | rejected | rejected | Match |
| CGAI-TV-105 | Signed anchor no longer matches the ledger head | revocation anchor | rejected | rejected | Match |
| CGAI-TV-106 | Session proof evaluated after expiry | session proof | rejected | rejected | Match |
| CGAI-TV-107 | Expected policy binding substituted | session binding | rejected | rejected | Match |
| CGAI-TV-108 | Unknown field added to signed proof | strict schema | rejected | rejected | Match |
Reproducible release
Inspect, rerun, and hash the same evidence.
The release includes deterministic signed vectors, a dependency-free Node.js verifier, case results, methodology, and a manifest binding each file to its byte count and SHA-256 digest.
Run digest: d6f6df3393c4ccf8d667a6b4e61779a6e826792c53a381935313e42a3fe266b9
Limits are part of the result
The fixtures are synthetic and contain no customer repositories, credentials, agent traffic, or production keys.
The benchmark covers nine declared cases, not the complete input space of every schema or cryptographic implementation.
A valid signature proves integrity under the referenced key; it does not prove the human or legal identity behind that key.
Current revocation status still depends on retrieving and protecting the latest signed ledger and anchor.
Runtime controls outside the authenticated CapitalGuard path remain outside this verification result.
Primary sources checked July 24, 2026
Apply the evidence
