Permission drift benchmark 0.1
See what changed before the agent runs.
CapitalGuard compared a signed, read-limited synthetic agent baseline with a broader candidate and identified 36 permission and control changes across ten classifications.
The fail-closed policy blocked the candidate, and the independent verifier rejected every declared artifact or binding mutation. This is publisher-run synthetic evidence, not a customer result.
CapitalGuard Security Research · Version 0.1.0 · Tested July 27, 2026
Case-level evidence
Every declared decision reproduced exactly.
| Case | Check | Expected | Observed | Result |
|---|---|---|---|---|
| CG-PD-001 | Fail-closed policy decision | block | block | Match |
| CG-PD-002 | Substantive change inventory | at least 20 changes | 36 changes | Match |
| CG-PD-003 | Declared classification coverage | control_removed|control_weakened|evidence_degraded|identity_inherited|informational|privilege_added|privilege_expanded|risk_reduced|surface_added|surface_removed | control_removed|control_weakened|evidence_degraded|identity_inherited|informational|privilege_added|privilege_expanded|risk_reduced|surface_added|surface_removed | Match |
| CG-PD-004 | Evidence degradation fails closed | degraded=true; decision=block | degraded=true; decision=block | Match |
| CG-PD-005 | Intact signed release | verified | verified | Match |
| CG-PD-006 | Private diff tamper | rejected | rejected | Match |
| CG-PD-007 | Shareable diff tamper | rejected | rejected | Match |
| CG-PD-008 | Signed receipt summary tamper | rejected | rejected | Match |
| CG-PD-009 | Signer-key digest substitution | rejected | rejected | Match |
| CG-PD-010 | Shareable comparison binding substitution | rejected | rejected | Match |
| CG-PD-011 | Shareable privacy boundary | zero declared private markers | 0 markers | Match |
Reproducible release
Download the evidence. Verify the bindings.
The release includes inert fixtures, case results, signed private and privacy-reduced diffs, a signed receipt, a dependency-free verifier, and a manifest binding each file to its exact size and SHA-256.
Run digest: dec20b5ce30488e03b80eb1494236a7afc19c226f2ced91570a9be84779151c0
What this evidence does not prove
This publisher-operated benchmark compares one synthetic baseline with one synthetic expanded agent surface using CapitalGuard Privilege Diff 0.1. It proves only the declared fixture outcomes and signed evidence bindings. It does not inspect a vendor product, customer repository, runtime behavior, exploitability, false-negative rate, or guarantee of protection.
The baseline and candidate are synthetic repository configurations created by CapitalGuard.
The benchmark exercises the declared Agent Surface Compiler 0.1 support matrix and cannot infer undeclared runtime behavior.
A block decision means the configured policy found unacknowledged expansion or degraded evidence; it does not prove exploitation.
The public verifier validates artifact hashes, Ed25519 receipt integrity, and cross-artifact bindings, not the proprietary comparison engine.
Unchanged configuration is not proof of safety, and a passing release check is not a security certification.
Primary sources checked July 27, 2026
Apply the method
