Permission drift benchmark 0.1

See what changed before the agent runs.

CapitalGuard compared a signed, read-limited synthetic agent baseline with a broader candidate and identified 36 permission and control changes across ten classifications.

The fail-closed policy blocked the candidate, and the independent verifier rejected every declared artifact or binding mutation. This is publisher-run synthetic evidence, not a customer result.

CapitalGuard Security Research · Version 0.1.0 · Tested July 27, 2026

Case-level evidence

Every declared decision reproduced exactly.

CaseCheckExpectedObservedResult
CG-PD-001Fail-closed policy decisionblockblock Match
CG-PD-002Substantive change inventoryat least 20 changes36 changes Match
CG-PD-003Declared classification coveragecontrol_removed|control_weakened|evidence_degraded|identity_inherited|informational|privilege_added|privilege_expanded|risk_reduced|surface_added|surface_removedcontrol_removed|control_weakened|evidence_degraded|identity_inherited|informational|privilege_added|privilege_expanded|risk_reduced|surface_added|surface_removed Match
CG-PD-004Evidence degradation fails closeddegraded=true; decision=blockdegraded=true; decision=block Match
CG-PD-005Intact signed releaseverifiedverified Match
CG-PD-006Private diff tamperrejectedrejected Match
CG-PD-007Shareable diff tamperrejectedrejected Match
CG-PD-008Signed receipt summary tamperrejectedrejected Match
CG-PD-009Signer-key digest substitutionrejectedrejected Match
CG-PD-010Shareable comparison binding substitutionrejectedrejected Match
CG-PD-011Shareable privacy boundaryzero declared private markers0 markers Match

Reproducible release

Download the evidence. Verify the bindings.

The release includes inert fixtures, case results, signed private and privacy-reduced diffs, a signed receipt, a dependency-free verifier, and a manifest binding each file to its exact size and SHA-256.

Run digest: dec20b5ce30488e03b80eb1494236a7afc19c226f2ced91570a9be84779151c0

What this evidence does not prove

This publisher-operated benchmark compares one synthetic baseline with one synthetic expanded agent surface using CapitalGuard Privilege Diff 0.1. It proves only the declared fixture outcomes and signed evidence bindings. It does not inspect a vendor product, customer repository, runtime behavior, exploitability, false-negative rate, or guarantee of protection.

The baseline and candidate are synthetic repository configurations created by CapitalGuard.

The benchmark exercises the declared Agent Surface Compiler 0.1 support matrix and cannot infer undeclared runtime behavior.

A block decision means the configured policy found unacknowledged expansion or degraded evidence; it does not prove exploitation.

The public verifier validates artifact hashes, Ed25519 receipt integrity, and cross-artifact bindings, not the proprietary comparison engine.

Unchanged configuration is not proof of safety, and a passing release check is not a security certification.

Primary sources checked July 27, 2026

Apply the method

Record the approved access. Review every expansion.

Open Permission Audit