{
  "benchmarkId": "CG-BENCHMARK-AGENT-RUNTIME-GATE-0.7.0",
  "claimBoundary": "CapitalGuard Enforced Mode 0.7 controls host-file access, host commands, outbound network access, MCP calls, and agent handoffs originating inside a verified OCI session by removing ambient host authority and routing authenticated, task-bound broker operations through a manifest-bound, full-hash Workspace Integrity check before authority release, host-derived Context Provenance, Sensitive Egress Gate, owner-signed Data Boundary Firewall, transformed-request reauthorization, Runtime Sequence Firewall, Agent Action Gateway, and Agent Change Gate. File writes are blocked without a manifest-bound Agent Change policy; configured writes become signed candidates outside the repository and require exact, expiring, one-use reviewer approval before a separate apply operation. Operations outside that broker, writes after an integrity check, explicitly ignored workspace paths, arbitrary semantic intent, unlabeled confidential prose, code correctness, application-semantic preservation after masking, host or OCI compromise, stolen authority keys, and hardware attestation remain outside its authority; rollback detection depends on retained broker, workspace, and change-state anchors.",
  "executionOrder": [
    "synthetic fixture",
    "policy-filtered projection",
    "signed session",
    "OCI launch contract",
    "authenticated broker",
    "host-derived Context Provenance",
    "Runtime Sequence Firewall",
    "Agent Action Gateway",
    "privacy check",
    "OWASP Agentic Top 10 evidence crosswalk"
  ],
  "frameworkReference": {
    "id": "OWASP-AGENTIC-TOP-10-2026",
    "title": "OWASP Top 10 for Agentic Applications 2026",
    "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/"
  },
  "frameworkStatement": "The crosswalk identifies which synthetic cases produce evidence relevant to an OWASP Agentic risk area. It does not claim complete category coverage, OWASP endorsement, certification, or absence of vulnerabilities.",
  "kernelAttestation": "not_performed_by_publisher_benchmark",
  "reproducibility": {
    "command": "node scripts/run-enforced-mode-benchmark.mjs",
    "publicContract": "/gateway/v0.7.0/support-matrix.json"
  },
  "resultRule": "A case passes only when the observed contract, trust-chain, broker, or gateway result equals the declared expectation.",
  "version": "0.7.0"
}
