Version history

No silent rewrites.

Material source, interpretation, score, benchmark, and schema changes are recorded here by dataset version.

v1.5.0

2026-07-30

AI-agent intent conformance evidence release

Published fifteen deterministic signed-plan, approval, actor, expiry, step-order, target-binding, replay, and uncertain-outcome cases.

Ran every case through CapitalGuard Agent Intent Firewall 0.1.0 with fixed synthetic requests and inert downstream callbacks.

Verified that all eleven declared pre-action violations reached the downstream callback zero times and both replay tests admitted exactly one action.

Added a dependency-free verifier for fixture signatures, fixture and result bindings, declared outcomes, and the deterministic run digest.

Documented that the benchmark does not infer semantic intent, assess every goal-hijacking path, inspect customer systems, compare vendors, independently attest execution, or guarantee security.

v1.4.0

2026-07-29

AI-agent delegation boundary evidence release

Published twelve deterministic signed delegation, authority attenuation, actor, policy, parent, expiry, depth, and single-use cases.

Ran every case through CapitalGuard Delegation Firewall 0.1.0 with fixed synthetic fixtures and no external agent or network execution.

Added sequential and concurrent double-consume tests that each admit exactly one request.

Added a dependency-free verifier for public envelope signatures, fixture bindings, declared outcomes, replay counts, and run digest.

Documented that the benchmark does not assess customer systems, compare vendors, independently attest execution, control bypass paths, or guarantee security.

v1.3.0

2026-07-28

MCP tool integrity evidence release

Published eight deterministic MCP identity, tool-definition, schema, approval, replay, quarantine, and response-boundary cases.

Ran the synthetic cases through the real CapitalGuard MCP Integrity Gate with provider-invocation and privacy checks.

Added a dependency-free verifier for the fixed registry, declared scenarios, observed outcomes, privacy flags, and deterministic run digest.

Added a five-step MCP security guide and blank JSON/CSV review register backed by current primary sources.

Documented that the benchmark does not inspect a vendor product, live MCP server, customer environment, exploit, or model susceptibility.

v1.2.0

2026-07-27

AI-agent permission drift evidence release

Published one signed synthetic baseline-to-candidate permission comparison with 36 observed changes across ten classifications.

Published eleven decision, integrity, binding, and privacy cases with all declared outcomes reproduced.

Added a dependency-free verifier for release hashes, Ed25519 receipt integrity, and cross-artifact bindings.

Added a five-step permission audit and blank JSON/CSV access register backed by current primary sources.

Documented that the benchmark does not inspect customer environments, vendor runtime behavior, exploitability, or protection outcomes.

v1.1.0

2026-07-16

Repository exposure benchmark release

Replaced marker-only fixture checks with a real CapitalGuard 1.3.0 scanner run inside a disposable synthetic repository.

Published six case-level results for secret-like paths, untrusted instructions, workflow authority, customer exports, MCP bridges, and package lifecycle scripts.

Verified that zero synthetic marker values appeared across six emitted evidence artifacts.

Added a reconstructable fixture pack, JSON and CSV results, SHA-256 run digest, and release-file manifest.

Documented the benchmark boundary: no vendor product, exploit, network action, or customer repository was executed.

v1.0.0

2026-07-13

Initial public Observatory release

Published ten AI-tool and protocol records with source-level citations.

Released the five-dimension CapitalGuard Public-Control Score and claim boundary.

Added six CVE records, one material platform security change, and one primary research signal.

Published six non-destructive synthetic repository test vectors mapped to CapitalGuard Standard 1.0.0.

Added machine-readable JSON and CSV exports plus daily official-source change detection.

Inspect the current release in human or machine-readable form.