{
  "claimBoundary": "CapitalGuard Secretless Execution Broker 0.1 keeps configured provider credentials encrypted outside the repository and agent runtime, accepts only independently signed one-use capabilities bound to an exact provider route and request digest, atomically reserves use before host-side credential injection, rejects direct credential reflection in raw, authentication-prefixed, URL-encoded, base64, and decoded JSON form, projects only configured response fields, and emits privacy-reduced signed evidence. It protects only requests routed through the broker and does not resist host, vault-key, signing-authority, provider, operating-system trust-store, or trusted-transport compromise; infer semantic intent; rotate provider credentials; prove provider behavior; inspect bypassed requests; detect arbitrary transformed or fragmented credential echoes; or automatically reconcile uncertain dispatch outcomes. Rollback detection depends on a separately retained authenticated anchor.",
  "digestAlgorithm": "SHA-256",
  "id": "CG-SECRETLESS-EXECUTION-BROKER-0.1.0-RELEASE",
  "licensedArtifacts": [
    {
      "bytes": 226180,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-secretless-execution-broker.cjs",
      "id": "secretless-execution-broker-library",
      "sha256": "bdc7a194b0f3710063cf8e41ccf6978a04e78d4044bbc6a268fb62ccbb2dc531"
    },
    {
      "bytes": 144206,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-secretless-execution-broker-cli.cjs",
      "id": "secretless-execution-broker-cli",
      "sha256": "2836ac7141961ed939526a8357968454d9bf735e6e2a4898afe087d678ccf52f"
    },
    {
      "bytes": 8303,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-secretless-execution-broker-guide.md",
      "id": "secretless-execution-broker-guide",
      "sha256": "e8061875058d1c32c4322f239ce7047263e95709ca918c777dcf621ea847464c"
    }
  ],
  "publicArtifacts": [
    {
      "bytes": 2316,
      "filename": "anchor.schema.json",
      "sha256": "7cab2905b4f5c8851e5e11b4be43182ee9c744285119755268ebc1cc1755bf3f"
    },
    {
      "bytes": 5082,
      "filename": "capability.schema.json",
      "sha256": "96ebbd70a6b8cb2a56d3d7de17684b1491fee26c263101a77fd239c4822c3eb8"
    },
    {
      "bytes": 3752,
      "filename": "invocation-evidence.schema.json",
      "sha256": "39b18640d1a484dc759ee15b3e0fc3043f35460c33a4f9e08cfdab21652e6910"
    },
    {
      "bytes": 4267,
      "filename": "methodology.json",
      "sha256": "3f2a2a5aa157d198b63c2e235374765579e083b6ac7e83b8efcb2a1877543b6c"
    },
    {
      "bytes": 11004,
      "filename": "provider-registry.schema.json",
      "sha256": "7df39885048722de3f57aa2b755a743359e7166a517e0f770fb9f0fa0b31b0cd"
    },
    {
      "bytes": 6309,
      "filename": "receipt.schema.json",
      "sha256": "87deb54e25517c21a5ae41af4f97363e2ccd9016c72e074337d8172a26bf3c7e"
    },
    {
      "bytes": 2096,
      "filename": "request.schema.json",
      "sha256": "d06259ac899b9da5c1a4eb44433f45d06f33ae251c22a00311459532c85f820a"
    },
    {
      "bytes": 7220,
      "filename": "state.schema.json",
      "sha256": "7ccfc1c00811bdd06da7c72cc5bb7b67d10dddd610d9ece8574ac6720e06c33e"
    },
    {
      "bytes": 4932,
      "filename": "support-matrix.json",
      "sha256": "f1fc6dc0da4ee5a19c60f592a307e9ca9c9fd70f621e69c994c6ec076e9df64d"
    },
    {
      "bytes": 3557,
      "filename": "test-vectors.json",
      "sha256": "c70a14fa6e2e063d8951494dc44938a2d06950d7cefec45735e55aa82849905c"
    },
    {
      "bytes": 3066,
      "filename": "threat-model.json",
      "sha256": "0d449794e0a15cd751fb5174f5a48ee159dc064e6869fc20e49dd0f87534cb70"
    },
    {
      "bytes": 2286,
      "filename": "vault-record.schema.json",
      "sha256": "01cdbb9e86b0534fc5480e06000852f388afadccabf8c88e3294bca10a64aa31"
    }
  ],
  "releaseDigestSha256": "aad6de37ceafd7ab664d508bd54d81e49810140d8c8d83f42a70ac520d22f665",
  "releasedAt": "2026-07-19T23:30:00.000Z",
  "runtimeStackClaimBoundary": "CapitalGuard Secretless Runtime Stack 0.1 exposes the Secretless Execution Broker only through owned Agent Intent or Enforced Mode adapter callbacks, binds the closed MCP argument digest to the broker request, and binds signed intent evidence to secretless receipts when using the direct intent stack. The Enforced Mode adapter proves only that the authenticated MCP adapter was invoked; its nested secretless receipt separately records whether the provider was dispatched. CapitalGuard Secretless Execution Broker 0.1 keeps configured provider credentials encrypted outside the repository and agent runtime, accepts only independently signed one-use capabilities bound to an exact provider route and request digest, atomically reserves use before host-side credential injection, rejects direct credential reflection in raw, authentication-prefixed, URL-encoded, base64, and decoded JSON form, projects only configured response fields, and emits privacy-reduced signed evidence. It protects only requests routed through the broker and does not resist host, vault-key, signing-authority, provider, operating-system trust-store, or trusted-transport compromise; infer semantic intent; rotate provider credentials; prove provider behavior; inspect bypassed requests; detect arbitrary transformed or fragmented credential echoes; or automatically reconcile uncertain dispatch outcomes. Rollback detection depends on a separately retained authenticated anchor.",
  "runtimeStackVersion": "0.1.0",
  "status": "stable",
  "version": "0.1.0"
}
