Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
64 changes: 64 additions & 0 deletions .github/workflows/probityai-observed-effect-conformance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
# Observed-effect references workflow.
#
# floating installs the latest released agentrust-trace, unpinned on purpose,
# as drift detection.
# fixed installs the agentrust-trace version named in integration.yaml
# tested_against, so that claim cannot move underneath itself.
# Both replay the published vectors-observed-effect corpus pinned to one release.
# This integration is an external-evidence-source and asserts no TRACE level.
name: probityai-observed-effect conformance
on:
push:
paths:
- "integrations/probityai-observed-effect/**"
- ".github/workflows/probityai-observed-effect-conformance.yml"
pull_request:
paths:
- "integrations/probityai-observed-effect/**"
- ".github/workflows/probityai-observed-effect-conformance.yml"
schedule:
- cron: "0 6 * * 1" # weekly: catch drift against the latest released packages
workflow_dispatch:

permissions:
contents: read

jobs:
check:
name: ${{ matrix.mode }} (py${{ matrix.python }})
strategy:
fail-fast: false
matrix:
python: ["3.11", "3.12", "3.13", "3.14"]
mode: [floating, fixed]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: ${{ matrix.python }}
- name: Install agentrust-trace (latest release)
if: matrix.mode == 'floating'
run: pip install agentrust-trace
- name: Install agentrust-trace (tested_against)
if: matrix.mode == 'fixed'
run: |
v=$(sed -n 's/^ agentrust-trace: "\(.*\)"$/\1/p' integrations/probityai-observed-effect/integration.yaml)
test -n "$v"
pip install "agentrust-trace==$v"
- name: Install this integration
run: pip install -e "integrations/probityai-observed-effect[test]"
- name: Integration tests
run: pytest integrations/probityai-observed-effect/tests -q
# The corpus runner requires Python 3.13 or later, so it runs in its own
# interpreter and the replay happens on every matrix leg.
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
id: replay-python
with:
python-version: "3.13"
update-environment: false
- name: Replay the published observed-effect corpus
run: |
"${{ steps.replay-python.outputs.python-path }}" -m venv "$RUNNER_TEMP/replay"
"$RUNNER_TEMP/replay/bin/pip" install "agent-evidence-vectors==0.15.0"
"$RUNNER_TEMP/replay/bin/agent-evidence-vectors" --corpus vectors-observed-effect
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,7 @@ TRACE only works as a standard if it is genuinely neutral. Integrations are list
| [OpenAI Agents SDK](integrations/openai-agents/) | agentrust-io | trace | verified |
| [OpenShell TRACE Adapter](integrations/openshell/) | agentrust-io | trace | community |
| [OpenTelemetry GenAI](integrations/otel-genai/) | agentrust-io | trace | community |
| [Observed-effect references](integrations/probityai-observed-effect/) | probityai | trace | community |
| [ramen-ai cMCP Adapter](integrations/ramen-ai-cmcp/) | ramen-ai | cmcp, trace | verified |
| [SAGE AgenTrust Bridge](integrations/sage-agenttrust/) | SAGE | cmcp, trace | community |
| [Agent Sentinel](integrations/sentinel/) | a1k7 | trace | community |
Expand Down
21 changes: 21 additions & 0 deletions integrations/probityai-observed-effect/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Observed-effect references

A TRACE Trust Record says what an agent was and what it ran under. This integration adds what an observer outside the agent saw change while it ran: each record carries one `references` entry with `rel: "observed-effect"`, and the entry's `digest` pins an in-toto statement the observer signed over the state before and after the interval.

## What it does

- `examples/` holds five signed Trust Records and the effect store their references resolve against. The two observer statements in `examples/source/` are copied byte for byte from [vectors-observed-effect at v0.15.0](https://github.com/probityai/agent-evidence-vectors/tree/v0.15.0/vectors-observed-effect); everything else regenerates from one published seed.
- `tests/` verifies every record with released `agentrust-trace`, then recomputes the relying party's verdict for each case from the committed bytes: verified, digest mismatch, unresolved, and observer key not configured.
- CI also replays the whole published corpus the statements come from, pinned to one release.

## Run it

```
pip install -e "integrations/probityai-observed-effect[test]"
python -m pytest integrations/probityai-observed-effect/tests
uvx agent-evidence-vectors==0.15.0 --corpus vectors-observed-effect
```

## What it does NOT claim

A verified reference establishes that the resolved bytes are the cited bytes and that the named observer signed them. It does not establish that the change the statement reports occurred, and it never changes whether the Trust Record itself verifies (trace-v0.2 section 3.1.2 rule 3). The `observed-effect` value is proposed for the references registry in [trace-spec#403](https://github.com/agentrust-io/trace-spec/pull/403) and is not registered yet; the v0.2 schema leaves `rel` open. No TRACE conformance level is claimed.
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
{
"eat_profile": "tag:agentrust-io.com,2026:trace-v0.2",
"iat": 1789776010,
"subject": "spiffe://trust.example.org/agent/build-bot",
"model": {
"provider": "example",
"model_id": "example-model"
},
"runtime": {
"platform": "software-only",
"measurement": "sha256:0000000000000000000000000000000000000000000000000000000000000000"
},
"policy": {
"bundle_hash": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"enforcement_mode": "enforce"
},
"data_class": "internal",
"build_provenance": {
"slsa_level": 1,
"digest": "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
},
"appraisal": {
"status": "none",
"verifier": "https://verifier.example.org"
},
"cnf": {
"jwk": {
"kty": "OKP",
"crv": "Ed25519",
"x": "ysSfGiHZFwj77FqkuI2D7bc9K0sNHVbPcoDjroN3aeA"
}
},
"references": [
{
"rel": "observed-effect",
"id": "interval/1",
"resolver": "https://observer.example.org/intervals",
"digest": "sha256:00bd35730a2e8fa462a5fbf0a30aac71302fdbd02b5217d6c3950a66531a9121",
"retention": "P1Y"
}
],
"signature": "QieV5TjRrAypQcw-2fNAUxvtnYj2PKBH54SjK2WOlP4fF-4AwbuGtwnRar9WUsdZgcAR5TlWtSSsuYFN_WK8Ag"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
{
"eat_profile": "tag:agentrust-io.com,2026:trace-v0.2",
"iat": 1789776010,
"subject": "spiffe://trust.example.org/agent/build-bot",
"model": {
"provider": "example",
"model_id": "example-model"
},
"runtime": {
"platform": "software-only",
"measurement": "sha256:0000000000000000000000000000000000000000000000000000000000000000"
},
"policy": {
"bundle_hash": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"enforcement_mode": "enforce"
},
"data_class": "internal",
"build_provenance": {
"slsa_level": 1,
"digest": "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
},
"appraisal": {
"status": "none",
"verifier": "https://verifier.example.org"
},
"cnf": {
"jwk": {
"kty": "OKP",
"crv": "Ed25519",
"x": "ysSfGiHZFwj77FqkuI2D7bc9K0sNHVbPcoDjroN3aeA"
}
},
"references": [
{
"rel": "observed-effect",
"id": "interval/2",
"resolver": "https://observer.example.org/intervals",
"digest": "sha256:69aab598cc1ea76cce6325742406dc7db49640527d686348a9e73353894dd3f8",
"retention": "P1Y"
}
],
"signature": "hgIkXMRuWkIzc3DS-da6CfurMNDQtoxLaTSYoeZii3gOTdPUaWG0b3Cr2U-9UckF7ChOxwXWwMXzCyMKAqHABA"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
{
"eat_profile": "tag:agentrust-io.com,2026:trace-v0.2",
"iat": 1789776010,
"subject": "spiffe://trust.example.org/agent/build-bot",
"model": {
"provider": "example",
"model_id": "example-model"
},
"runtime": {
"platform": "software-only",
"measurement": "sha256:0000000000000000000000000000000000000000000000000000000000000000"
},
"policy": {
"bundle_hash": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"enforcement_mode": "enforce"
},
"data_class": "internal",
"build_provenance": {
"slsa_level": 1,
"digest": "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
},
"appraisal": {
"status": "none",
"verifier": "https://verifier.example.org"
},
"cnf": {
"jwk": {
"kty": "OKP",
"crv": "Ed25519",
"x": "ysSfGiHZFwj77FqkuI2D7bc9K0sNHVbPcoDjroN3aeA"
}
},
"references": [
{
"rel": "observed-effect",
"id": "interval/2",
"resolver": "https://observer.example.org/intervals",
"digest": "sha256:69aab598cc1ea76cce6325742406dc7db49640527d686348a9e73353894dd3f8",
"retention": "P1Y"
}
],
"signature": "hgIkXMRuWkIzc3DS-da6CfurMNDQtoxLaTSYoeZii3gOTdPUaWG0b3Cr2U-9UckF7ChOxwXWwMXzCyMKAqHABA"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
{
"eat_profile": "tag:agentrust-io.com,2026:trace-v0.2",
"iat": 1789776010,
"subject": "spiffe://trust.example.org/agent/build-bot",
"model": {
"provider": "example",
"model_id": "example-model"
},
"runtime": {
"platform": "software-only",
"measurement": "sha256:0000000000000000000000000000000000000000000000000000000000000000"
},
"policy": {
"bundle_hash": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"enforcement_mode": "enforce"
},
"data_class": "internal",
"build_provenance": {
"slsa_level": 1,
"digest": "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
},
"appraisal": {
"status": "none",
"verifier": "https://verifier.example.org"
},
"cnf": {
"jwk": {
"kty": "OKP",
"crv": "Ed25519",
"x": "ysSfGiHZFwj77FqkuI2D7bc9K0sNHVbPcoDjroN3aeA"
}
},
"references": [
{
"rel": "observed-effect",
"id": "interval/9",
"resolver": "https://observer.example.org/intervals",
"digest": "sha256:5bff9cfbe71b95959bf6a22101688acb936c00323399089f0cb9b93255fbc874",
"retention": "P1Y"
}
],
"signature": "JAOx0cH1jIw0KBUrArsmOT-Evlx0dgWQzsJgi-on-0wfGLLqXgSVGWpsg-Z1e53eyHJi2szlp0OeThLrPlFgDQ"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
{
"eat_profile": "tag:agentrust-io.com,2026:trace-v0.2",
"iat": 1789776010,
"subject": "spiffe://trust.example.org/agent/build-bot",
"model": {
"provider": "example",
"model_id": "example-model"
},
"runtime": {
"platform": "software-only",
"measurement": "sha256:0000000000000000000000000000000000000000000000000000000000000000"
},
"policy": {
"bundle_hash": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
"enforcement_mode": "enforce"
},
"data_class": "internal",
"build_provenance": {
"slsa_level": 1,
"digest": "sha256:eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee"
},
"appraisal": {
"status": "none",
"verifier": "https://verifier.example.org"
},
"cnf": {
"jwk": {
"kty": "OKP",
"crv": "Ed25519",
"x": "ysSfGiHZFwj77FqkuI2D7bc9K0sNHVbPcoDjroN3aeA"
}
},
"references": [
{
"rel": "observed-effect",
"id": "interval/3",
"resolver": "https://observer.example.org/intervals",
"digest": "sha256:dcfe876e7184675bd9877675a6841292c3802d150b8c5550041be2e05cdf8f13",
"retention": "P1Y"
}
],
"signature": "flpGZJRQ9Hf_EtszJyklnCwhe_bZaqauIbQoO3MRQ4OY6W_SBVdPzvsoGACDLWHQhhJgIDNfCMM5hgdA0Wy4BQ"
}
Loading
Loading