{"dataset":"DN Agent Trust / Agent Runtime Evidence Dataset","version":"0.1","riskGraphVersion":"1.6","evaluatedAt":"2026-10-11T13:08:07.635Z","scope":"Five-system financial-agent evidence cohort; not a general managed-runtime portability or performance benchmark.","methodologyUrl":"https://decentralised.news/agent-trust/methodology","policy":"Alphabetical comparison, not a safety ranking. Evidence confidence is DN's assessment score, not a probability of safety or measured coverage. Test counts and control counts are not comparable assurance scores. A passing feed does not confer or upgrade an exposure class. Missing, stale and failed observations remain visible. No production certification.","rows":[{"systemId":"almanak","systemName":"Almanak","operator":"Almanak","exposureClass":"E3","exposureClassStatus":"provisional","evidenceMode":"fork-onchain-open-position-executed","evidenceConfidence":99.8,"verifiedControlCount":62,"surveillanceState":"current-pass","profileUrl":"https://decentralised.news/agent-trust/almanak","manifestUrl":"/data/agent-risk-graph/surveillance/almanak/manifest.json","limitations":"scheduled surveillance currently re-tests the pinned upstream commit; upstream-version advancement remains a separate controlled update","nextTests":["live-adapter completeness for aggregate exposure context","per-principal or scoped gateway authorization","token rotation and secret compromise recovery","Safe owner rotation or multisig recovery boundary","production-mainnet observation without privileged fund movement"],"feeds":[{"key":"allocationLimits","endpoint":"/data/agent-risk-graph/surveillance/almanak/latest/allocation-limits.json","cadence":"weekly","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"allocation-limits","observedAt":"2026-10-11T09:42:06.284575+00:00","status":"pass","benchmark":"DN Almanak Allocation Limit Enforcement","benchmarkVersion":"surveillance-1.0","evidenceLevel":"scheduled-code-executed-policy-enforcement","upstreamRepository":"almanak-co/sdk","upstreamCommit":"39cfabb780d297f5f90e2f3ee68215dfb382b5f2","dnRepositoryCommit":"7b21915ea574e0efd297d21970501cec37d50776","githubRunId":"38129184681","assertions":{"single-trade cap":true,"daily spend cap":true,"position-size cap":true,"price-aware notional":true,"unpriced exposure fail-closed":true,"human approval threshold":true,"drawdown stop-loss":true},"controls":{},"boundaryFinding":{},"limitations":["Scheduled code-executed surveillance against the pinned Almanak upstream commit.","A failure triggers E3 review but may still require diagnosis of environment/setup causes.","This is not a production penetration test or certification."],"sourceArtifact":"allocation-limits.json"}},{"key":"crossProtocolExposure","endpoint":"/data/agent-risk-graph/surveillance/almanak/latest/cross-protocol-exposure.json","cadence":"weekly","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"cross-protocol-exposure","observedAt":"2026-10-11T09:42:06.284575+00:00","status":"pass","benchmark":"DN Almanak Cross-Protocol Aggregate Exposure","benchmarkVersion":"surveillance-1.0","evidenceLevel":"scheduled-code-executed-aggregate-exposure-enforcement","upstreamRepository":"almanak-co/sdk","upstreamCommit":"39cfabb780d297f5f90e2f3ee68215dfb382b5f2","dnRepositoryCommit":"7b21915ea574e0efd297d21970501cec37d50776","githubRunId":"38129184681","assertions":{"total exposure ceiling":true,"per-chain ceiling":true,"concentration ceiling":true,"in-flight exposure inclusion":true,"bridge in-flight exposure":true,"multi-protocol weighted risk":true,"aggregate debt-over-collateral":true},"controls":{},"boundaryFinding":{},"limitations":["Scheduled code-executed surveillance against the pinned Almanak upstream commit.","A failure triggers E3 review but may still require diagnosis of environment/setup causes.","This is not a production penetration test or certification."],"sourceArtifact":"cross-protocol-exposure.json"}},{"key":"gatewayAuthorization","endpoint":"/data/agent-risk-graph/surveillance/almanak/latest/gateway-authorization.json","cadence":"weekly","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"gateway-authorization","observedAt":"2026-10-11T09:42:06.284575+00:00","status":"pass","benchmark":"DN Almanak Gateway Authorization Boundary","benchmarkVersion":"surveillance-1.0","evidenceLevel":"scheduled-code-executed-gateway-auth-boundary","upstreamRepository":"almanak-co/sdk","upstreamCommit":"39cfabb780d297f5f90e2f3ee68215dfb382b5f2","dnRepositoryCommit":"7b21915ea574e0efd297d21970501cec37d50776","githubRunId":"38129184681","assertions":{"valid token allowed":true,"missing token rejected":true,"invalid token rejected":true,"ExecutionService.Execute authenticated":true,"secure startup fail-closed":true,"hosted mode authentication required":true,"constant-time comparison":true,"auth-failure throttling":true},"controls":{},"boundaryFinding":{},"limitations":["Scheduled code-executed surveillance against the pinned Almanak upstream commit.","A failure triggers E3 review but may still require diagnosis of environment/setup causes.","This is not a production penetration test or certification."],"sourceArtifact":"gateway-authorization.json"}},{"key":"signerRecovery","endpoint":"/data/agent-risk-graph/surveillance/almanak/latest/signer-recovery.json","cadence":"monthly-deep-assurance","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"signer-recovery","observedAt":"2026-10-11T09:41:12.514695+00:00","status":"pass","benchmark":"DN Almanak Signer Compromise & Recovery Boundary","benchmarkVersion":"deep-surveillance-1.0","evidenceLevel":"scheduled-fork-onchain-signer-recovery","upstreamRepository":"almanak-co/sdk","upstreamCommit":"39cfabb780d297f5f90e2f3ee68215dfb382b5f2","dnRepositoryCommit":"7b21915ea574e0efd297d21970501cec37d50776","githubRunId":"38129184610","assertions":{"signerRecoveryBenchmarkCompleted":true,"forkResolutionCompleted":true,"localForkStarted":true},"controls":{},"boundaryFinding":{},"limitations":["Scheduled managed-fork surveillance rather than production-mainnet execution.","Public RPC availability can create environment failures requiring diagnosis.","A failure places the relevant E3 evidence under review but is not automatically treated as a product-security defect."],"sourceArtifact":"signer-recovery.json"}},{"key":"openPositionContainment","endpoint":"/data/agent-risk-graph/surveillance/almanak/latest/open-position-containment.json","cadence":"monthly-deep-assurance","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"open-position-containment","observedAt":"2026-10-11T09:41:12.514695+00:00","status":"pass","benchmark":"DN Almanak Open Position Containment","benchmarkVersion":"deep-surveillance-1.0","evidenceLevel":"scheduled-fork-onchain-open-position-containment","upstreamRepository":"almanak-co/sdk","upstreamCommit":"39cfabb780d297f5f90e2f3ee68215dfb382b5f2","dnRepositoryCommit":"7b21915ea574e0efd297d21970501cec37d50776","githubRunId":"38129184610","assertions":{"openPositionContainmentBenchmarkCompleted":true},"controls":{},"boundaryFinding":{},"limitations":["Scheduled managed-fork surveillance rather than production-mainnet execution.","Public RPC availability can create environment failures requiring diagnosis.","A failure places the relevant E3 evidence under review but is not automatically treated as a product-security defect."],"sourceArtifact":"open-position-containment.json"}}]},{"systemId":"coinbase-agentkit","systemName":"Coinbase AgentKit","operator":"Coinbase","exposureClass":null,"exposureClassStatus":"unclassified","evidenceMode":"code-executed-upstream-unit-boundary-tests","evidenceConfidence":78,"verifiedControlCount":7,"surveillanceState":"current-pass","profileUrl":"https://decentralised.news/agent-trust/coinbase-agentkit","manifestUrl":"/data/agent-risk-graph/surveillance/coinbase-agentkit/manifest.json","limitations":"surveillance re-tests deterministic upstream boundary suites with mocks rather than live wallet execution","nextTests":["principal or delegated-wallet revocation behavior","spend-limit or transaction-limit enforcement","compromised-key recovery","duplicate/replay protection","live tool-call reliability","production transaction containment"],"feeds":[{"key":"capabilityBoundary","endpoint":"/data/agent-risk-graph/surveillance/coinbase-agentkit/latest/capability-boundary.json","cadence":"weekly","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"capability-boundary","observedAt":"2026-10-11T08:13:11.984858+00:00","status":"pass","benchmark":"DN Coinbase AgentKit Capability Boundary Benchmark","benchmarkVersion":"1.0","evidenceLevel":"code-executed-upstream-unit-boundary-tests","upstreamRepository":"coinbase/agentkit","upstreamCommit":"2e6dbaf725b9ec5f3b53003278100b0e655c214d","dnRepositoryCommit":"0edd16b1b00bd7159610d994b024de394051177b","githubRunId":"38123980679","assertions":{"protocolFamilyCapabilityGateExercised":true,"unsupportedNetworkFailurePathExercised":true,"invalidAddressSchemaRejectionExercised":true,"unknownTokenFailurePathExercised":true,"transactionFailurePropagationExercised":true,"walletSignerSurfaceExercised":true},"controls":{},"boundaryFinding":{},"limitations":["Uses upstream deterministic unit tests with mocks rather than live wallet execution.","Does not prove principal revocation, spend limits, compromised-key recovery or production custody security.","Does not justify a DN Machine Exposure Class by itself."],"sourceArtifact":"result.json"}}]},{"systemId":"definitive-flash","systemName":"Definitive Flash","operator":"Definitive","exposureClass":null,"exposureClassStatus":"unclassified","evidenceMode":"code-executed-upstream-signed-execution-boundary-tests","evidenceConfidence":88,"verifiedControlCount":9,"surveillanceState":"current-pass","profileUrl":"https://decentralised.news/agent-trust/definitive-flash","manifestUrl":"/data/agent-risk-graph/surveillance/definitive-flash/manifest.json","limitations":"surveillance re-tests deterministic upstream signed-execution suites and fake-client reconciliation rather than live trading or production API authorization","nextTests":["production API authorization boundary","wallet signer/revocation behavior","spend-limit or notional-limit enforcement","cancel/revoke latency","duplicate-order protection under delayed reconciliation","execution-state reconciliation against live API","live MCP schema stability"],"feeds":[{"key":"signedExecutionSafety","endpoint":"/data/agent-risk-graph/surveillance/definitive-flash/latest/signed-execution-safety.json","cadence":"weekly","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"signed-execution-safety","observedAt":"2026-10-11T08:13:44.914751+00:00","status":"pass","benchmark":"DN Definitive Flash Signed Execution Safety Benchmark","benchmarkVersion":"1.0","evidenceLevel":"code-executed-upstream-signed-execution-boundary-tests","upstreamRepository":"DefinitiveCo/flash-mcp","upstreamCommit":"25064e2ce10dc7d22f9ddf128c7164ec6eaddfcf","dnRepositoryCommit":"0edd16b1b00bd7159610d994b024de394051177b","githubRunId":"38123980742","assertions":{"requiredSignedOrderFieldsValidated":true,"evmAndSvmFieldFamiliesSeparated":true,"permit2TypedDataAndSignaturePaired":true,"crossChainRecipientAndBridgeQuoteRequired":true,"privateKeyExcludedFromExternalSignedSubmit":true,"ambiguousSubmitReconciliationExercised":true,"duplicateRetryWarningExercised":true,"marketTerminalPollingExercised":true,"nativeAssetNormalizationExercised":true},"controls":{},"boundaryFinding":{},"limitations":["Uses deterministic upstream tests and fake clients rather than live trading.","The pinned upstream commit has a package.json override not reflected in bun.lock, so dependencies are installed from the pinned manifest with --no-save and metadata mutation is rejected.","Does not prove production API authorization, wallet custody, principal revocation, spend limits, cancel latency or backend venue behavior.","Does not justify a DN Machine Exposure Class by itself."],"sourceArtifact":"result.json"}}]},{"systemId":"liquid-coinvest","systemName":"Liquid Co-Invest / Co-Invest Computer","operator":"Liquid","exposureClass":null,"exposureClassStatus":"unclassified","evidenceMode":"code-executed-upstream-mcp-authorization-and-idempotency-tests","evidenceConfidence":88,"verifiedControlCount":8,"surveillanceState":"current-pass","profileUrl":"https://decentralised.news/agent-trust/liquid-coinvest","manifestUrl":"/data/agent-risk-graph/surveillance/liquid-coinvest/manifest.json","limitations":"surveillance re-tests the public local MCP client and mocked HTTP boundary rather than Liquid's private backend or live order execution","nextTests":["backend idempotency enforcement under retry","live order submission reconciliation","cancel/close behavior","position/notional limit enforcement","token revocation latency","production read-only enforcement","backend authorization scope","live error recovery"],"feeds":[{"key":"mcpAuthorizationSafety","endpoint":"/data/agent-risk-graph/surveillance/liquid-coinvest/latest/mcp-authorization-safety.json","cadence":"weekly","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"mcp-authorization-safety","observedAt":"2026-10-11T08:58:27.024942+00:00","status":"pass","benchmark":"DN Liquid Co-Invest MCP Authorization & Duplicate-Order Safety Benchmark","benchmarkVersion":"1.0","evidenceLevel":"code-executed-upstream-mcp-authorization-and-idempotency-tests","upstreamRepository":"liquid-public/coinvest-mcp","upstreamCommit":"98d7f7744152f17dc1e4ecf81e67e71da2fc14aa","dnRepositoryCommit":"eaf7a4c84860dbb0e491cc69d008d9e3342fe59b","githubRunId":"38126685667","assertions":{"readOnlyWriteSuppressionExercised":true,"writeCapabilityClassificationExercised":true,"perWriteIdempotencyKeyExercised":true,"readCallsExcludeIdempotencyKeyExercised":true,"mcpTokenAuthorizationPropagationExercised":true,"httpFailureSurfacingExercised":true,"catalogFilteringExercised":true},"controls":{},"boundaryFinding":{},"limitations":["Tests the public local MCP client and mocked HTTP boundary, not Liquid's private backend implementation.","A client-generated idempotency key does not by itself prove backend duplicate-order prevention.","Does not prove live position limits, margin controls, cancel/close behavior, token revocation latency, server-side invariant enforcement or liveness rescue.","Does not justify a DN Machine Exposure Class by itself."],"sourceArtifact":"result.json"}}]},{"systemId":"virtuals-economyos-acp","systemName":"Virtuals EconomyOS / ACP","operator":"Virtuals Protocol","exposureClass":null,"exposureClassStatus":"unclassified","evidenceMode":"code-executed-upstream-commerce-state-and-payment-integrity-tests","evidenceConfidence":92,"verifiedControlCount":9,"surveillanceState":"current-pass","profileUrl":"https://decentralised.news/agent-trust/virtuals-economyos-acp","manifestUrl":"/data/agent-risk-graph/surveillance/virtuals-economyos-acp/manifest.json","limitations":"surveillance re-tests deterministic upstream commerce-state and payment-integrity unit suites rather than live escrow, production settlement, dispute adjudication or wallet authorization","nextTests":["live escrow funding and release lifecycle","buyer/provider dispute transition behavior","production wallet authorization boundary","principal or delegated-wallet revocation","x402 replay/duplicate payment protection","smart-wallet recovery","live backend availability and job reconciliation"],"feeds":[{"key":"commerceStateIntegrity","endpoint":"/data/agent-risk-graph/surveillance/virtuals-economyos-acp/latest/commerce-state-integrity.json","cadence":"weekly","state":"current-pass","observation":{"surveillanceSchemaVersion":"1.0","benchmarkKey":"commerce-state-integrity","observedAt":"2026-10-11T08:29:26.123467+00:00","status":"pass","benchmark":"DN Virtuals ACP Commerce State & Payment Integrity Benchmark","benchmarkVersion":"1.0","evidenceLevel":"code-executed-upstream-commerce-state-and-payment-integrity-tests","upstreamRepository":"Virtual-Protocol/acp-python","upstreamCommit":"398241f6f132129b41cfadb20b3401a4f968b596","dnRepositoryCommit":"874db50c6e4b6db272482753c3c24f9fd4c442f8","githubRunId":"38124952695","assertions":{"negotiationAcceptancePhaseGateExercised":true,"transactionDeliveryPhaseGateExercised":true,"evaluationCompletionGateExercised":true,"x402PaymentStructureExercised":true,"x402NonceRequirementExercised":true,"x402FailureHandlingExercised":true,"entityBoundSignaturePackingExercised":true,"jobEventIdentityReconciliationExercised":true},"controls":{},"boundaryFinding":{},"limitations":["Uses deterministic upstream unit tests and mocks rather than live escrow or production settlement.","Does not prove production wallet authorization, principal revocation, dispute enforcement, smart-wallet recovery or backend availability.","Does not justify a DN Machine Exposure Class by itself."],"sourceArtifact":"result.json"}}]}]}