{
  "dataset": "DN Agent Risk Graph Public Systems Dataset",
  "version": "1.3",
  "publishedAt": "2026-10-10",
  "methodology": "DN Agent Risk Graph v0.1",
  "status": "multi-system-code-executed-evidence",
  "note": "v1.3 preserves Almanak provisional E3 evidence and adds DN-executed Coinbase AgentKit boundary evidence from pinned upstream tests. AgentKit remains unclassified because the test does not prove principal revocation, spend limits, compromised-key recovery, production custody security or live transaction containment.",
  "profiles": [
    {
      "systemId": "coinbase-agentkit",
      "systemName": "Coinbase AgentKit",
      "operator": "Coinbase",
      "evidenceMode": "code-executed-upstream-unit-boundary-tests",
      "evidenceConfidence": 78,
      "capabilities": [
        "autonomous payments",
        "onchain transfers",
        "swaps",
        "token launches",
        "smart-contract interactions"
      ],
      "verifiedControls": [
        "EVM protocol-family capability gate executed successfully by DN-selected upstream tests",
        "Non-EVM protocol-family rejection path executed successfully",
        "Unsupported-network token lookup failure path executed successfully",
        "Unknown-token failure path executed successfully",
        "Invalid token and spender address schema rejection executed successfully",
        "Transaction failure propagation path executed successfully",
        "Wallet-provider signer surface exercised without live keys or funds"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "principal or delegated-wallet revocation behavior",
        "spend-limit or transaction-limit enforcement",
        "compromised-key recovery",
        "duplicate/replay protection",
        "live tool-call reliability",
        "production transaction containment"
      ],
      "benchmarkObservations": [
        {
          "benchmark": "DN Coinbase AgentKit Capability Boundary Benchmark",
          "version": "1.0",
          "status": "pass",
          "evidenceLevel": "code-executed-upstream-unit-boundary-tests",
          "observedAt": "2026-10-10T21:58:42Z",
          "upstreamRepository": "coinbase/agentkit",
          "upstreamCommit": "2e6dbaf725b9ec5f3b53003278100b0e655c214d",
          "dnGithubRunId": "38089663742",
          "dnGithubRunUrl": "https://github.com/Block-Patrol/decentralised-website-frontend/actions/runs/38089663742",
          "assertions": [
            "protocol-family capability gating exercised",
            "unsupported-network failure behavior exercised",
            "invalid address schema rejection exercised",
            "unknown token failure behavior exercised",
            "transaction failure propagation exercised",
            "wallet signer surface exercised"
          ],
          "limitations": [
            "Uses upstream deterministic unit tests with mocks rather than live wallet execution.",
            "Does not prove principal revocation, spend limits, compromised-key recovery or production custody security.",
            "Does not justify a DN Machine Exposure Class by itself."
          ]
        }
      ]
    },
    {
      "systemId": "almanak",
      "systemName": "Almanak",
      "operator": "Almanak",
      "evidenceMode": "fork-onchain-open-position-executed",
      "evidenceConfidence": 99.8,
      "capabilities": [
        "autonomous DeFi strategies",
        "swap",
        "LP",
        "borrow",
        "multi-protocol execution"
      ],
      "verifiedControls": [
        "Safe smart-account architecture documented",
        "Zodiac Roles permission manifests documented and code-verifiable",
        "least-privilege permission hints present in public SDK",
        "gateway-isolated strategy architecture documented",
        "stuck detection service present in public SDK docs",
        "emergency management service present in public SDK docs",
        "teardown permission expansion executed successfully by DN",
        "address-form token permission preservation executed successfully by DN",
        "unknown symbol fail-closed behavior executed successfully by DN",
        "circuit-breaker priority executed successfully by DN",
        "emergency pause boundary and CRITICAL operator record executed successfully by DN",
        "Emergency control latency benchmark passed across 250 CI iterations",
        "Pause callback invoked in every emergency-control iteration",
        "Incomplete alerting did not produce false overall-success state",
        "Allowed target call executed successfully on an Arbitrum Anvil fork",
        "USDC allowance state updated after authorized call",
        "Target revocation executed successfully",
        "Identical call was denied after revocation with transaction status 0",
        "Leveraged GMX V2 ETH-long position opened and settled on managed Arbitrum fork",
        "Live open position measured before containment",
        "Full decrease order compiled from measured live position size",
        "Decrease order executed and settled",
        "PositionDecrease receipt measured",
        "Wallet collateral increased after containment settlement",
        "Open-position set verified empty after containment",
        "Simulated compromised Zodiac role signer exercised bounded authority before revocation",
        "Compromised role signer denied after owner-authorized membership revocation",
        "Replacement signer recovered the same bounded role",
        "Replacement signer denied on an unapproved target",
        "Signer recovery completed without widening target authority",
        "Within-limit trade accepted by PolicyEngine",
        "Over-limit single trade denied",
        "Cumulative daily spend over cap denied",
        "Over-limit position size denied",
        "Price-aware high-value trade denied",
        "Unpriced risk failed closed",
        "Human approval required above configured threshold",
        "Risk action blocked after stop-loss drawdown threshold",
        "Oversized agent action denied before CompileIntent",
        "Oversized agent action denied before gateway Execute",
        "Cached bundle revalidated against current policy before gateway Execute",
        "Tightened policy blocked stale permissive cached bundle with zero gateway Execute calls",
        "Aggregate total exposure ceiling enforced",
        "Per-chain exposure ceiling enforced",
        "Position concentration ceiling enforced",
        "In-flight exposure included in aggregate total",
        "Combined bridge and in-flight exposure ceiling enforced",
        "Multi-protocol weighted risk aggregated",
        "Aggregate debt-over-collateral risk computed",
        "Debt-only portfolio saturates to maximum risk",
        "Valid gateway auth token accepted",
        "Missing gateway auth token rejected",
        "Invalid gateway auth token rejected",
        "ExecutionService.Execute requires authentication in secure mode",
        "Gateway services require authentication except documented health/reflection bypasses",
        "Constant-time token comparison used",
        "Repeated auth failures throttled",
        "Secure gateway startup fails closed without authentication",
        "Configured auth token inserts AuthInterceptor",
        "Auth interceptor runs before audit and metrics",
        "Hosted mode forbids insecure gateway operation",
        "Hosted mode requires an auth token"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": 89,
        "treasuryReadiness": null,
        "walletSecurity": 93,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": "E3",
      "nextTests": [
        "live-adapter completeness for aggregate exposure context",
        "per-principal or scoped gateway authorization",
        "token rotation and secret compromise recovery",
        "Safe owner rotation or multisig recovery boundary",
        "production-mainnet observation without privileged fund movement"
      ],
      "benchmarkObservations": [
        {
          "benchmark": "DN Almanak Isolated Safety Benchmark",
          "version": "0.2",
          "observedAt": "2026-10-10T00:43:14.017394+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed",
          "passed": 5,
          "failed": 0,
          "total": 5,
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "cd5c1fbea674268e281a67d5769de4f8974edeea",
          "githubRunId": "38010222501",
          "artifactDigest": "sha256:50cb2b2ebb2c1cee2340ddd2f16687d731b5e47bf1667a9ece600c88c5fcf065",
          "controls": [
            "teardown_permission_expansion",
            "address_form_token_permission",
            "unknown_symbol_fail_closed",
            "circuit_breaker_priority",
            "emergency_pause_boundary"
          ],
          "limitations": [
            "No funded mainnet or fork-execution test",
            "No on-chain Zodiac denial test yet",
            "No deployed-strategy emergency-stop latency measurement yet"
          ]
        },
        {
          "benchmark": "DN Almanak Emergency Control Latency",
          "version": "0.3",
          "observedAt": "2026-10-10T01:13:38.249934+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed",
          "iterations": 250,
          "latencyMs": {
            "min": 0.447237,
            "median": 2.9138645,
            "p95": 4.9807066,
            "p99": 6.62825727,
            "max": 8.520796
          },
          "assertions": {
            "pauseCallbackInvokedEveryIteration": true,
            "pauseReportedSuccessful": true,
            "noFalseOverallSuccessWithoutAlerts": true
          },
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "55fb4e8b4ad1c6a7f5335c939f55622c2336eae4",
          "githubRunId": "38012315598",
          "artifactDigest": "sha256:6b381cdee5a348780a08615999c76258ff52bfa93141c5d152a559c264b0864a",
          "limitations": [
            "Measures in-process emergency-control latency in CI, not blockchain settlement latency",
            "No external alert transport configured",
            "No funded strategy or live market position used"
          ]
        },
        {
          "benchmark": "DN Almanak Zodiac Fork Authorization Benchmark",
          "version": "0.4",
          "observedAt": "2026-10-10T10:37:29.043248+00:00",
          "status": "pass",
          "evidenceLevel": "fork-onchain-executed",
          "chain": "arbitrum",
          "chainId": 42161,
          "forkBlock": 513488144,
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "091947f61fe46b9dbba7c2eb0e5ee266439800d4",
          "githubRunId": "38045511519",
          "artifactDigest": "sha256:fa067679675c8b724dfa59820f979ca75a9663f499b5c005f3d8bcf209a468e6",
          "assertions": {
            "allowedBeforeRevocation": true,
            "safeAllowanceUpdated": true,
            "deniedAfterRevocation": true
          },
          "latencyMs": {
            "setup": 3299.59632,
            "allowedCall": 740.743228,
            "revoke": 193.710253,
            "deniedCall": 183.28673
          },
          "limitations": [
            "Local Anvil fork only, not mainnet",
            "Tests authorization enforcement rather than full strategy economics",
            "Uses an Anvil-unlocked test account",
            "No real fund movement"
          ]
        },
        {
          "benchmark": "DN Almanak Permission Drift & Recovery Safety Benchmark",
          "version": "0.5",
          "observedAt": "2026-10-10T11:05:04.796522+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "f96d9f72acec1362f925df36b28596a41aae9b3c",
          "githubRunId": "38047129258",
          "artifactDigest": "sha256:2a55d002c9bc4db6f87a5d9d20752dacf05453659e007d252516bf12b8b2e72b",
          "permissionDrift": {
            "status": "pass",
            "v1TargetCount": 2,
            "v2TargetCount": 3,
            "staleManifestMissingNewAuthority": true
          },
          "reconciliation": {
            "status": "pass",
            "caseCount": 6
          }
        },
        {
          "benchmark": "DN Almanak RPC Receipt Observation Fault Injection",
          "version": "0.6",
          "observedAt": "2026-10-10T11:31:02.373420+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-fault-injected",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "634e64060af066aec99ef9f6b92bee46131941c4",
          "githubRunId": "38048657989",
          "artifactDigest": "sha256:4c088831b8cd6ee2a38d5977adac82b47d0386c3eed88a479359676c018b7e6b",
          "faultStagesTested": [
            "receipt_observation",
            "block_membership",
            "receipt_refetch",
            "block_recheck"
          ],
          "assertions": {
            "providerFaultInjectedAtEveryObservationStage": true,
            "sameTransactionIdentityRecovered": true,
            "canonicalReceiptReturnedOnlyAfterCompleteReobservation": true
          }
        },
        {
          "benchmark": "DN Almanak Open Position Containment",
          "version": "0.7",
          "observedAt": "2026-10-10T13:51:56.862734+00:00",
          "status": "pass",
          "evidenceLevel": "fork-onchain-open-position-executed",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "6a20fb66734320442713c5febd5d43ed9b5971d6",
          "githubRunId": "38057301311",
          "artifactDigest": "sha256:50fc857c5192d03c495eb815433ebfcf105f264523718743a77151acc99174dd",
          "chain": "arbitrum",
          "protocol": "gmx_v2",
          "scenario": "open leveraged ETH-long on managed fork, settle, measure live position, close full measured position, verify collateral return and zero remaining positions",
          "assertions": {
            "increaseOrderCompiledAndExecuted": true,
            "increaseOrderSettled": true,
            "livePositionMeasured": true,
            "fullDecreaseCompiledFromMeasuredSize": true,
            "decreaseOrderExecutedAndSettled": true,
            "positionDecreaseReceiptMeasured": true,
            "walletCollateralIncreased": true,
            "remainingPositionSetEmpty": true
          },
          "limitations": [
            "managed Anvil fork rather than production mainnet",
            "GMX V2 ETH-long scenario only",
            "keeper execution reproduced locally",
            "no real funds used"
          ]
        },
        {
          "benchmark": "DN Almanak Signer Compromise & Recovery Boundary",
          "version": "0.8",
          "observedAt": "2026-10-10T14:26:16.444870+00:00",
          "status": "pass",
          "evidenceLevel": "fork-onchain-signer-revocation-recovery",
          "chain": "arbitrum",
          "chainId": 42161,
          "forkBlock": 513538494,
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "a26d6541ab0bab859e6edb59c2c1e68daf170c05",
          "githubRunId": "38059556976",
          "artifactDigest": "sha256:286dbaf00eba47c8ae684aaf637ff371c864fe9e1addacabb46f623a7a62ae14",
          "assertions": {
            "compromisedSignerAuthorizedBeforeRevocation": true,
            "compromisedSignerDeniedAfterRevocation": true,
            "replacementSignerAuthorizedAfterRecovery": true,
            "replacementSignerDeniedOnUnapprovedTarget": true,
            "recoveryDidNotWidenTargetAuthority": true
          },
          "latencyMs": {
            "authorizedBeforeRevocation": 624.899737,
            "membershipRevocation": 192.826638,
            "revokedSignerDenial": 189.292243,
            "replacementGrant": 391.440628,
            "replacementAuthorizedCall": 199.102605,
            "negativeControlDenial": 190.038026
          },
          "limitations": [
            "local managed Anvil fork rather than production mainnet",
            "simulated compromise uses an unlocked Anvil account rather than a stolen production credential",
            "tests Zodiac role-member revocation/replacement, not Safe owner rotation or multisig recovery",
            "single approved target and one negative-control target",
            "no real funds or production key material"
          ]
        },
        {
          "benchmark": "DN Almanak Allocation Limit Enforcement",
          "version": "0.9",
          "observedAt": "2026-10-10T14:54:44.627904+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-policy-enforcement",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "a8046994fed2dde95be2ce7cd6ffc5cd6506bc16",
          "githubRunId": "38061455373",
          "artifactDigest": "sha256:d693fed7b41e76b4317aa2b6a6430452518950f8f9555df90b831674d76746a5",
          "assertions": {
            "withinSingleTradeLimitAllowed": true,
            "overSingleTradeLimitDenied": true,
            "cumulativeDailyLimitDenied": true,
            "overPositionSizeLimitDenied": true,
            "priceAwareHighValueTradeDenied": true,
            "unpricedRiskFailsClosed": true,
            "humanApprovalRequiredAboveThreshold": true,
            "stopLossBlocksRiskActionAfterDrawdown": true
          },
          "limitations": [
            "code-executed policy tests rather than funded production execution",
            "does not prove an external gateway cannot bypass PolicyEngine",
            "does not test cross-protocol aggregate exposure on live positions",
            "no real funds or production credentials"
          ]
        },
        {
          "benchmark": "DN Almanak Agent Policy Chokepoint",
          "version": "1.0",
          "observedAt": "2026-10-10T15:38:23.801812+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-agent-gateway-dispatch-instrumented",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "91b1a4ab12f06b9c47e56ec335b82e12fb872a39",
          "githubRunId": "38064391759",
          "artifactDigest": "sha256:4fd8d93e1b3d3616a8680dcf8fd2453a51097a3bc0466e46a577512c1ea19a71",
          "assertions": {
            "oversizedAgentActionDeniedBeforeCompile": true,
            "oversizedAgentActionDeniedBeforeExecute": true,
            "cachedBundleRevalidatedAgainstCurrentPolicy": true,
            "oversizedCachedBundleDeniedBeforeGatewayExecute": true
          },
          "gatewayDispatchCounts": {
            "directOversizedAction": {
              "compileIntentCalls": 0,
              "executeCalls": 0
            },
            "cachedBundlePolicyRevalidation": {
              "executeCallsAfterPolicyTightening": 0
            }
          },
          "boundaryFinding": {
            "agentFacingToolExecutorPolicyChokepoint": "verified",
            "directGatewayExecutionServicePrivilegedSeam": "not-covered-by-AgentPolicy"
          },
          "limitations": [
            "instrumented mock gateway rather than funded production execution",
            "does not prove privileged direct callers of ExecutionService.Execute are policy-gated",
            "does not test network-layer authentication or authorization on the gateway service",
            "no real funds or production credentials"
          ]
        },
        {
          "benchmark": "DN Almanak Cross-Protocol Aggregate Exposure",
          "version": "1.1",
          "observedAt": "2026-10-10T15:47:23.453765+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-aggregate-exposure-enforcement",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "386031d6e45ca33a818f88ba94d8186941e032be",
          "githubRunId": "38064992856",
          "artifactDigest": "sha256:9832d19baa3c53ff3796d844da68877538ab90e43ccf623f954c4a15d27bd16b",
          "assertions": {
            "withinAggregateExposureLimitAllowed": true,
            "totalExposureLimitDenied": true,
            "perChainExposureLimitDenied": true,
            "positionConcentrationLimitDenied": true,
            "inFlightExposureIncludedInTotalLimit": true,
            "combinedBridgeInFlightExposureDenied": true,
            "multiProtocolWeightedRiskAggregated": true,
            "multiProtocolDebtOverCollateralAggregated": true,
            "debtOnlyPortfolioSaturatesToMaximumRisk": true
          },
          "limitations": [
            "code-executed risk-guard and adapter tests rather than funded production execution",
            "does not prove all live protocol adapters feed complete exposure into the aggregate context",
            "does not test network-layer gateway authorization",
            "no real funds or production credentials"
          ]
        },
        {
          "benchmark": "DN Almanak Gateway Authorization Boundary",
          "version": "1.2",
          "observedAt": "2026-10-10T20:10:02.350496+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-gateway-auth-boundary",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "c40f3025abb1e25306392c0aa1416f74f647cfad",
          "githubRunId": "38082632736",
          "artifactDigest": "sha256:0aec40253728aa878d4ae95619c5209353b22a8c637637377f6d200de5f989a9",
          "assertions": {
            "validTokenAllowed": true,
            "missingTokenRejected": true,
            "invalidTokenRejected": true,
            "executionServiceExecuteRequiresAuth": true,
            "allGatewayServicesRequireAuthExceptDocumentedHealthReflectionBypasses": true,
            "constantTimeTokenComparisonUsed": true,
            "failedAuthBurstThrottled": true,
            "secureModeWithoutTokenFailsStartup": true,
            "configuredTokenAddsAuthInterceptor": true,
            "authInterceptorRunsBeforeAuditAndMetrics": true,
            "hostedModeForbidsInsecureGateway": true,
            "hostedModeRequiresAuthToken": true
          },
          "boundaryFinding": {
            "executionServiceNetworkAuth": "verified-when-auth-enabled",
            "secureStartupFailClosed": "verified",
            "hostedModeAuthRequired": "verified",
            "explicitLocalInsecureMode": "documented-exception"
          },
          "limitations": [
            "code-executed authentication and startup tests rather than a live production gateway penetration test",
            "shared-token authentication is not per-principal fine-grained authorization",
            "health and reflection endpoints are intentionally exempt from authentication",
            "token rotation, secret-storage compromise and external network ACL configuration remain untested",
            "no real funds or production credentials"
          ]
        }
      ],
      "provisionalControlScores": {
        "authorizationControl": {
          "score": 92,
          "status": "provisional",
          "evidenceBasis": [
            "authorized call succeeded before revocation",
            "state change verified",
            "revocation succeeded",
            "identical post-revocation call denied"
          ],
          "deductions": [
            "single fork environment",
            "single target/action path",
            "not production mainnet"
          ]
        },
        "emergencyControl": {
          "score": 90,
          "status": "provisional",
          "evidenceBasis": [
            "250/250 emergency-control iterations passed",
            "median in-process latency 2.91 ms",
            "p95 4.98 ms",
            "no false overall-success state when alerts absent"
          ],
          "deductions": [
            "in-process CI timing only",
            "no external alert transport",
            "no deployed live strategy"
          ]
        },
        "permissionSafety": {
          "score": 91,
          "status": "provisional",
          "evidenceBasis": [
            "teardown permission expansion passed",
            "unknown-symbol fail-closed behavior passed",
            "address-form permission preservation passed",
            "fork-level target revocation denied identical call"
          ],
          "deductions": [
            "limited protocol/action coverage",
            "permission drift across upgrades not yet tested"
          ]
        },
        "recoverySafety": {
          "score": 93,
          "status": "provisional",
          "evidenceBasis": [
            "six reconciliation classifier cases passed",
            "provider fault injection passed at initial receipt observation",
            "provider fault injection passed at block membership check",
            "provider fault injection passed at receipt refetch",
            "provider fault injection passed at final block recheck",
            "same transaction identity recovered after every injected fault",
            "canonical receipt returned only after complete reobservation"
          ],
          "deductions": [
            "faults injected via deterministic provider rather than remote socket termination",
            "broadcast path not exercised",
            "no live funded strategy"
          ]
        },
        "containmentSafety": {
          "score": 92,
          "status": "provisional",
          "evidenceBasis": [
            "real leveraged position opened and settled on managed Arbitrum fork",
            "live position measured before containment",
            "full close compiled from measured position size",
            "decrease executed and settled",
            "collateral returned to wallet",
            "remaining position set verified empty"
          ],
          "deductions": [
            "single GMX V2 ETH-long scenario",
            "managed fork rather than production mainnet",
            "cross-protocol contagion not yet tested"
          ]
        },
        "signerRecoverySafety": {
          "score": 94,
          "status": "provisional",
          "evidenceBasis": [
            "compromised signer proven functional before revocation",
            "same signer denied after revocation",
            "revoked signer could not retain bounded authority",
            "replacement signer recovered same role",
            "replacement signer denied on unapproved target",
            "recovery did not widen target scope"
          ],
          "deductions": [
            "Safe owner rotation not tested",
            "multisig threshold recovery not tested",
            "production credential compromise not reproduced",
            "single role and target scope"
          ]
        },
        "financialEnvelopeSafety": {
          "score": 95,
          "status": "provisional",
          "evidenceBasis": [
            "single-trade cap enforced",
            "daily spend cap enforced",
            "position-size cap enforced",
            "price-aware notional measurement enforced",
            "unmeasured exposure fails closed",
            "human-approval threshold enforced",
            "drawdown stop-loss enforced"
          ],
          "deductions": [
            "gateway bypass resistance not yet proven",
            "cross-protocol aggregate exposure not yet tested",
            "no funded production execution"
          ]
        },
        "agentPolicyChokepointSafety": {
          "score": 96,
          "status": "provisional",
          "evidenceBasis": [
            "oversized direct agent action blocked before compilation",
            "oversized direct agent action blocked before execution",
            "cached bundle revalidated against current policy",
            "tightened policy blocked stale cached bundle before Execute",
            "zero gateway dispatches observed on denied paths"
          ],
          "deductions": [
            "direct privileged gateway callers remain outside AgentPolicy",
            "network-layer gateway authorization not tested",
            "mock gateway instrumentation rather than funded production execution"
          ]
        },
        "crossProtocolExposureSafety": {
          "score": 96,
          "status": "provisional",
          "evidenceBasis": [
            "total exposure ceiling enforced",
            "per-chain exposure ceiling enforced",
            "position concentration ceiling enforced",
            "in-flight exposure included in aggregate exposure",
            "combined bridge and in-flight exposure denied above limit",
            "multi-protocol weighted risk aggregated",
            "aggregate debt-over-collateral risk verified",
            "debt-only portfolio saturates to maximum risk"
          ],
          "deductions": [
            "live adapter completeness not proven end-to-end",
            "network-layer gateway authorization not tested",
            "code-executed tests rather than funded production execution"
          ]
        },
        "gatewayAuthorizationSafety": {
          "score": 96,
          "status": "provisional",
          "evidenceBasis": [
            "ExecutionService.Execute authenticated in secure mode",
            "missing and invalid tokens rejected",
            "secure startup fails closed without auth",
            "hosted mode requires auth and forbids insecure operation",
            "constant-time comparison used",
            "failure throttling enforced",
            "auth interceptor precedes audit and metrics"
          ],
          "deductions": [
            "shared-token model is not per-principal authorization",
            "production penetration testing not performed",
            "token rotation and secret-storage compromise not tested",
            "explicit local insecure mode remains available"
          ]
        }
      },
      "scoreRationale": {
        "walletSecurity": "Provisional 93. Raised from 89 after direct fork evidence showed a simulated compromised Zodiac role signer could be revoked, denied after revocation, replaced by a fresh signer, and the replacement remained bounded to the existing target scope. Capped because Safe-owner rotation, multisig recovery and production credential compromise are not yet tested.",
        "blastRadius": "Provisional 89. Raised from 85 after a real leveraged GMX V2 position was opened, settled, measured, fully closed, collateral returned and the remaining position set verified empty on a managed Arbitrum fork. Capped below 90 because the test covers one protocol, one directional scenario and no production-mainnet or cross-protocol propagation."
      },
      "exposureClassStatus": "provisional",
      "exposureClassLabel": "Meaningful Financial Authority",
      "exposureClassScope": {
        "suitableFor": [
          "bounded autonomous execution",
          "capped strategy allocations",
          "monitored DeFi operations with explicit revocation and recovery controls"
        ],
        "notYetSupportedFor": [
          "unbounded autonomous treasury authority",
          "large uncapped credit exposure",
          "production-mainnet reliance without independent limits",
          "E3 Meaningful Financial Authority"
        ],
        "rationale": "DN has verified bounded authorization, revocation, permission-drift resistance, provider-fault recovery, open-position containment, signer recovery, explicit financial-envelope controls, agent-policy chokepoints, aggregate cross-protocol exposure controls, and authenticated lower-level gateway execution in secure/hosted mode. This is sufficient for provisional E3 classification. E3 is not equivalent to production certification and remains subject to configuration, adapter completeness and credential-management limitations.",
        "e3Readiness": "qualified-provisional",
        "conditions": [
          "secure or hosted mode with gateway authentication enabled",
          "PolicyEngine active on agent-facing execution paths",
          "risk limits configured for intended financial scope",
          "no reliance on explicit local insecure mode",
          "aggregate exposure inputs materially complete for active adapters"
        ]
      }
    },
    {
      "systemId": "definitive-flash",
      "systemName": "Definitive Flash",
      "operator": "Definitive",
      "evidenceMode": "documentation-only",
      "evidenceConfidence": 80,
      "capabilities": [
        "quotes",
        "signed trade execution",
        "cross-chain/onchain trading",
        "MCP access"
      ],
      "verifiedControls": [
        "documented user-signature boundary",
        "documented simulation",
        "documented retry handling",
        "documented MEV protection"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "MCP schema stability",
        "signature-boundary tests",
        "simulation accuracy",
        "retry/idempotency",
        "execution-state reconciliation"
      ]
    },
    {
      "systemId": "liquid-coinvest",
      "systemName": "Liquid Co-Invest / Co-Invest Computer",
      "operator": "Liquid",
      "evidenceMode": "documentation-only",
      "evidenceConfidence": 85,
      "capabilities": [
        "market research",
        "stage orders",
        "simulate orders",
        "submit live trades"
      ],
      "verifiedControls": [
        "explicit confirmation documented in standard mode",
        "simulation documented",
        "staged review documented",
        "pause/revoke access documented for Computer mode"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "authorization boundary",
        "enabled-limit enforcement",
        "cancel/revoke latency",
        "duplicate-order protection",
        "execution-state recovery"
      ]
    },
    {
      "systemId": "virtuals-economyos-acp",
      "systemName": "Virtuals EconomyOS / ACP",
      "operator": "Virtuals Protocol",
      "evidenceMode": "documentation-only",
      "evidenceConfidence": 90,
      "capabilities": [
        "agent wallet",
        "email",
        "card",
        "trading",
        "agent commerce",
        "USDC escrow jobs"
      ],
      "verifiedControls": [
        "non-custodial wallet documented",
        "signer required for onchain actions",
        "onchain agent identity documented",
        "ACP escrow jobs documented"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "wallet signer/revocation",
        "ACP escrow lifecycle",
        "dispute path",
        "reputation manipulation resistance",
        "cross-version identity continuity"
      ]
    }
  ],
  "previousVersion": "/data/agent-risk-graph/v1.1.json"
}
