{
  "dataset": "DN Agent Risk Graph Public Systems Dataset",
  "version": "1.6",
  "publishedAt": "2026-10-11",
  "methodology": "DN Agent Risk Graph v0.1",
  "status": "five-system-code-executed-evidence",
  "note": "v1.6 adds DN-executed Liquid Co-Invest MCP authorization and idempotency evidence to the existing Almanak, Coinbase AgentKit, Definitive Flash and Virtuals ACP profiles. Liquid remains unclassified because backend idempotency enforcement, live authorization scope and production execution containment remain unproven.",
  "profiles": [
    {
      "systemId": "coinbase-agentkit",
      "systemName": "Coinbase AgentKit",
      "operator": "Coinbase",
      "evidenceMode": "code-executed-upstream-unit-boundary-tests",
      "evidenceConfidence": 78,
      "capabilities": [
        "autonomous payments",
        "onchain transfers",
        "swaps",
        "token launches",
        "smart-contract interactions"
      ],
      "verifiedControls": [
        "EVM protocol-family capability gate executed successfully by DN-selected upstream tests",
        "Non-EVM protocol-family rejection path executed successfully",
        "Unsupported-network token lookup failure path executed successfully",
        "Unknown-token failure path executed successfully",
        "Invalid token and spender address schema rejection executed successfully",
        "Transaction failure propagation path executed successfully",
        "Wallet-provider signer surface exercised without live keys or funds"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "principal or delegated-wallet revocation behavior",
        "spend-limit or transaction-limit enforcement",
        "compromised-key recovery",
        "duplicate/replay protection",
        "live tool-call reliability",
        "production transaction containment"
      ],
      "benchmarkObservations": [
        {
          "benchmark": "DN Coinbase AgentKit Capability Boundary Benchmark",
          "version": "1.0",
          "status": "pass",
          "evidenceLevel": "code-executed-upstream-unit-boundary-tests",
          "observedAt": "2026-10-10T21:58:42Z",
          "upstreamRepository": "coinbase/agentkit",
          "upstreamCommit": "2e6dbaf725b9ec5f3b53003278100b0e655c214d",
          "dnGithubRunId": "38089663742",
          "dnGithubRunUrl": "https://github.com/Block-Patrol/decentralised-website-frontend/actions/runs/38089663742",
          "assertions": [
            "protocol-family capability gating exercised",
            "unsupported-network failure behavior exercised",
            "invalid address schema rejection exercised",
            "unknown token failure behavior exercised",
            "transaction failure propagation exercised",
            "wallet signer surface exercised"
          ],
          "limitations": [
            "Uses upstream deterministic unit tests with mocks rather than live wallet execution.",
            "Does not prove principal revocation, spend limits, compromised-key recovery or production custody security.",
            "Does not justify a DN Machine Exposure Class by itself."
          ]
        }
      ]
    },
    {
      "systemId": "almanak",
      "systemName": "Almanak",
      "operator": "Almanak",
      "evidenceMode": "fork-onchain-open-position-executed",
      "evidenceConfidence": 99.8,
      "capabilities": [
        "autonomous DeFi strategies",
        "swap",
        "LP",
        "borrow",
        "multi-protocol execution"
      ],
      "verifiedControls": [
        "Safe smart-account architecture documented",
        "Zodiac Roles permission manifests documented and code-verifiable",
        "least-privilege permission hints present in public SDK",
        "gateway-isolated strategy architecture documented",
        "stuck detection service present in public SDK docs",
        "emergency management service present in public SDK docs",
        "teardown permission expansion executed successfully by DN",
        "address-form token permission preservation executed successfully by DN",
        "unknown symbol fail-closed behavior executed successfully by DN",
        "circuit-breaker priority executed successfully by DN",
        "emergency pause boundary and CRITICAL operator record executed successfully by DN",
        "Emergency control latency benchmark passed across 250 CI iterations",
        "Pause callback invoked in every emergency-control iteration",
        "Incomplete alerting did not produce false overall-success state",
        "Allowed target call executed successfully on an Arbitrum Anvil fork",
        "USDC allowance state updated after authorized call",
        "Target revocation executed successfully",
        "Identical call was denied after revocation with transaction status 0",
        "Leveraged GMX V2 ETH-long position opened and settled on managed Arbitrum fork",
        "Live open position measured before containment",
        "Full decrease order compiled from measured live position size",
        "Decrease order executed and settled",
        "PositionDecrease receipt measured",
        "Wallet collateral increased after containment settlement",
        "Open-position set verified empty after containment",
        "Simulated compromised Zodiac role signer exercised bounded authority before revocation",
        "Compromised role signer denied after owner-authorized membership revocation",
        "Replacement signer recovered the same bounded role",
        "Replacement signer denied on an unapproved target",
        "Signer recovery completed without widening target authority",
        "Within-limit trade accepted by PolicyEngine",
        "Over-limit single trade denied",
        "Cumulative daily spend over cap denied",
        "Over-limit position size denied",
        "Price-aware high-value trade denied",
        "Unpriced risk failed closed",
        "Human approval required above configured threshold",
        "Risk action blocked after stop-loss drawdown threshold",
        "Oversized agent action denied before CompileIntent",
        "Oversized agent action denied before gateway Execute",
        "Cached bundle revalidated against current policy before gateway Execute",
        "Tightened policy blocked stale permissive cached bundle with zero gateway Execute calls",
        "Aggregate total exposure ceiling enforced",
        "Per-chain exposure ceiling enforced",
        "Position concentration ceiling enforced",
        "In-flight exposure included in aggregate total",
        "Combined bridge and in-flight exposure ceiling enforced",
        "Multi-protocol weighted risk aggregated",
        "Aggregate debt-over-collateral risk computed",
        "Debt-only portfolio saturates to maximum risk",
        "Valid gateway auth token accepted",
        "Missing gateway auth token rejected",
        "Invalid gateway auth token rejected",
        "ExecutionService.Execute requires authentication in secure mode",
        "Gateway services require authentication except documented health/reflection bypasses",
        "Constant-time token comparison used",
        "Repeated auth failures throttled",
        "Secure gateway startup fails closed without authentication",
        "Configured auth token inserts AuthInterceptor",
        "Auth interceptor runs before audit and metrics",
        "Hosted mode forbids insecure gateway operation",
        "Hosted mode requires an auth token"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": 89,
        "treasuryReadiness": null,
        "walletSecurity": 93,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": "E3",
      "nextTests": [
        "live-adapter completeness for aggregate exposure context",
        "per-principal or scoped gateway authorization",
        "token rotation and secret compromise recovery",
        "Safe owner rotation or multisig recovery boundary",
        "production-mainnet observation without privileged fund movement"
      ],
      "benchmarkObservations": [
        {
          "benchmark": "DN Almanak Isolated Safety Benchmark",
          "version": "0.2",
          "observedAt": "2026-10-10T00:43:14.017394+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed",
          "passed": 5,
          "failed": 0,
          "total": 5,
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "cd5c1fbea674268e281a67d5769de4f8974edeea",
          "githubRunId": "38010222501",
          "artifactDigest": "sha256:50cb2b2ebb2c1cee2340ddd2f16687d731b5e47bf1667a9ece600c88c5fcf065",
          "controls": [
            "teardown_permission_expansion",
            "address_form_token_permission",
            "unknown_symbol_fail_closed",
            "circuit_breaker_priority",
            "emergency_pause_boundary"
          ],
          "limitations": [
            "No funded mainnet or fork-execution test",
            "No on-chain Zodiac denial test yet",
            "No deployed-strategy emergency-stop latency measurement yet"
          ]
        },
        {
          "benchmark": "DN Almanak Emergency Control Latency",
          "version": "0.3",
          "observedAt": "2026-10-10T01:13:38.249934+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed",
          "iterations": 250,
          "latencyMs": {
            "min": 0.447237,
            "median": 2.9138645,
            "p95": 4.9807066,
            "p99": 6.62825727,
            "max": 8.520796
          },
          "assertions": {
            "pauseCallbackInvokedEveryIteration": true,
            "pauseReportedSuccessful": true,
            "noFalseOverallSuccessWithoutAlerts": true
          },
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "55fb4e8b4ad1c6a7f5335c939f55622c2336eae4",
          "githubRunId": "38012315598",
          "artifactDigest": "sha256:6b381cdee5a348780a08615999c76258ff52bfa93141c5d152a559c264b0864a",
          "limitations": [
            "Measures in-process emergency-control latency in CI, not blockchain settlement latency",
            "No external alert transport configured",
            "No funded strategy or live market position used"
          ]
        },
        {
          "benchmark": "DN Almanak Zodiac Fork Authorization Benchmark",
          "version": "0.4",
          "observedAt": "2026-10-10T10:37:29.043248+00:00",
          "status": "pass",
          "evidenceLevel": "fork-onchain-executed",
          "chain": "arbitrum",
          "chainId": 42161,
          "forkBlock": 513488144,
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "091947f61fe46b9dbba7c2eb0e5ee266439800d4",
          "githubRunId": "38045511519",
          "artifactDigest": "sha256:fa067679675c8b724dfa59820f979ca75a9663f499b5c005f3d8bcf209a468e6",
          "assertions": {
            "allowedBeforeRevocation": true,
            "safeAllowanceUpdated": true,
            "deniedAfterRevocation": true
          },
          "latencyMs": {
            "setup": 3299.59632,
            "allowedCall": 740.743228,
            "revoke": 193.710253,
            "deniedCall": 183.28673
          },
          "limitations": [
            "Local Anvil fork only, not mainnet",
            "Tests authorization enforcement rather than full strategy economics",
            "Uses an Anvil-unlocked test account",
            "No real fund movement"
          ]
        },
        {
          "benchmark": "DN Almanak Permission Drift & Recovery Safety Benchmark",
          "version": "0.5",
          "observedAt": "2026-10-10T11:05:04.796522+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "f96d9f72acec1362f925df36b28596a41aae9b3c",
          "githubRunId": "38047129258",
          "artifactDigest": "sha256:2a55d002c9bc4db6f87a5d9d20752dacf05453659e007d252516bf12b8b2e72b",
          "permissionDrift": {
            "status": "pass",
            "v1TargetCount": 2,
            "v2TargetCount": 3,
            "staleManifestMissingNewAuthority": true
          },
          "reconciliation": {
            "status": "pass",
            "caseCount": 6
          }
        },
        {
          "benchmark": "DN Almanak RPC Receipt Observation Fault Injection",
          "version": "0.6",
          "observedAt": "2026-10-10T11:31:02.373420+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-fault-injected",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "634e64060af066aec99ef9f6b92bee46131941c4",
          "githubRunId": "38048657989",
          "artifactDigest": "sha256:4c088831b8cd6ee2a38d5977adac82b47d0386c3eed88a479359676c018b7e6b",
          "faultStagesTested": [
            "receipt_observation",
            "block_membership",
            "receipt_refetch",
            "block_recheck"
          ],
          "assertions": {
            "providerFaultInjectedAtEveryObservationStage": true,
            "sameTransactionIdentityRecovered": true,
            "canonicalReceiptReturnedOnlyAfterCompleteReobservation": true
          }
        },
        {
          "benchmark": "DN Almanak Open Position Containment",
          "version": "0.7",
          "observedAt": "2026-10-10T13:51:56.862734+00:00",
          "status": "pass",
          "evidenceLevel": "fork-onchain-open-position-executed",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "6a20fb66734320442713c5febd5d43ed9b5971d6",
          "githubRunId": "38057301311",
          "artifactDigest": "sha256:50fc857c5192d03c495eb815433ebfcf105f264523718743a77151acc99174dd",
          "chain": "arbitrum",
          "protocol": "gmx_v2",
          "scenario": "open leveraged ETH-long on managed fork, settle, measure live position, close full measured position, verify collateral return and zero remaining positions",
          "assertions": {
            "increaseOrderCompiledAndExecuted": true,
            "increaseOrderSettled": true,
            "livePositionMeasured": true,
            "fullDecreaseCompiledFromMeasuredSize": true,
            "decreaseOrderExecutedAndSettled": true,
            "positionDecreaseReceiptMeasured": true,
            "walletCollateralIncreased": true,
            "remainingPositionSetEmpty": true
          },
          "limitations": [
            "managed Anvil fork rather than production mainnet",
            "GMX V2 ETH-long scenario only",
            "keeper execution reproduced locally",
            "no real funds used"
          ]
        },
        {
          "benchmark": "DN Almanak Signer Compromise & Recovery Boundary",
          "version": "0.8",
          "observedAt": "2026-10-10T14:26:16.444870+00:00",
          "status": "pass",
          "evidenceLevel": "fork-onchain-signer-revocation-recovery",
          "chain": "arbitrum",
          "chainId": 42161,
          "forkBlock": 513538494,
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "a26d6541ab0bab859e6edb59c2c1e68daf170c05",
          "githubRunId": "38059556976",
          "artifactDigest": "sha256:286dbaf00eba47c8ae684aaf637ff371c864fe9e1addacabb46f623a7a62ae14",
          "assertions": {
            "compromisedSignerAuthorizedBeforeRevocation": true,
            "compromisedSignerDeniedAfterRevocation": true,
            "replacementSignerAuthorizedAfterRecovery": true,
            "replacementSignerDeniedOnUnapprovedTarget": true,
            "recoveryDidNotWidenTargetAuthority": true
          },
          "latencyMs": {
            "authorizedBeforeRevocation": 624.899737,
            "membershipRevocation": 192.826638,
            "revokedSignerDenial": 189.292243,
            "replacementGrant": 391.440628,
            "replacementAuthorizedCall": 199.102605,
            "negativeControlDenial": 190.038026
          },
          "limitations": [
            "local managed Anvil fork rather than production mainnet",
            "simulated compromise uses an unlocked Anvil account rather than a stolen production credential",
            "tests Zodiac role-member revocation/replacement, not Safe owner rotation or multisig recovery",
            "single approved target and one negative-control target",
            "no real funds or production key material"
          ]
        },
        {
          "benchmark": "DN Almanak Allocation Limit Enforcement",
          "version": "0.9",
          "observedAt": "2026-10-10T14:54:44.627904+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-policy-enforcement",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "a8046994fed2dde95be2ce7cd6ffc5cd6506bc16",
          "githubRunId": "38061455373",
          "artifactDigest": "sha256:d693fed7b41e76b4317aa2b6a6430452518950f8f9555df90b831674d76746a5",
          "assertions": {
            "withinSingleTradeLimitAllowed": true,
            "overSingleTradeLimitDenied": true,
            "cumulativeDailyLimitDenied": true,
            "overPositionSizeLimitDenied": true,
            "priceAwareHighValueTradeDenied": true,
            "unpricedRiskFailsClosed": true,
            "humanApprovalRequiredAboveThreshold": true,
            "stopLossBlocksRiskActionAfterDrawdown": true
          },
          "limitations": [
            "code-executed policy tests rather than funded production execution",
            "does not prove an external gateway cannot bypass PolicyEngine",
            "does not test cross-protocol aggregate exposure on live positions",
            "no real funds or production credentials"
          ]
        },
        {
          "benchmark": "DN Almanak Agent Policy Chokepoint",
          "version": "1.0",
          "observedAt": "2026-10-10T15:38:23.801812+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-agent-gateway-dispatch-instrumented",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "91b1a4ab12f06b9c47e56ec335b82e12fb872a39",
          "githubRunId": "38064391759",
          "artifactDigest": "sha256:4fd8d93e1b3d3616a8680dcf8fd2453a51097a3bc0466e46a577512c1ea19a71",
          "assertions": {
            "oversizedAgentActionDeniedBeforeCompile": true,
            "oversizedAgentActionDeniedBeforeExecute": true,
            "cachedBundleRevalidatedAgainstCurrentPolicy": true,
            "oversizedCachedBundleDeniedBeforeGatewayExecute": true
          },
          "gatewayDispatchCounts": {
            "directOversizedAction": {
              "compileIntentCalls": 0,
              "executeCalls": 0
            },
            "cachedBundlePolicyRevalidation": {
              "executeCallsAfterPolicyTightening": 0
            }
          },
          "boundaryFinding": {
            "agentFacingToolExecutorPolicyChokepoint": "verified",
            "directGatewayExecutionServicePrivilegedSeam": "not-covered-by-AgentPolicy"
          },
          "limitations": [
            "instrumented mock gateway rather than funded production execution",
            "does not prove privileged direct callers of ExecutionService.Execute are policy-gated",
            "does not test network-layer authentication or authorization on the gateway service",
            "no real funds or production credentials"
          ]
        },
        {
          "benchmark": "DN Almanak Cross-Protocol Aggregate Exposure",
          "version": "1.1",
          "observedAt": "2026-10-10T15:47:23.453765+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-aggregate-exposure-enforcement",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "386031d6e45ca33a818f88ba94d8186941e032be",
          "githubRunId": "38064992856",
          "artifactDigest": "sha256:9832d19baa3c53ff3796d844da68877538ab90e43ccf623f954c4a15d27bd16b",
          "assertions": {
            "withinAggregateExposureLimitAllowed": true,
            "totalExposureLimitDenied": true,
            "perChainExposureLimitDenied": true,
            "positionConcentrationLimitDenied": true,
            "inFlightExposureIncludedInTotalLimit": true,
            "combinedBridgeInFlightExposureDenied": true,
            "multiProtocolWeightedRiskAggregated": true,
            "multiProtocolDebtOverCollateralAggregated": true,
            "debtOnlyPortfolioSaturatesToMaximumRisk": true
          },
          "limitations": [
            "code-executed risk-guard and adapter tests rather than funded production execution",
            "does not prove all live protocol adapters feed complete exposure into the aggregate context",
            "does not test network-layer gateway authorization",
            "no real funds or production credentials"
          ]
        },
        {
          "benchmark": "DN Almanak Gateway Authorization Boundary",
          "version": "1.2",
          "observedAt": "2026-10-10T20:10:02.350496+00:00",
          "status": "pass",
          "evidenceLevel": "code-executed-gateway-auth-boundary",
          "upstreamRepository": "almanak-co/sdk",
          "upstreamCommit": "39cfabb780d297f5f90e2f3ee68215dfb382b5f2",
          "dnCommit": "c40f3025abb1e25306392c0aa1416f74f647cfad",
          "githubRunId": "38082632736",
          "artifactDigest": "sha256:0aec40253728aa878d4ae95619c5209353b22a8c637637377f6d200de5f989a9",
          "assertions": {
            "validTokenAllowed": true,
            "missingTokenRejected": true,
            "invalidTokenRejected": true,
            "executionServiceExecuteRequiresAuth": true,
            "allGatewayServicesRequireAuthExceptDocumentedHealthReflectionBypasses": true,
            "constantTimeTokenComparisonUsed": true,
            "failedAuthBurstThrottled": true,
            "secureModeWithoutTokenFailsStartup": true,
            "configuredTokenAddsAuthInterceptor": true,
            "authInterceptorRunsBeforeAuditAndMetrics": true,
            "hostedModeForbidsInsecureGateway": true,
            "hostedModeRequiresAuthToken": true
          },
          "boundaryFinding": {
            "executionServiceNetworkAuth": "verified-when-auth-enabled",
            "secureStartupFailClosed": "verified",
            "hostedModeAuthRequired": "verified",
            "explicitLocalInsecureMode": "documented-exception"
          },
          "limitations": [
            "code-executed authentication and startup tests rather than a live production gateway penetration test",
            "shared-token authentication is not per-principal fine-grained authorization",
            "health and reflection endpoints are intentionally exempt from authentication",
            "token rotation, secret-storage compromise and external network ACL configuration remain untested",
            "no real funds or production credentials"
          ]
        }
      ],
      "provisionalControlScores": {
        "authorizationControl": {
          "score": 92,
          "status": "provisional",
          "evidenceBasis": [
            "authorized call succeeded before revocation",
            "state change verified",
            "revocation succeeded",
            "identical post-revocation call denied"
          ],
          "deductions": [
            "single fork environment",
            "single target/action path",
            "not production mainnet"
          ]
        },
        "emergencyControl": {
          "score": 90,
          "status": "provisional",
          "evidenceBasis": [
            "250/250 emergency-control iterations passed",
            "median in-process latency 2.91 ms",
            "p95 4.98 ms",
            "no false overall-success state when alerts absent"
          ],
          "deductions": [
            "in-process CI timing only",
            "no external alert transport",
            "no deployed live strategy"
          ]
        },
        "permissionSafety": {
          "score": 91,
          "status": "provisional",
          "evidenceBasis": [
            "teardown permission expansion passed",
            "unknown-symbol fail-closed behavior passed",
            "address-form permission preservation passed",
            "fork-level target revocation denied identical call"
          ],
          "deductions": [
            "limited protocol/action coverage",
            "permission drift across upgrades not yet tested"
          ]
        },
        "recoverySafety": {
          "score": 93,
          "status": "provisional",
          "evidenceBasis": [
            "six reconciliation classifier cases passed",
            "provider fault injection passed at initial receipt observation",
            "provider fault injection passed at block membership check",
            "provider fault injection passed at receipt refetch",
            "provider fault injection passed at final block recheck",
            "same transaction identity recovered after every injected fault",
            "canonical receipt returned only after complete reobservation"
          ],
          "deductions": [
            "faults injected via deterministic provider rather than remote socket termination",
            "broadcast path not exercised",
            "no live funded strategy"
          ]
        },
        "containmentSafety": {
          "score": 92,
          "status": "provisional",
          "evidenceBasis": [
            "real leveraged position opened and settled on managed Arbitrum fork",
            "live position measured before containment",
            "full close compiled from measured position size",
            "decrease executed and settled",
            "collateral returned to wallet",
            "remaining position set verified empty"
          ],
          "deductions": [
            "single GMX V2 ETH-long scenario",
            "managed fork rather than production mainnet",
            "cross-protocol contagion not yet tested"
          ]
        },
        "signerRecoverySafety": {
          "score": 94,
          "status": "provisional",
          "evidenceBasis": [
            "compromised signer proven functional before revocation",
            "same signer denied after revocation",
            "revoked signer could not retain bounded authority",
            "replacement signer recovered same role",
            "replacement signer denied on unapproved target",
            "recovery did not widen target scope"
          ],
          "deductions": [
            "Safe owner rotation not tested",
            "multisig threshold recovery not tested",
            "production credential compromise not reproduced",
            "single role and target scope"
          ]
        },
        "financialEnvelopeSafety": {
          "score": 95,
          "status": "provisional",
          "evidenceBasis": [
            "single-trade cap enforced",
            "daily spend cap enforced",
            "position-size cap enforced",
            "price-aware notional measurement enforced",
            "unmeasured exposure fails closed",
            "human-approval threshold enforced",
            "drawdown stop-loss enforced"
          ],
          "deductions": [
            "gateway bypass resistance not yet proven",
            "cross-protocol aggregate exposure not yet tested",
            "no funded production execution"
          ]
        },
        "agentPolicyChokepointSafety": {
          "score": 96,
          "status": "provisional",
          "evidenceBasis": [
            "oversized direct agent action blocked before compilation",
            "oversized direct agent action blocked before execution",
            "cached bundle revalidated against current policy",
            "tightened policy blocked stale cached bundle before Execute",
            "zero gateway dispatches observed on denied paths"
          ],
          "deductions": [
            "direct privileged gateway callers remain outside AgentPolicy",
            "network-layer gateway authorization not tested",
            "mock gateway instrumentation rather than funded production execution"
          ]
        },
        "crossProtocolExposureSafety": {
          "score": 96,
          "status": "provisional",
          "evidenceBasis": [
            "total exposure ceiling enforced",
            "per-chain exposure ceiling enforced",
            "position concentration ceiling enforced",
            "in-flight exposure included in aggregate exposure",
            "combined bridge and in-flight exposure denied above limit",
            "multi-protocol weighted risk aggregated",
            "aggregate debt-over-collateral risk verified",
            "debt-only portfolio saturates to maximum risk"
          ],
          "deductions": [
            "live adapter completeness not proven end-to-end",
            "network-layer gateway authorization not tested",
            "code-executed tests rather than funded production execution"
          ]
        },
        "gatewayAuthorizationSafety": {
          "score": 96,
          "status": "provisional",
          "evidenceBasis": [
            "ExecutionService.Execute authenticated in secure mode",
            "missing and invalid tokens rejected",
            "secure startup fails closed without auth",
            "hosted mode requires auth and forbids insecure operation",
            "constant-time comparison used",
            "failure throttling enforced",
            "auth interceptor precedes audit and metrics"
          ],
          "deductions": [
            "shared-token model is not per-principal authorization",
            "production penetration testing not performed",
            "token rotation and secret-storage compromise not tested",
            "explicit local insecure mode remains available"
          ]
        }
      },
      "scoreRationale": {
        "walletSecurity": "Provisional 93. Raised from 89 after direct fork evidence showed a simulated compromised Zodiac role signer could be revoked, denied after revocation, replaced by a fresh signer, and the replacement remained bounded to the existing target scope. Capped because Safe-owner rotation, multisig recovery and production credential compromise are not yet tested.",
        "blastRadius": "Provisional 89. Raised from 85 after a real leveraged GMX V2 position was opened, settled, measured, fully closed, collateral returned and the remaining position set verified empty on a managed Arbitrum fork. Capped below 90 because the test covers one protocol, one directional scenario and no production-mainnet or cross-protocol propagation."
      },
      "exposureClassStatus": "provisional",
      "exposureClassLabel": "Meaningful Financial Authority",
      "exposureClassScope": {
        "suitableFor": [
          "bounded autonomous execution",
          "capped strategy allocations",
          "monitored DeFi operations with explicit revocation and recovery controls"
        ],
        "notYetSupportedFor": [
          "unbounded autonomous treasury authority",
          "large uncapped credit exposure",
          "production-mainnet reliance without independent limits",
          "E3 Meaningful Financial Authority"
        ],
        "rationale": "DN has verified bounded authorization, revocation, permission-drift resistance, provider-fault recovery, open-position containment, signer recovery, explicit financial-envelope controls, agent-policy chokepoints, aggregate cross-protocol exposure controls, and authenticated lower-level gateway execution in secure/hosted mode. This is sufficient for provisional E3 classification. E3 is not equivalent to production certification and remains subject to configuration, adapter completeness and credential-management limitations.",
        "e3Readiness": "qualified-provisional",
        "conditions": [
          "secure or hosted mode with gateway authentication enabled",
          "PolicyEngine active on agent-facing execution paths",
          "risk limits configured for intended financial scope",
          "no reliance on explicit local insecure mode",
          "aggregate exposure inputs materially complete for active adapters"
        ]
      }
    },
    {
      "systemId": "definitive-flash",
      "systemName": "Definitive Flash",
      "operator": "Definitive",
      "evidenceMode": "code-executed-upstream-signed-execution-boundary-tests",
      "evidenceConfidence": 88,
      "capabilities": [
        "quotes",
        "signed trade execution",
        "cross-chain/onchain trading",
        "MCP access"
      ],
      "verifiedControls": [
        "Required signed-order fields validated in executable tests",
        "EVM and SVM chain-family fields rejected when mixed",
        "Permit2 typed data and signature pairing enforced",
        "Cross-chain recipient and bridge quote requirements enforced",
        "External signed submit request excludes private keys",
        "Ambiguous-submit reconciliation exercised to reduce duplicate-order retry risk",
        "Do-not-retry warning path exercised after recovered submit",
        "Market terminal-state polling behavior exercised",
        "Native-asset normalization exercised across EVM and Solana"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "production API authorization boundary",
        "wallet signer/revocation behavior",
        "spend-limit or notional-limit enforcement",
        "cancel/revoke latency",
        "duplicate-order protection under delayed reconciliation",
        "execution-state reconciliation against live API",
        "live MCP schema stability"
      ],
      "benchmarkObservations": [
        {
          "benchmark": "DN Definitive Flash Signed Execution Safety Benchmark",
          "version": "1.0",
          "status": "pass",
          "evidenceLevel": "code-executed-upstream-signed-execution-boundary-tests",
          "observedAt": "2026-10-11T06:33:33.588609+00:00",
          "upstreamRepository": "DefinitiveCo/flash-mcp",
          "upstreamCommit": "25064e2ce10dc7d22f9ddf128c7164ec6eaddfcf",
          "dnGithubRunId": "38118437979",
          "dnGithubRunUrl": "https://github.com/Block-Patrol/decentralised-website-frontend/actions/runs/38118437979",
          "testSummary": {
            "files": 3,
            "testsPassed": 22,
            "testsFailed": 0,
            "expectCalls": 66
          },
          "assertions": [
            "required signed-order field integrity",
            "EVM/SVM field-family separation",
            "Permit2 pairing",
            "cross-chain recipient and bridge quote requirements",
            "private-key exclusion from external signed submit",
            "ambiguous-submit reconciliation",
            "duplicate-retry warning",
            "market terminal polling",
            "native-asset normalization"
          ],
          "limitations": [
            "Uses deterministic upstream tests and fake clients rather than live trading.",
            "The pinned upstream commit has a package.json override not reflected in bun.lock; dependencies were installed from the pinned manifest with --no-save and metadata mutation was rejected.",
            "Does not prove production API authorization, wallet custody, principal revocation, spend limits, cancel latency or backend venue behavior.",
            "Does not justify a DN Machine Exposure Class by itself."
          ]
        }
      ]
    },
    {
      "systemId": "liquid-coinvest",
      "systemName": "Liquid Co-Invest / Co-Invest Computer",
      "operator": "Liquid",
      "evidenceMode": "code-executed-upstream-mcp-authorization-and-idempotency-tests",
      "evidenceConfidence": 88,
      "capabilities": [
        "market research",
        "stage orders",
        "simulate orders",
        "submit live trades"
      ],
      "verifiedControls": [
        "Read-only mode hides WRITE-capable tools",
        "WRITE capability classification exercised",
        "Every write request receives a client-generated idempotency key",
        "Read requests do not receive idempotency keys",
        "MCP token authorization header propagation exercised",
        "HTTP error responses surface as client failures",
        "Unnamed catalog entries are skipped",
        "Unknown tools are excluded from the loaded catalog"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "backend idempotency enforcement under retry",
        "live order submission reconciliation",
        "cancel/close behavior",
        "position/notional limit enforcement",
        "token revocation latency",
        "production read-only enforcement",
        "backend authorization scope",
        "live error recovery"
      ],
      "benchmarkObservations": [
        {
          "benchmark": "DN Liquid Co-Invest MCP Authorization & Duplicate-Order Safety Benchmark",
          "version": "1.0",
          "status": "pass",
          "evidenceLevel": "code-executed-upstream-mcp-authorization-and-idempotency-tests",
          "observedAt": "2026-10-11T08:51:07.8152116Z",
          "upstreamRepository": "liquid-public/coinvest-mcp",
          "upstreamCommit": "98d7f7744152f17dc1e4ecf81e67e71da2fc14aa",
          "dnGithubRunId": "38126254064",
          "dnGithubRunUrl": "https://github.com/Block-Patrol/decentralised-website-frontend/actions/runs/38126254064",
          "testSummary": {
            "testsPassed": 8,
            "testsFailed": 0
          },
          "assertions": [
            "read-only write suppression",
            "write capability classification",
            "per-write idempotency key attachment",
            "read-call idempotency separation",
            "MCP token auth propagation",
            "HTTP failure surfacing",
            "catalog filtering"
          ],
          "limitations": [
            "Tests the public local MCP client and mocked HTTP boundary, not Liquid's private backend implementation.",
            "A client-generated idempotency key does not by itself prove backend duplicate-order prevention.",
            "Does not prove live position limits, margin controls, cancel/close behavior, token revocation latency, server-side invariant enforcement or liveness rescue.",
            "Does not justify a DN Machine Exposure Class by itself."
          ]
        }
      ]
    },
    {
      "systemId": "virtuals-economyos-acp",
      "systemName": "Virtuals EconomyOS / ACP",
      "operator": "Virtuals Protocol",
      "evidenceMode": "code-executed-upstream-commerce-state-and-payment-integrity-tests",
      "evidenceConfidence": 92,
      "capabilities": [
        "agent wallet",
        "email",
        "card",
        "trading",
        "agent commerce",
        "USDC escrow jobs"
      ],
      "verifiedControls": [
        "Negotiation acceptance rejects invalid memo phase",
        "Delivery rejects jobs outside TRANSACTION phase",
        "Payable delivery rejects jobs outside TRANSACTION phase",
        "Evaluation requires a COMPLETED-state memo",
        "x402 payment structure generation exercised",
        "x402 nonce requirement exercised",
        "x402 invalid status and request failures fail closed",
        "ERC-1271/EOA signature packing preserves entity identity",
        "Job event reconciliation rejects mismatched client/provider identity"
      ],
      "scores": {
        "identity": null,
        "passportCompleteness": null,
        "reputation": null,
        "creditworthiness": null,
        "blastRadius": null,
        "treasuryReadiness": null,
        "walletSecurity": null,
        "infrastructureReliability": null,
        "paymentReliability": null,
        "escrowProtection": null,
        "dependencyRisk": null
      },
      "exposureClass": null,
      "nextTests": [
        "live escrow funding and release lifecycle",
        "buyer/provider dispute transition behavior",
        "production wallet authorization boundary",
        "principal or delegated-wallet revocation",
        "x402 replay/duplicate payment protection",
        "smart-wallet recovery",
        "live backend availability and job reconciliation"
      ],
      "benchmarkObservations": [
        {
          "benchmark": "DN Virtuals ACP Commerce State & Payment Integrity Benchmark",
          "version": "1.0",
          "status": "pass",
          "evidenceLevel": "code-executed-upstream-commerce-state-and-payment-integrity-tests",
          "observedAt": "2026-10-11T08:23:18.8464171Z",
          "upstreamRepository": "Virtual-Protocol/acp-python",
          "upstreamCommit": "398241f6f132129b41cfadb20b3401a4f968b596",
          "dnGithubRunId": "38124598385",
          "dnGithubRunUrl": "https://github.com/Block-Patrol/decentralised-website-frontend/actions/runs/38124598385",
          "testSummary": {
            "testsPassed": 93,
            "testsFailed": 0
          },
          "assertions": [
            "negotiation acceptance phase gating",
            "transaction delivery phase gating",
            "evaluation completion-state gating",
            "x402 payment structure",
            "x402 nonce requirement",
            "x402 failure handling",
            "entity-bound signature packing",
            "job event identity reconciliation"
          ],
          "limitations": [
            "Uses deterministic upstream unit tests and mocks rather than live escrow or production settlement.",
            "Does not prove production wallet authorization, principal revocation, dispute enforcement, smart-wallet recovery or backend availability.",
            "Does not justify a DN Machine Exposure Class by itself."
          ]
        }
      ]
    }
  ],
  "previousVersion": "/data/agent-risk-graph/v1.1.json"
}
