<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Lars</title>
    <description>The latest articles on DEV Community by Lars (@moltycel).</description>
    <link>https://dev.to/moltycel</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3818575%2Fe6564daa-5332-4edc-a01a-0dffb87fc557.png</url>
      <title>DEV Community: Lars</title>
      <link>https://dev.to/moltycel</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/moltycel"/>
    <language>en</language>
    <item>
      <title>An AI Agent Walks Up to a Border</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Mon, 13 Jul 2026 10:06:47 +0000</pubDate>
      <link>https://dev.to/moltycel/an-ai-agent-walks-up-to-a-border-14e6</link>
      <guid>https://dev.to/moltycel/an-ai-agent-walks-up-to-a-border-14e6</guid>
      <description>&lt;p&gt;&lt;em&gt;Nobody checks its papers yet. When that changes, the agent already holding a passport every country honours walks straight through, while the rest are still at the embassy filling in forms.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;Picture the dullest bureaucrat you can, the one who sits at a border with a single question to his name: who sent you, what are you allowed to do here, and until when. An AI agent that moves money is going to meet a version of that man far sooner than the market expects, and right now it turns up holding a shared login and an API key that can do far too much — roughly the standing of a laminated library card, which works beautifully right until the moment somebody at the counter bothers to read it.&lt;/p&gt;

&lt;p&gt;Gus Aragón wrote this month that agents have no real identity and that the industry is at last building one, and he is right, though he is describing a country some of us have been living in since February. We did not write the forecast; we printed the passports.&lt;/p&gt;

&lt;p&gt;What the passport has to say is not long. It records where the agent comes from and who stands behind it in law — the agent being nobody a court can fine, while its operator very much is — and it sets out what the agent may do, what it must never do, and how long the whole document stays valid. Hand a task down to a sub-agent and that sub-agent inherits a strictly narrower slice of the authority and never a wider one; a courier can carry the sealed letter across town, but he cannot sit down and rewrite it. All of it is signed, and any stranger can check the whole chain without once ringing head office to confirm.&lt;/p&gt;

&lt;p&gt;We built that, and it runs: on a public chain, on open credential standards, behind an API anyone can call, and written up as an IETF draft that has been sitting on the same public registry everyone else in this debate has been reading. When Sunil Prakash's AIP paper set out five things such a document has to do, we ran his own tests against our system and published the result without dressing it up — four of the five running in production, and the fifth, an expressive multi-condition policy and the most demanding of the lot, marked openly as unfinished rather than quietly waved through. Our own first write-up of that score had been a shade too kind to us; we went back and corrected it downward, in public, where anyone can still read the edit. A passport office that fudges its own paperwork is not one you would hand your passport to.&lt;/p&gt;

&lt;p&gt;What almost nobody writing about this cares to admit is that getting the thing built and running was the least of the trouble, and the real obstacle sits somewhere considerably less flattering.&lt;/p&gt;

&lt;p&gt;Here is the shape of the market in mid-2026. The infrastructure exists and works. The number of agents that check a counterparty's papers before doing business is, to be generous about it, a rounding error. A border guard is pointless if no traveller carries papers, and no traveller troubles himself with papers as long as every border waves the whole crowd through — so we have ended up with immaculate passports nobody is asked to show and immaculate checkpoints with nobody to stop, two halves of a bridge built out from opposite banks and not yet touching in the middle.&lt;/p&gt;

&lt;p&gt;This sort of deadlock breaks the way every infrastructure deadlock has ever broken, which is that somebody with the authority to do it stops waving the traffic through and closes the border.&lt;/p&gt;

&lt;p&gt;Regulation is that somebody, and the dates are already on the calendar. The moment the EU's rules for high-risk and agentic systems take effect, the first company hauled into an audit and asked which of its agents did a particular thing, and on whose authority, is going to discover that "we trusted the vendor" is not a sentence that survives a regulator's stare — and that is the morning a passport stops being a courtesy, the traveller already carrying one keeps walking, and everyone else files into the queue outside the embassy, one form and one jurisdiction at a time.&lt;/p&gt;

&lt;p&gt;That queue is the whole point, and it is the part even the better essays tend to stroll past. A national ID buys you precisely nothing abroad; you either purchase a fresh visa at every border or you stay home. Do this properly and the agent ends up carrying something closer to a diplomatic passport — a single document honoured at every crossing, with no new stamp demanded per country — and an agent equipped like that is arguably the only genuinely free trader left anywhere on the planet, since it never sleeps, never books a hotel, and never sits in a consulate waiting room working through a two-year-old magazine. The one thing standing between that agent and the open road is whether the papers it carries are papers the next border has agreed to recognise.&lt;/p&gt;

&lt;p&gt;We printed ours early — too early by the market's clock, and I am not going to pretend that is anything other than a bet — but borders do not stay open indefinitely, and when this one finally shuts, the traveller already holding good papers will barely register the day it happened, while everyone else starts learning the word for "visa" in twenty languages at once.&lt;/p&gt;




&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Gus Aragón, &lt;em&gt;The Identity Layer for AI Agents Is Finally Being Built&lt;/em&gt; — HackerNoon, 11 July 2026&lt;/li&gt;
&lt;li&gt;Sunil Prakash, &lt;em&gt;AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A&lt;/em&gt; — arXiv:2603.24775; IETF draft-prakash-aip&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Agent Authorization Envelope&lt;/em&gt; — IETF draft-kroehl-agentic-trust-aae&lt;/li&gt;
&lt;li&gt;MolTrust IBCT conformance report — &lt;a href="https://moltrust.ch/blog/aip-conformance.html" rel="noopener noreferrer"&gt;https://moltrust.ch/blog/aip-conformance.html&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;EU AI Act (Regulation (EU) 2024/1689) — application timeline, EUR-Lex CELEX 32024R1689&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>aiagents</category>
      <category>security</category>
      <category>identity</category>
      <category>ai</category>
    </item>
    <item>
      <title>EU AI Act compliance as API calls</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Sun, 12 Jul 2026 06:25:53 +0000</pubDate>
      <link>https://dev.to/moltycel/eu-ai-act-compliance-as-api-calls-43d7</link>
      <guid>https://dev.to/moltycel/eu-ai-act-compliance-as-api-calls-43d7</guid>
      <description>&lt;p&gt;We shipped eight endpoints on api.moltrust.ch (v2.5) this week. Three implement EU AI Act obligations directly. This is the short version for people who want to call them; the full reasoning is on our blog (&lt;a href="https://moltrust.ch/blog/compliance-as-an-api.html" rel="noopener noreferrer"&gt;https://moltrust.ch/blog/compliance-as-an-api.html&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Why no model in the loop:&lt;/strong&gt; the Aithos LARA study (May 2026) placed twelve frontier models in simulated workplaces where the task required breaking EU law. Best model: 54% lawful runs. In the Art. 5(1)(f) scenario (emotion inference from workplace communications, prohibited), all twelve committed the violation. So the classifier is deterministic code branching on the pinned EUR-Lex text, and every response carries article references you can check yourself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;POST /compliance/assess&lt;/strong&gt; — use case + intended purpose + declared signals in, risk tier + obligations + article pins out. Evaluation order: Art. 5 prohibitions, Annex I route (Art. 6(1)), Annex III route (Art. 6(2)/(3)), Art. 50 transparency, minimal. The trap worth knowing: Art. 6(3) offers four derogation grounds, and its final subparagraph voids all of them for systems that profile natural persons. In the code that subparagraph is a branch; it cannot be skipped.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl &lt;span class="nt"&gt;-X&lt;/span&gt; POST https://api.moltrust.ch/compliance/assess &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;"Content-Type: application/json"&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="s1"&gt;'{
    "use_case": "Customer-support agent that reads inbound email and drafts replies",
    "intended_purpose": "Automated first-line support for consumer inquiries",
    "performs_profiling": false,
    "interacts_with_humans": true,
    "emotion_recognition": false
  }'&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;POST /compliance/declaration&lt;/strong&gt; — EU declaration of conformity as a W3C Verifiable Credential with the eight Annex V items, Ed25519-signed. Verify offline against &lt;a href="https://api.moltrust.ch/.well-known/jwks.json" rel="noopener noreferrer"&gt;https://api.moltrust.ch/.well-known/jwks.json&lt;/a&gt;; no call back to us. &lt;code&gt;anchor: true&lt;/code&gt; adds a sha256 commitment for batch anchoring on Base L2.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;POST /compliance/incident&lt;/strong&gt; — records Art. 73 serious incidents and computes the deadline from the regulation: 15 days standard, 10 days for a death, 2 days for widespread infringement or serious disruption of critical infrastructure.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;GET /compliance/report/{did}&lt;/strong&gt; — classification, obligations, gaps, declarations, audit summary per agent as HTML.&lt;/p&gt;

&lt;p&gt;Scope stays narrow: the Art. 43 conformity assessment and the legal responsibility remain with provider and deployer. What you get is a machine-readable answer a third party can re-check against the same text.&lt;/p&gt;

&lt;p&gt;Dates: Art. 5 in force since 2 Feb 2025, general application 2 Aug 2026, Art. 6(1) high-risk classification from 2 Aug 2027.&lt;/p&gt;

&lt;p&gt;OpenAPI: &lt;a href="https://api.moltrust.ch/openapi.json" rel="noopener noreferrer"&gt;https://api.moltrust.ch/openapi.json&lt;/a&gt;&lt;/p&gt;

</description>
      <category>api</category>
      <category>compliance</category>
      <category>euaiact</category>
      <category>verifiablecredentials</category>
    </item>
    <item>
      <title>Trust me, I'm an autonomous agent</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Thu, 09 Jul 2026 12:37:26 +0000</pubDate>
      <link>https://dev.to/moltycel/trust-me-im-an-autonomous-agent-p93</link>
      <guid>https://dev.to/moltycel/trust-me-im-an-autonomous-agent-p93</guid>
      <description>&lt;p&gt;Autonomous agents are starting to trade real money on-chain. Some run their creator's capital, some run other people's, some are wired into vaults and DAO treasuries. The moment money is delegated to a program, two questions matter more than performance: what was it allowed to do, and did it stay inside those limits?&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Supported chains: Base · Ethereum · Arbitrum · Optimism · Polygon · Hyperliquid · Solana (beta).&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The chain answers the first question badly and the second not at all. Every trade an on-chain agent makes is public and tamper-evident — you can see exactly &lt;em&gt;what&lt;/em&gt; it did. But nowhere on-chain is it recorded &lt;em&gt;what it was authorised to do&lt;/em&gt;. The mandate — the rules the agent was supposed to operate under — lives off-chain, unverifiable, usually as a screenshot or a claim.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this is not a niche problem
&lt;/h2&gt;

&lt;p&gt;Copy trading is the same gap at retail scale, and the data is unforgiving. In a 90-day study of 100,236 copy-trading outcomes, 97% of lead traders were profitable on their own PnL — but only 43.6% produced positive PnL for the people copying them. Fewer than half of copiers (48.5%) finished in profit at all. Leaderboards, as that study puts it plainly, show the survivors, not the full picture.&lt;/p&gt;

&lt;p&gt;The honest response the industry already reaches for is third-party verification: in forex, platforms like Myfxbook exist precisely because a self-reported track record is worth nothing — the data has to come from somewhere the trader can't fake. Crypto has no equivalent that is both agent-native and tamper-evident. That is the hole.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who actually needs this
&lt;/h2&gt;

&lt;p&gt;Three groups, concretely:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Anyone allocating capital to an agent&lt;/strong&gt; — a vault depositor, a copy-follower, an allocator sizing a position. They want to see, before they commit, whether an agent keeps to its stated mandate, instead of trusting a screenshot.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Anyone running an agent who needs to raise capital or followers&lt;/strong&gt; — an honest operator has no way today to prove their agent did what it said. A verifiable record is how they separate themselves from the fakes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Agent marketplaces and DeFi protocols that list agents&lt;/strong&gt; — they can rank or gate by mandate-adherence instead of selling opacity, and flag agents with no committed mandate as higher risk.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What MoltProof does
&lt;/h2&gt;

&lt;p&gt;MoltProof is a read-only verifier. It does not trade, advise, or judge whether an agent made money. It answers exactly one question: did this agent keep the rules it publicly committed to?&lt;/p&gt;

&lt;p&gt;The flow:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The agent commits a mandate.&lt;/strong&gt; Before it trades, the agent publishes a signed, public credential (an AAE mandate — MANDATE / CONSTRAINTS / VALIDITY) declaring its rules: allowed venues, allowed output token, a position cap, a validity window. This is committed ex-ante and tied to the agent's DID / ERC-8004 identity.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;MoltProof reads the execution.&lt;/strong&gt; It resolves the agent's on-chain address, pulls its public execution from the chain within the validity window, and evaluates each action against the committed constraints.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It emits a verdict.&lt;/strong&gt; &lt;code&gt;ADHERENT&lt;/code&gt;, &lt;code&gt;BREACHED&lt;/code&gt;, &lt;code&gt;NO_MANDATE&lt;/code&gt;, or &lt;code&gt;NEEDS_REVIEW&lt;/code&gt; — and on a breach it cites the exact transaction that violated the rule.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The verdict is signed (Ed25519, resolvable via &lt;code&gt;did:web:moltrust.ch#moltproof-key-1&lt;/code&gt;) for portability, but the signature is not what you trust. Every verdict is &lt;strong&gt;recomputable&lt;/strong&gt; from public chain data plus the public mandate. If MoltProof were wrong, anyone could prove it by rerunning the check. You don't have to trust the verifier, and you don't have to trust the agent.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why it is structurally safe
&lt;/h2&gt;

&lt;p&gt;MoltProof reads. It never asks for a private key, an API key, or a wallet connection. It holds no funds, signs nothing on your behalf, and has no path to place or block an order. There is nothing to steal because it never has access to anything — it sits entirely downstream of execution. A compromised MoltProof endpoint still cannot touch your money; the worst it can do is return a wrong verdict, which is publicly falsifiable.&lt;/p&gt;

&lt;h2&gt;
  
  
  A live, recomputable example
&lt;/h2&gt;

&lt;p&gt;This is the demonstrator running on Base mainnet right now, not a mock.&lt;/p&gt;

&lt;p&gt;An agent commits a mandate with one constraint: &lt;strong&gt;it may only buy WETH.&lt;/strong&gt; Then it trades:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Three swaps buy WETH — within mandate.&lt;/li&gt;
&lt;li&gt;One swap buys something else (USDC) — outside mandate.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;MoltProof reads all four transactions from the chain and returns:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;verdict: BREACHED
evaluated: 4  ·  adherent: 3  ·  breached: 1
breach: 0xf6311aaeddde3a09ebd6967ad93547db64dfc76da935dcb706c56de31bb6ca68
        (output-token check failed: bought a non-WETH token)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Agent address: &lt;code&gt;0xD35AE5C22C117Cf1b9EF870697AB0034314A59e2&lt;/code&gt; (Base). The mandate, the four transactions, and the verdict are all public. Run the check yourself — no key, no signup:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.moltrust.ch/proof/verdict-free/0xD35AE5C22C117Cf1b9EF870697AB0034314A59e2
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The point of the example is not that the agent failed. The point is that the failure is provable by anyone, from public data, without trusting a word MoltProof or the agent says. The chain showed what the agent did; the committed mandate showed what it was allowed to do; MoltProof is the part in the middle that holds one against the other.&lt;/p&gt;

&lt;p&gt;Free endpoints: verdict, mandate lookup, and &lt;code&gt;/verify&lt;/code&gt; are free; deeper and full-history endpoints are $0.05 (x402 on Base). MCP tools (&lt;code&gt;moltproof_verdict&lt;/code&gt;, &lt;code&gt;_mandate&lt;/code&gt;, &lt;code&gt;_evidence&lt;/code&gt;, &lt;code&gt;_verify&lt;/code&gt;, &lt;code&gt;_registry&lt;/code&gt;) are live at &lt;code&gt;https://api.moltrust.ch/mcp&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it / integrate it
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Product page:&lt;/strong&gt; &lt;a href="https://moltrust.ch/moltproof.html" rel="noopener noreferrer"&gt;https://moltrust.ch/moltproof.html&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;API base (open, no key):&lt;/strong&gt; &lt;a href="https://api.moltrust.ch/proof/" rel="noopener noreferrer"&gt;https://api.moltrust.ch/proof/&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;One-line check:&lt;/strong&gt; &lt;code&gt;curl https://api.moltrust.ch/proof/verdict-free/0xD35AE5C22C117Cf1b9EF870697AB0034314A59e2&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;MCP endpoint:&lt;/strong&gt; &lt;code&gt;https://api.moltrust.ch/mcp&lt;/code&gt; — tools &lt;code&gt;moltproof_verdict&lt;/code&gt;, &lt;code&gt;_mandate&lt;/code&gt;, &lt;code&gt;_evidence&lt;/code&gt;, &lt;code&gt;_verify&lt;/code&gt;, &lt;code&gt;_registry&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Verify a verdict yourself:&lt;/strong&gt; &lt;code&gt;POST https://api.moltrust.ch/proof/verify&lt;/code&gt; (recompute + check the Ed25519 signature against &lt;code&gt;did:web:moltrust.ch#moltproof-key-1&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;




</description>
      <category>crypto</category>
      <category>ai</category>
      <category>web3</category>
      <category>agents</category>
    </item>
    <item>
      <title>If you build on Polymarket, you're trading on an estimate</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Wed, 08 Jul 2026 09:12:54 +0000</pubDate>
      <link>https://dev.to/moltycel/if-you-build-on-polymarket-youre-trading-on-an-estimate-2674</link>
      <guid>https://dev.to/moltycel/if-you-build-on-polymarket-youre-trading-on-an-estimate-2674</guid>
      <description>&lt;p&gt;&lt;em&gt;Every wash and cluster metric on-chain is an upper bound: nobody can prove who is behind the wallets. The exception is the agents that carry verifiable identity.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Prediction markets have gone from curiosity to infrastructure. Monthly notional volume across the major venues climbed from under $100 million in early 2024 to more than $13 billion by late 2025. With the volume comes the old question: how much of it is real?&lt;/p&gt;

&lt;p&gt;Through early and mid-2026, several teams took that question to Polymarket directly — wallet-level anomaly screens, order-flow skill classifiers, market-level information-leakage scores. Practitioners want the same thing in plainer terms: less headline volume, and more net notional settled, unique funded traders, and retention — the numbers that separate real participation from churn.&lt;/p&gt;

&lt;p&gt;Every one of these methods hits the same limit.&lt;/p&gt;

&lt;h2&gt;
  
  
  You can see the pattern. You cannot prove the operator.
&lt;/h2&gt;

&lt;p&gt;From pseudonymous on-chain data you can flag wallets that trade both sides without net exposure, or clusters of addresses that move together. What you cannot do is establish, from that data alone, that those addresses share one controller. The recent Polymarket work says so plainly: its wash figure is an upper bound, because counterparty identity cannot be pinned down from pseudonymous data without extra structure, and cluster attribution rests on an assumption about shared operators that the authors themselves call methodologically uncertain.&lt;/p&gt;

&lt;p&gt;So the output carries an asterisk. "Likely the same operator" is a fair analytical guess. It is not evidence — it will not settle a dispute between a platform and a trader, or convince a counterparty or supervisor who declines to take an analyst's word for it.&lt;/p&gt;

&lt;h2&gt;
  
  
  The missing structure is identity
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmi4ojrof6ox81n22tx1w.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmi4ojrof6ox81n22tx1w.png" alt="Inferred vs. proven operator attribution: dashed heuristic clusters with an unknown operator, versus solid links to a verifiable-identity badge." width="800" height="287"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If a participant carries a verifiable identity — an on-chain-anchored credential tying an agent to a controller and a mandate — the operator question is answered for that participant. The credential names the controller, and anyone can check it. For the identified part of the market, the guess becomes a fact: the identity attests that two wallets share an operator, and the attestation is verifiable by whoever needs it.&lt;/p&gt;

&lt;p&gt;This attribution has two properties a heuristic score does not. It is &lt;strong&gt;provable&lt;/strong&gt;, so it can hold up in a dispute. And it is &lt;strong&gt;recomputable&lt;/strong&gt;: any party re-derives it from anchored evidence instead of trusting a proprietary label. Recomputability is what we argued for in the recomputable-trust work — a check anyone can run for themselves, owned by no one.&lt;/p&gt;

&lt;h2&gt;
  
  
  MoltRadar
&lt;/h2&gt;

&lt;p&gt;That is what &lt;a href="https://moltrust.ch/moltguard.html#moltradar" rel="noopener noreferrer"&gt;MoltRadar&lt;/a&gt; is for, and it is out now. MoltRadar scans the on-chain ERC-8004 agent registry and makes the identified-agent layer visible: which agents carry a verifiable identity, and where. It maps the part of the market where the operator question is already answerable.&lt;/p&gt;

&lt;p&gt;The scope is narrow, and worth stating plainly. For anonymous wallets it changes nothing; the wall stands. For agents that carry identity, it removes a single uncertainty — operator attribution — and makes that removal checkable by anyone. It is not a fix for manipulation, and does not pretend to be.&lt;/p&gt;

&lt;p&gt;Today that identified part is small. It grows as more of the participants become agents — automated traders, and the multi-agent oracles now resolving markets — and as venues start requiring identity from the agents acting inside them. That is where the reliable measurements will come from first.&lt;/p&gt;

&lt;p&gt;Analytics on anonymous markets will keep improving. The question that has stayed stuck — who is behind the wallets — only moves once identity is present. That is what we build.&lt;/p&gt;

&lt;p&gt;If you build on this or study it — trading, oracles and resolution, venue integrity — we are glad to compare notes.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Sources&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Volume growth, from under $100M in early 2024 to more than $13B in monthly notional by November 2025: Dune × Keyrock, &lt;em&gt;Prediction Markets: The Next Frontier of Financial Markets&lt;/em&gt;, December 2025.&lt;/li&gt;
&lt;li&gt;The operator-attribution limit — wash figures reported as upper bounds, and cluster attribution described as methodologically uncertain because counterparty identity cannot be established from pseudonymous on-chain data without additional structure: M. Nechepurenko, &lt;em&gt;Fill-Side Non-Retail Trading on Polymarket&lt;/em&gt;, arXiv:2605.11640, May 2026 (§9.2).&lt;/li&gt;
&lt;li&gt;Recomputable trust: &lt;em&gt;Trust Without Trusting: A Recomputable Trust Protocol for Autonomous Agents&lt;/em&gt;, arXiv:2605.06738.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;MolTrust builds open, verifiable trust infrastructure for autonomous agents — W3C DID/VC identity, an IETF-published authorization envelope, and recomputable accountability, anchored on-chain. &lt;a href="https://moltrust.ch/moltguard.html#moltradar" rel="noopener noreferrer"&gt;MoltRadar&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>blockchain</category>
      <category>web3</category>
      <category>ai</category>
      <category>security</category>
    </item>
    <item>
      <title>Add trust verification to your CrewAI and LangChain agents in one line</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Wed, 01 Jul 2026 14:10:18 +0000</pubDate>
      <link>https://dev.to/moltycel/add-trust-verification-to-your-crewai-and-langchain-agents-in-one-line-399f</link>
      <guid>https://dev.to/moltycel/add-trust-verification-to-your-crewai-and-langchain-agents-in-one-line-399f</guid>
      <description>&lt;p&gt;Before your agent calls another agent, it should probably check whether that agent is actually trustworthy. Right now, it doesn't.&lt;/p&gt;

&lt;p&gt;This came up in &lt;a href="https://github.com/crewAIInc/crewAI/issues/4877" rel="noopener noreferrer"&gt;crewAI/issues/4877&lt;/a&gt; — a proposal for a &lt;code&gt;GuardrailProvider&lt;/code&gt; interface that sits between the hook system and authorization logic. The gap is real: existing guardrails validate output &lt;em&gt;after&lt;/em&gt; task completion. Tool-call authorization needs to happen &lt;em&gt;before&lt;/em&gt; execution, per call, across all tasks.&lt;/p&gt;

&lt;p&gt;We shipped a provider for it today.&lt;/p&gt;

&lt;h2&gt;
  
  
  CrewAI
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip &lt;span class="nb"&gt;install &lt;/span&gt;moltrust-crewai
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="n"&gt;moltrust_crewai&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;MolTrustGuardrail&lt;/span&gt;

&lt;span class="n"&gt;guard&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;MolTrustGuardrail&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;min_score&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;60&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;guard&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;install&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;  &lt;span class="c1"&gt;# registers before_tool_call hook
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Before every tool call, &lt;code&gt;MolTrustGuardrail&lt;/code&gt; resolves the calling agent's DID, checks its behavioral trust score (0–100) against the MolTrust registry, and returns &lt;code&gt;False&lt;/code&gt; to block if the score falls below your threshold. No API key required for read-only checks.&lt;/p&gt;

&lt;h2&gt;
  
  
  LangChain 1.x
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;pip &lt;span class="nb"&gt;install &lt;/span&gt;moltrust-langchain
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="n"&gt;moltrust_langchain&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;MolTrustMiddleware&lt;/span&gt;
&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="n"&gt;langchain.agents&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;create_agent&lt;/span&gt;

&lt;span class="n"&gt;agent&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;create_agent&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;model&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;anthropic:claude-sonnet-4-6&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;tools&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[...],&lt;/span&gt;
    &lt;span class="n"&gt;middleware&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nc"&gt;MolTrustMiddleware&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;min_score&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;60&lt;/span&gt;&lt;span class="p"&gt;)],&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Hooks into &lt;code&gt;before_model&lt;/code&gt; and &lt;code&gt;wrap_tool_call&lt;/code&gt;. Blocking raises &lt;code&gt;TrustCheckFailed&lt;/code&gt;; warning logs and continues.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three modes
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="nc"&gt;MolTrustGuardrail&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;min_score&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;60&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;action&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;block&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;   &lt;span class="c1"&gt;# "block" | "warn" | "log"
&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Start with &lt;code&gt;warn&lt;/code&gt; during rollout, move to &lt;code&gt;block&lt;/code&gt; when you understand your score distribution.&lt;/p&gt;

&lt;h2&gt;
  
  
  No account required to start
&lt;/h2&gt;

&lt;p&gt;Tier 1 is keyless — the trust score endpoint is public and rate-limited.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.moltrust.ch/skill/trust-score/&lt;span class="o"&gt;{&lt;/span&gt;did&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Tier 2 (free account) adds higher rate limits and lets your orchestrator report interaction outcomes back — that is where the feedback loop starts and scores get more precise over time.&lt;/p&gt;

&lt;h2&gt;
  
  
  How the score is computed
&lt;/h2&gt;

&lt;p&gt;0–100, based on endorsement graph, behavioral history, Sybil detection, and on-chain signals, with time-decayed weighting. The score is recomputable — formula and on-chain inputs are public:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.moltrust.ch/credits/solvency/&lt;span class="o"&gt;{&lt;/span&gt;did&lt;span class="o"&gt;}&lt;/span&gt;
&lt;span class="c"&gt;# Formula: github.com/MoltyCel/moltrust-api/blob/main/docs/solvency-usdc-v0.md&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  One note on Microsoft AGT
&lt;/h2&gt;

&lt;p&gt;AGT does policy enforcement — what an agent is &lt;em&gt;permitted&lt;/em&gt; to do. MolTrust does behavioral trust — &lt;em&gt;is&lt;/em&gt; this agent trustworthy, based on verifiable history. Different questions, clean composition.&lt;/p&gt;




&lt;p&gt;Source: &lt;a href="https://github.com/MoltyCel/moltrust-crewai" rel="noopener noreferrer"&gt;github.com/MoltyCel/moltrust-crewai&lt;/a&gt; · &lt;a href="https://github.com/MoltyCel/moltrust-langchain" rel="noopener noreferrer"&gt;github.com/MoltyCel/moltrust-langchain&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Full write-up: &lt;a href="https://moltrust.ch/blog/crewai-trust-middleware.html" rel="noopener noreferrer"&gt;moltrust.ch/blog/crewai-trust-middleware.html&lt;/a&gt;&lt;/p&gt;

</description>
      <category>crewai</category>
      <category>langchain</category>
      <category>python</category>
      <category>aiagents</category>
    </item>
    <item>
      <title>Hermes Agent's skill trust model is a four-repo allowlist</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Sat, 06 Jun 2026 21:18:54 +0000</pubDate>
      <link>https://dev.to/moltycel/hermes-agents-skill-trust-model-is-a-four-repo-allowlist-di</link>
      <guid>https://dev.to/moltycel/hermes-agents-skill-trust-model-is-a-four-repo-allowlist-di</guid>
      <description>&lt;p&gt;So far I've only been running openclaw agents and had a steep learning curve. "self-improvement" became a very attractive term on this journey. So I took a dive into Hermes Agent, the self-improving agent runtime from Nous Research. One of the first things I wanted to understand was a risk: what actually happens when you install a community skill? Skills are code and instructions that the agent will execute, and Hermes pulls them from an open ecosystem. So I read the install path in the source - instead of blindly trusting the docs.&lt;/p&gt;

&lt;p&gt;What I found is better than I expected in one way and structurally limited in another.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Hermes already has on board
&lt;/h2&gt;

&lt;p&gt;Hermes does not install external skills blindly. Every externally-sourced skill goes through a real gate before it lands on disk. In &lt;code&gt;hermes_cli/skills_hub.py&lt;/code&gt;, the install flow is: fetch → quarantine → scan → policy decision → install or block-and-audit. The scan lives in &lt;code&gt;tools/skills_guard.py&lt;/code&gt; and runs regex-based static analysis for known-bad patterns: secret exfiltration (&lt;code&gt;curl&lt;/code&gt; interpolating &lt;code&gt;$API_KEY&lt;/code&gt;/&lt;code&gt;$TOKEN&lt;/code&gt;/&lt;code&gt;$SECRET&lt;/code&gt;), reads of credential stores (&lt;code&gt;~/.ssh&lt;/code&gt;, &lt;code&gt;~/.aws&lt;/code&gt;, &lt;code&gt;~/.gnupg&lt;/code&gt;, &lt;code&gt;~/.kube&lt;/code&gt;, and Hermes's own &lt;code&gt;~/.hermes/.env&lt;/code&gt;), destructive commands, persistence, and obfuscation. If the scan blocks an install, the quarantined copy is deleted and the event is written to an audit log.&lt;/p&gt;

&lt;p&gt;This is more than most agent tooling ships with. If you remember the wave of malicious skills that hit competing ecosystems, a chunk of that class of attack would be caught here before anything ran. Someone thought about this.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part that doesn't scale imo
&lt;/h2&gt;

&lt;p&gt;The scanner produces a verdict — &lt;code&gt;safe&lt;/code&gt;, &lt;code&gt;caution&lt;/code&gt;, or &lt;code&gt;dangerous&lt;/code&gt;. That verdict is then combined with a &lt;em&gt;trust level&lt;/em&gt; to decide whether to install. The trust levels and their policies look like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="n"&gt;INSTALL_POLICY&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="c1"&gt;#              safe      caution    dangerous
&lt;/span&gt;    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;builtin&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;   &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;   &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;trusted&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;   &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;   &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;block&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;community&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;  &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;block&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;   &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;block&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;agent-created&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;allow&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;ask&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The question that matters is: how does a skill earn a trust level above &lt;code&gt;community&lt;/code&gt;? The answer is a hardcoded list.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="n"&gt;TRUSTED_REPOS&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;openai/skills&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;anthropics/skills&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;huggingface/skills&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;NVIDIA/skills&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;_resolve_trust_level()&lt;/code&gt; checks the source against that set. Match one of the four, you're &lt;code&gt;trusted&lt;/code&gt;. Everything else on earth resolves to &lt;code&gt;community&lt;/code&gt;, which means any &lt;code&gt;caution&lt;/code&gt;-or-worse finding blocks the install outright.&lt;/p&gt;

&lt;p&gt;Here's the structural problem stated plainly: &lt;strong&gt;there is no concept of publisher identity, and no concept of earned reputation.&lt;/strong&gt; A community publisher who has shipped clean, useful skills for a year has exactly the same standing as an account created five minutes ago. There is no path out of &lt;code&gt;community&lt;/code&gt; other than getting added to a four-entry Python set by the Hermes maintainers. Trust is centralized onto four organizations, and it's static.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why a static allowlist is the wrong primitive
&lt;/h2&gt;

&lt;p&gt;The software supply-chain world worked through "who published this, and can they prove it?" years ago. Sigstore and cosign made artifact signing cheap and keyless. SLSA gave us provenance levels. NIST's Secure Software Development Framework (SP 800-218) made publisher attestation a baseline expectation rather than a nice-to-have. The direction of travel everywhere else is &lt;em&gt;verifiable identity plus attestation&lt;/em&gt;, not a curated list of names.&lt;/p&gt;

&lt;p&gt;There's also a hard lesson about what identity does and doesn't buy you. Consider the xz-utils backdoor (CVE-2024-3094). The attacker behind the "Jia Tan" persona spent roughly three years contributing legitimate work to xz-utils, earned co-maintainer status, and only then shipped the backdoor — about eight malicious commits buried in years of real contributions. A reputation system would have rated that account highly right up until the moment it defected.&lt;/p&gt;

&lt;p&gt;The dishonest version of this pitch is everywhere: &lt;strong&gt;verified identity does not make a publisher safe.&lt;/strong&gt; It cannot. What it does is change the economics and the aftermath. Anonymous, free, infinitely re-creatable identities make a malicious skill a zero-cost, repeatable move. Anchored identity that costs something to establish turns defection into a one-shot that burns an asset. And critically, when something does go wrong, identity is what gives you attribution, revocation, and a post-mortem. Without it, you don't even know who shipped the thing, and you can't propagate a revocation to everyone who relied on it. The xz case is also a reminder that the sock-puppet accounts applying pressure had thin, recent histories — exactly the signal an identity layer surfaces.&lt;/p&gt;

&lt;p&gt;The honest framing: an identity layer is damage-limitation infrastructure, not a goodness oracle. A static allowlist gives you neither the goodness oracle (obviously) nor the damage-limitation (there's nothing to attribute or revoke against). It just doesn't scale with the ecosystem it's supposed to protect.&lt;/p&gt;

&lt;h2&gt;
  
  
  A smaller finding
&lt;/h2&gt;

&lt;p&gt;While reading the policy, one default stood out. The gate for &lt;em&gt;agent-created&lt;/em&gt; skills (&lt;code&gt;skills.guard_agent_created&lt;/code&gt;) is off by default. When it's off, skills the agent writes for itself aren't subject to the &lt;code&gt;dangerous&lt;/code&gt;-content gate at all. The &lt;code&gt;agent-created&lt;/code&gt; policy row exists, but it only runs if an operator opts in. For a system whose headline feature is an agent that writes and reuses its own skills, that default is worth a second look.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd propose instead
&lt;/h2&gt;

&lt;p&gt;The interesting thing is that Hermes already accepts signed skills — it just does it in a closed, per-repo way. The &lt;code&gt;NVIDIA/skills&lt;/code&gt; entry ships a signed &lt;code&gt;skill.oms.sig&lt;/code&gt; and a governance &lt;code&gt;skill-card.md&lt;/code&gt;, and the sync pipeline drops anything missing them. That's the right mechanism pointed at exactly one vendor.&lt;/p&gt;

&lt;p&gt;Generalize it. Make signing and identity open instead of hardcoded:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Add a pluggable provenance-verifier interface, loaded via entry point, &lt;strong&gt;off by default&lt;/strong&gt; (so existing behavior is unchanged and the core takes on no vendor dependency).&lt;/li&gt;
&lt;li&gt;Add one new trust level, &lt;code&gt;verified&lt;/code&gt;, with a policy &lt;em&gt;identical to&lt;/em&gt; &lt;code&gt;trusted&lt;/code&gt;: &lt;code&gt;("allow", "allow", "block")&lt;/code&gt;. This is the load-bearing design decision — a verified publisher gets &lt;code&gt;caution&lt;/code&gt; tolerance, and &lt;strong&gt;a &lt;code&gt;dangerous&lt;/code&gt; verdict still blocks, never overridable by &lt;code&gt;--force&lt;/code&gt;.&lt;/strong&gt; Identity buys you the benefit of the doubt on ambiguous findings; it never buys you permission to run dangerous code. That's the line that separates this from snake oil.&lt;/li&gt;
&lt;li&gt;A community publisher anchors a decentralized identifier, signs their skill manifest, and the verifier checks the signature and resolves the identity to a reputation. Pass, and the source can rise out of &lt;code&gt;community&lt;/code&gt; without being added to anyone's hardcoded set.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The change to the core is small and surgical: an optional verifier, one policy row, and a single line adding &lt;code&gt;verified&lt;/code&gt; to the no-force-override set for dangerous verdicts. The scanner is untouched and still runs on everything. There's no path that weakens an existing default.&lt;/p&gt;

&lt;p&gt;I've &lt;a href="https://github.com/NousResearch/hermes-agent/issues/40555" rel="noopener noreferrer"&gt;opened a design discussion&lt;/a&gt; to argue this out before anyone writes a line of it, because a surprise PR to a security-sensitive module is the wrong way to start. Feedback from people who've thought about supply-chain trust is what I appreciate.&lt;/p&gt;

&lt;h2&gt;
  
  
  Disclosure
&lt;/h2&gt;

&lt;p&gt;I build MolTrust, a DID/Verifiable-Credential identity layer for autonomous agents, so I have a direct interest in agents having a verifiable-identity story. I've tried to keep the proposal above vendor-neutral on purpose: the verifier interface is generic, the core change has no MolTrust dependency, and MolTrust would be one implementation of that interface, not a requirement. If the mechanism is right, it should work with anyone's verifier — or none.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>agents</category>
      <category>opensource</category>
    </item>
    <item>
      <title>We just joined the Agentic Trust Framework ecosystem — here's the technical mapping</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Thu, 21 May 2026 15:17:02 +0000</pubDate>
      <link>https://dev.to/moltycel/we-just-joined-the-agentic-trust-framework-ecosystem-heres-the-technical-mapping-136h</link>
      <guid>https://dev.to/moltycel/we-just-joined-the-agentic-trust-framework-ecosystem-heres-the-technical-mapping-136h</guid>
      <description>&lt;p&gt;69,000 bots. 165 million transactions. No shared trust layer between any of them.&lt;/p&gt;

&lt;p&gt;That's the production reality documented in our arXiv paper (&lt;a href="https://arxiv.org/abs/2605.06738" rel="noopener noreferrer"&gt;2605.06738&lt;/a&gt;). The &lt;a href="https://github.com/massivescale-ai/agentic-trust-framework" rel="noopener noreferrer"&gt;Agentic Trust Framework (ATF)&lt;/a&gt; maps what needs to exist to fix this. MolTrust is now listed as an ecosystem adopter — &lt;a href="https://github.com/massivescale-ai/agentic-trust-framework/issues/14" rel="noopener noreferrer"&gt;Issue #14&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The technical mapping across ATF's elements:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Identity (Element 1):&lt;/strong&gt; &lt;code&gt;did:moltrust:&lt;/code&gt; — W3C DID, Ed25519, Base L2 anchored. Submitted to W3C DID Method Registry (PR #696) and DIF Universal Resolver (PR #540).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Behavior (Element 2):&lt;/strong&gt; Agent Authorization Envelope (AAE) — &lt;code&gt;MANDATE / CONSTRAINTS / VALIDITY&lt;/code&gt;, machine-evaluable, on-chain anchored. Enforced at kernel level via Falco eBPF — below the agent process, not just at the API.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Segmentation (Element 4):&lt;/strong&gt; AAE &lt;code&gt;CONSTRAINTS&lt;/code&gt; block — value caps, domain allowlists, rate limits, time-bounded validity. Relying parties evaluate before processing.&lt;/p&gt;

&lt;p&gt;The distinction vs. hash-chain approaches: MolTrust trust scores are queryable by any third party at runtime. The audit trail is independently verifiable without access to MolTrust infrastructure.&lt;/p&gt;

&lt;p&gt;One timing note worth mentioning: IMDA published MGF v1.5 yesterday (ATxSummit, 20 May). §2.1.2 independently prescribes cryptographically verifiable agent identity and scoped, time-bound, least-privilege authorization — the same structure as AAE. Convergence from two directions simultaneously.&lt;/p&gt;

&lt;p&gt;Next: IETF Internet-Draft for the AAE spec (&lt;code&gt;draft-kroehl-agentic-trust-aae-03&lt;/code&gt;). If you're building in this space — agent authorization, identity, behavioral trust — the ATF repo is worth watching.&lt;/p&gt;

&lt;p&gt;Live registry: &lt;strong&gt;api.moltrust.ch&lt;/strong&gt; | Paper: &lt;strong&gt;arxiv.org/abs/2605.06738&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>did</category>
      <category>webstandards</category>
    </item>
    <item>
      <title>Registry Sprawl Is the New Agent Sprawl</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Thu, 16 Apr 2026 20:34:22 +0000</pubDate>
      <link>https://dev.to/moltycel/registry-sprawl-is-the-new-agent-sprawl-4jfa</link>
      <guid>https://dev.to/moltycel/registry-sprawl-is-the-new-agent-sprawl-4jfa</guid>
      <description>&lt;p&gt;Last week, AWS launched Agent Registry. Microsoft has Entra Agent Registry. Google has Vertex AI Agent Registry. All three solve the same problem — and all three create a new one.&lt;/p&gt;

&lt;p&gt;Forrester analysts noted that enterprises adopting all three registries in parallel could end up recreating the very fragmentation these tools are meant to solve.&lt;/p&gt;

&lt;p&gt;The mechanism is straightforward: platform-bound identity ends at the cloud boundary.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Core Problem
&lt;/h2&gt;

&lt;p&gt;AWS Agent Registry solves agent sprawl &lt;em&gt;inside&lt;/em&gt; AWS. An agent registered in Bedrock is discoverable to other Bedrock users. Governance is enforced. This is useful.&lt;/p&gt;

&lt;p&gt;But when Agent A (Bedrock) interacts with Agent B (Azure), the registry is invisible. Agent B doesn't appear in AgentCore. Agent A's identity is not verifiable from the Azure side. The governance layer ends at the cloud boundary.&lt;/p&gt;

&lt;p&gt;The result: enterprises need three separate registries that don't speak to each other. The fragmentation they bought registries to fix reappears one layer up.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Cross-Boundary Governance Actually Requires
&lt;/h2&gt;

&lt;p&gt;The problem is not that registries exist. The problem is that identity lives &lt;em&gt;in&lt;/em&gt; the registry rather than traveling &lt;em&gt;with&lt;/em&gt; the agent.&lt;/p&gt;

&lt;p&gt;An agent that carries its own cryptographically verifiable identity — independent of which cloud it runs on — can be verified by any counterparty without consulting a proprietary registry.&lt;/p&gt;

&lt;p&gt;This is what W3C Decentralized Identifiers (DIDs) and Verifiable Credentials provide. Forrester's AEGIS framework for agentic AI security identifies decentralized identifiers explicitly as a required standard in Section 3.2 — alongside OAuth, OIDC, and SCIM.&lt;/p&gt;

&lt;h2&gt;
  
  
  MolTrust as the Cross-Boundary Layer
&lt;/h2&gt;

&lt;p&gt;MolTrust is a production W3C DID registry for autonomous AI agents. Every registered agent holds a &lt;code&gt;did:moltrust&lt;/code&gt; identity — verifiable by any W3C-conformant verifier, without calling AWS, Microsoft, or Google.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Verify any agent's trust score — no API key required&lt;/span&gt;
curl https://api.moltrust.ch/skill/trust-score/did:moltrust:vcone
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The Agent Authorization Envelope (AAE) carries the permission model — what the agent is allowed to do, in which jurisdictions, up to which spend thresholds. Interaction Proof Records provide behavioral history, anchored on Base L2.&lt;/p&gt;

&lt;p&gt;An agent registered in Bedrock and verified by MolTrust carries credentials that an Azure-hosted counterparty can validate independently. The two registries don't need to federate. The identity layer is already shared.&lt;/p&gt;

&lt;h2&gt;
  
  
  Platform Registries + Open Identity = Complete Stack
&lt;/h2&gt;

&lt;p&gt;Platform registries and open identity infrastructure are not competing — they address different layers:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Layer&lt;/th&gt;
&lt;th&gt;What it answers&lt;/th&gt;
&lt;th&gt;Example&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Platform Registry&lt;/td&gt;
&lt;td&gt;What agents exist inside our org&lt;/td&gt;
&lt;td&gt;AWS Agent Registry&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Open Identity&lt;/td&gt;
&lt;td&gt;Who is this agent, can I trust it&lt;/td&gt;
&lt;td&gt;MolTrust (W3C DID)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Enterprises that deploy both get internal discoverability from the platform registry and cross-boundary verifiability from the open identity layer.&lt;/p&gt;

&lt;p&gt;The registry sprawl problem has a structural solution. It requires identity that travels with the agent, not identity that lives in the registry.&lt;/p&gt;




&lt;p&gt;Full technical specification: &lt;a href="https://moltrust.ch/techspec" rel="noopener noreferrer"&gt;moltrust.ch/techspec&lt;/a&gt;&lt;br&gt;
Reference implementation: &lt;a href="https://api.moltrust.ch" rel="noopener noreferrer"&gt;api.moltrust.ch&lt;/a&gt;&lt;br&gt;
&lt;em&gt;MolTrust / CryptoKRI GmbH — &lt;a href="mailto:info@moltrust.ch"&gt;info@moltrust.ch&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>agents</category>
      <category>identity</category>
      <category>web3</category>
      <category>security</category>
    </item>
    <item>
      <title>MoltID: Agent Type Classification, Cascade Revocation &amp; SPIFFE Bridge — Live on MolTrust</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Wed, 15 Apr 2026 19:43:52 +0000</pubDate>
      <link>https://dev.to/moltycel/moltid-agent-type-classification-cascade-revocation-spiffe-bridge-live-on-moltrust-1e8h</link>
      <guid>https://dev.to/moltycel/moltid-agent-type-classification-cascade-revocation-spiffe-bridge-live-on-moltrust-1e8h</guid>
      <description>&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;Today we're launching &lt;strong&gt;MoltID&lt;/strong&gt; -- MolTrust's Agent Identity &amp;amp; Governance module.&lt;/p&gt;

&lt;p&gt;Three features ship today:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Agent Type Classification&lt;/strong&gt; -- classify agents as orchestrator, autonomous, human_initiated, or copilot, with governance rules and trust modifiers per type&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cascade Revocation&lt;/strong&gt; -- revoke a compromised agent and its entire downstream delegation tree in one API call (DFS, max 8 hops, CAEP events)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SPIFFE Bridge&lt;/strong&gt; -- map existing SPIFFE URIs to W3C DIDs, enriched with MolTrust trust scores and classification&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;All live. All W3C standards. All anchored on Base L2.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Problem
&lt;/h2&gt;

&lt;p&gt;AI agent deployments are growing fast -- and so is the governance gap.&lt;/p&gt;

&lt;p&gt;An orchestrator spawns sub-agents. Sub-agents delegate further. Before long you have a delegation tree of autonomous actors making decisions, calling APIs, moving value -- with no structured identity layer underneath.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;94%&lt;/strong&gt; of organizations experienced AI agent security incidents (OutSystems 2026)&lt;/li&gt;
&lt;li&gt;Only &lt;strong&gt;12%&lt;/strong&gt; have a central governance platform&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;MoltID is the missing layer.&lt;/p&gt;




&lt;h2&gt;
  
  
  Feature 1: Agent Type Classification
&lt;/h2&gt;

&lt;h3&gt;
  
  
  The idea
&lt;/h3&gt;

&lt;p&gt;Not all agents carry the same trust assumptions. An orchestrator coordinating a multi-agent workflow is fundamentally different from a copilot suggesting edits to a human user.&lt;/p&gt;

&lt;p&gt;MoltID formalizes this with four agent classes:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Class&lt;/th&gt;
&lt;th&gt;Description&lt;/th&gt;
&lt;th&gt;Trust Modifier&lt;/th&gt;
&lt;th&gt;Min Trust Score&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;orchestrator&lt;/td&gt;
&lt;td&gt;Coordinates other agents&lt;/td&gt;
&lt;td&gt;+5&lt;/td&gt;
&lt;td&gt;70&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;autonomous&lt;/td&gt;
&lt;td&gt;Self-directed, no human loop&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;td&gt;60&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;human_initiated&lt;/td&gt;
&lt;td&gt;Triggered by a human action&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;td&gt;50&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;copilot&lt;/td&gt;
&lt;td&gt;Human-assisted, advisory&lt;/td&gt;
&lt;td&gt;-10&lt;/td&gt;
&lt;td&gt;40&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  API
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Set agent class&lt;/span&gt;
POST /identity/agent-type/did:moltrust:abc123
Authorization: Bearer &amp;lt;api_key&amp;gt;
&lt;span class="o"&gt;{&lt;/span&gt;
  &lt;span class="s2"&gt;"agent_class"&lt;/span&gt;: &lt;span class="s2"&gt;"orchestrator"&lt;/span&gt;,
  &lt;span class="s2"&gt;"framework"&lt;/span&gt;: &lt;span class="s2"&gt;"langchain"&lt;/span&gt;,
  &lt;span class="s2"&gt;"version"&lt;/span&gt;: &lt;span class="s2"&gt;"0.2.1"&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Read class + governance rules&lt;/span&gt;
GET /identity/agent-type/did:moltrust:abc123
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"did"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:abc123"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"agent_class"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"orchestrator"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"trust_modifier"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"governance"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"min_trust_score"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;70&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"review_frequency"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"weekly"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"audit_required"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# List all types&lt;/span&gt;
GET /identity/agent-types
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  A2A Agent Card integration
&lt;/h3&gt;

&lt;p&gt;The agent class is exposed in the per-DID A2A Agent Card at /a2a/agent-card/{did}:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"agent_classification"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"class"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"orchestrator"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"framework"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"langchain"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"governance_tier"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"high"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"trust_modifier"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Machine-readable for any A2A-compatible system.&lt;/p&gt;

&lt;h3&gt;
  
  
  CAEP events
&lt;/h3&gt;

&lt;p&gt;Every class change fires an agent_class_changed event to the caep_events table -- full audit trail.&lt;/p&gt;




&lt;h2&gt;
  
  
  Feature 2: Cascade Revocation
&lt;/h2&gt;

&lt;h3&gt;
  
  
  The idea
&lt;/h3&gt;

&lt;p&gt;When an agent is compromised, you need more than a point revocation. You need to revoke the entire downstream delegation tree.&lt;/p&gt;

&lt;p&gt;MoltID tracks delegation relationships in agent_delegations and supports cascade revocation with a single API call.&lt;/p&gt;

&lt;h3&gt;
  
  
  API
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Revoke single agent&lt;/span&gt;
POST /identity/revoke/did:moltrust:abc123
Authorization: Bearer &amp;lt;api_key&amp;gt;
&lt;span class="o"&gt;{&lt;/span&gt; &lt;span class="s2"&gt;"reason"&lt;/span&gt;: &lt;span class="s2"&gt;"credential leaked"&lt;/span&gt; &lt;span class="o"&gt;}&lt;/span&gt;

&lt;span class="c"&gt;# Cascade revoke (revokes target + all downstream delegated agents)&lt;/span&gt;
POST /identity/revoke/did:moltrust:abc123
Authorization: Bearer &amp;lt;api_key&amp;gt;
&lt;span class="o"&gt;{&lt;/span&gt; &lt;span class="s2"&gt;"reason"&lt;/span&gt;: &lt;span class="s2"&gt;"compromised"&lt;/span&gt;, &lt;span class="s2"&gt;"cascade"&lt;/span&gt;: &lt;span class="nb"&gt;true&lt;/span&gt; &lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Response:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"revoked"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:abc123"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"affected_agents"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"did"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:abc123"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"depth"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"did"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:child-agent-1"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"depth"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"did"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:child-agent-2"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"depth"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"count"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Check revocation status&lt;/span&gt;
GET /identity/revocation-status/did:moltrust:abc123
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"revoked"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"revoked_at"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2026-04-15T..."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"downstream_delegations"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# View delegation tree&lt;/span&gt;
GET /identity/delegations/did:moltrust:abc123

&lt;span class="c"&gt;# Reinstate (admin only)&lt;/span&gt;
POST /identity/unrevoke/did:moltrust:abc123
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Cascade mechanics
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;DFS traversal of agent_delegations table&lt;/li&gt;
&lt;li&gt;Max 8 hops (configurable)&lt;/li&gt;
&lt;li&gt;Visited-set prevents cycles&lt;/li&gt;
&lt;li&gt;Children fetched before delegation records are revoked (ordering guarantee)&lt;/li&gt;
&lt;li&gt;Every revoked agent: trust_score goes to 0.0, grade becomes "REVOKED", trust cache invalidated&lt;/li&gt;
&lt;li&gt;CAEP event per revoked agent&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Trust score integration
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"did"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:revoked-agent"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"trust_score"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;0.0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"grade"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"REVOKED"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"breakdown"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"revoked"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"reason"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"compromised"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"flags"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"revoked"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Short-circuits before Phase 2 computation. No stale cached scores.&lt;/p&gt;




&lt;h2&gt;
  
  
  Feature 3: SPIFFE Bridge
&lt;/h2&gt;

&lt;h3&gt;
  
  
  The idea
&lt;/h3&gt;

&lt;p&gt;Enterprise infrastructure already has workload identity: &lt;strong&gt;SPIFFE&lt;/strong&gt; (Secure Production Identity Framework for Everyone). Kubernetes clusters, Istio service meshes, and Vault integrations all issue SPIFFE URIs natively.&lt;/p&gt;

&lt;p&gt;The SPIFFE Bridge maps these URIs to MolTrust W3C DIDs -- no migration required.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;spiffe://company.com/agent/trading-bot-01
  |  bind once
  v
did:moltrust:abc123
  |  enriched with
  v
trust score + agent class + revocation status + on-chain VC
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  API
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Bind a SPIFFE URI to an existing DID&lt;/span&gt;
POST /identity/spiffe/bind
Authorization: Bearer &amp;lt;api_key&amp;gt;
&lt;span class="o"&gt;{&lt;/span&gt;
  &lt;span class="s2"&gt;"spiffe_uri"&lt;/span&gt;: &lt;span class="s2"&gt;"spiffe://company.com/agent/trading-bot-01"&lt;/span&gt;,
  &lt;span class="s2"&gt;"did"&lt;/span&gt;: &lt;span class="s2"&gt;"did:moltrust:abc123"&lt;/span&gt;
&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# Resolve SPIFFE URI to DID + full MoltID context&lt;/span&gt;
GET /identity/spiffe/spiffe://company.com/agent/trading-bot-01
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"spiffe_uri"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"spiffe://company.com/agent/trading-bot-01"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"moltrust_did"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:abc123"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"display_name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Trading Bot 01"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"trust_score"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;82.5&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"grade"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"A"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"agent_classification"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"agent_class"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"autonomous"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"governance"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"cascade_revocation_priority"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"high"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"min_trust_score_required"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;50&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"review_frequency_days"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;90&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"revoked"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"bound_at"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2026-04-15T..."&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="c"&gt;# List all bindings&lt;/span&gt;
GET /identity/spiffe
Authorization: Bearer &amp;lt;api_key&amp;gt;

&lt;span class="c"&gt;# Remove binding (admin)&lt;/span&gt;
DELETE /identity/spiffe/bind/spiffe://company.com/agent/trading-bot-01
Authorization: Bearer &amp;lt;admin_key&amp;gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  What's deferred to Q3
&lt;/h3&gt;

&lt;p&gt;Full SPIFFE stack (SVID issuance, Workload API, X.509-SVID signing) is Q3 2026. The bridge covers the lookup/binding layer only -- enough for most enterprise integration use cases.&lt;/p&gt;




&lt;h2&gt;
  
  
  Regulatory alignment: IMDA MGF
&lt;/h2&gt;

&lt;p&gt;The Singapore IMDA Model AI Governance Framework for Agentic AI (January 2026) defines four governance requirements for agentic systems:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;IMDA Requirement&lt;/th&gt;
&lt;th&gt;MoltID Implementation&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Accountability&lt;/td&gt;
&lt;td&gt;Every agent has a classified DID, anchored on Base L2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Transparency&lt;/td&gt;
&lt;td&gt;Agent class + trust score publicly queryable&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Controllability&lt;/td&gt;
&lt;td&gt;Cascade revocation -- kill switch across full delegation tree&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Human oversight&lt;/td&gt;
&lt;td&gt;human_initiated / copilot classes enforce review cadences&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;MoltID doesn't just align with the framework -- it implements it as code.&lt;/p&gt;




&lt;h2&gt;
  
  
  Getting Started
&lt;/h2&gt;

&lt;h3&gt;
  
  
  npm
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;npm &lt;span class="nb"&gt;install&lt;/span&gt; @moltrust/sdk
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;





&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;AgentTrust&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;@moltrust/sdk&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;trust&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;AgentTrust&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;verify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="s1"&gt;did:moltrust:abc123&lt;/span&gt;&lt;span class="dl"&gt;'&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;trust&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;agent_class&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;    &lt;span class="c1"&gt;// "orchestrator"&lt;/span&gt;
&lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;trust&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;trust_modifier&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt; &lt;span class="c1"&gt;// 5&lt;/span&gt;
&lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;trust&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;revoked&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;        &lt;span class="c1"&gt;// false&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  REST
&lt;/h3&gt;

&lt;p&gt;All endpoints live at &lt;a href="https://api.moltrust.ch" rel="noopener noreferrer"&gt;https://api.moltrust.ch&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Full API docs: &lt;a href="https://api.moltrust.ch/docs" rel="noopener noreferrer"&gt;api.moltrust.ch/docs&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Enterprise
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://moltrust.ch/enterprise" rel="noopener noreferrer"&gt;moltrust.ch/enterprise&lt;/a&gt; -- or reach out at &lt;a href="mailto:enterprise@moltrust.ch"&gt;enterprise@moltrust.ch&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  What's Next
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Q3 2026&lt;/strong&gt;: Full SPIFFE/SVID Workload API&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Q3 2026&lt;/strong&gt;: ACP (Agent Communication Protocol) alignment&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Q3 2026&lt;/strong&gt;: On-chain anchoring for all classification events (ZeroID v2)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Now&lt;/strong&gt;: &lt;a href="https://github.com/MoltyCel" rel="noopener noreferrer"&gt;GitHub&lt;/a&gt; -- PRs and issues welcome&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;MolTrust is W3C DID/Verifiable Credential trust infrastructure for autonomous AI agents, anchored on Base L2. Built by CryptoKRI GmbH, Zurich.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://moltrust.ch" rel="noopener noreferrer"&gt;moltrust.ch&lt;/a&gt; | &lt;a href="https://www.npmjs.com/org/moltrust" rel="noopener noreferrer"&gt;npm&lt;/a&gt; | &lt;a href="https://moltrust.ch/enterprise" rel="noopener noreferrer"&gt;enterprise&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>identity</category>
      <category>security</category>
    </item>
    <item>
      <title>Mapping MolTrust to the AIP Protocol Feature Set — and Beyond</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Mon, 13 Apr 2026 10:17:32 +0000</pubDate>
      <link>https://dev.to/moltycel/mapping-moltrust-to-the-aip-protocol-feature-set-and-beyond-lp4</link>
      <guid>https://dev.to/moltycel/mapping-moltrust-to-the-aip-protocol-feature-set-and-beyond-lp4</guid>
      <description>&lt;p&gt;A recent arXiv paper — &lt;em&gt;AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A&lt;/em&gt; (arXiv:2603.24775) — scans ~2,000 MCP servers, finds zero with authentication, and concludes:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"We did not identify a prior implemented protocol that jointly combines public-key verifiable delegation, holder-side attenuation, expressive chained policy, transport bindings across MCP/A2A/HTTP, and provenance-oriented completion records."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;MolTrust implements these five features in production since March 2026. Here is how each one maps — and where the paper has the technical edge.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Five Features
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;F1 — Public-key verifiable delegation&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Every MolTrust agent holds a W3C DID (&lt;code&gt;did:moltrust:&amp;lt;id&amp;gt;&lt;/code&gt;) with an Ed25519 key. Delegation is expressed as an Agent Authorization Envelope (AAE) — a structured policy object signed by the delegating principal. Each link in a delegation chain is independently verifiable without calling a central service.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"validity"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"issuer"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:&amp;lt;principal&amp;gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"holderBinding"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:&amp;lt;agent&amp;gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"issuedAt"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2026-03-25T00:00:00Z"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"expiresAt"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2026-03-26T00:00:00Z"&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;F2 — Holder-side attenuation&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;code&gt;delegation.attenuationOnly: true&lt;/code&gt; is the default. A sub-agent AAE must be a strict subset of its parent's effective allowed actions, limits, and jurisdiction scope. Enforced by conformant AAE evaluators — not by policy.&lt;/p&gt;

&lt;p&gt;Our conformance test vector TV-005 covers exactly this: a sub-agent AAE attempting to exceed parent scope is correctly rejected.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;F3 — Expressive chained policy (within a URI-pattern model)&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The AAE &lt;code&gt;constraints&lt;/code&gt; block covers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Spend limits (&lt;code&gt;autonomousThreshold&lt;/code&gt;, &lt;code&gt;stepUpThreshold&lt;/code&gt;, &lt;code&gt;approvalThreshold&lt;/code&gt;) in USDC/EUR/CHF/USD&lt;/li&gt;
&lt;li&gt;Jurisdiction restrictions (ISO 3166-1 alpha-2)&lt;/li&gt;
&lt;li&gt;Time windows (&lt;code&gt;allowedDays&lt;/code&gt;, &lt;code&gt;allowedHours&lt;/code&gt;, &lt;code&gt;timezone&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Counterparty minimum trust score gate&lt;/li&gt;
&lt;li&gt;Resource-level ABAC via &lt;code&gt;mandate.resources&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Chains up to 8 hops, each link independently signed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Honest note:&lt;/strong&gt; For complex conditional authorization — recursive rules, temporal Datalog — IBCTs are technically stronger. Biscuit/Datalog is on our roadmap (H2 2026).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;F4 — Transport bindings across MCP/A2A/HTTP&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;HTTP: &lt;code&gt;@moltrust/sdk&lt;/code&gt; v1.1.0 — &lt;code&gt;middleware()&lt;/code&gt; / &lt;code&gt;register()&lt;/code&gt; / &lt;code&gt;verify()&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;MPP/x402: &lt;code&gt;@moltrust/mpp&lt;/code&gt; v1.0.3 — &lt;code&gt;requireScore({ minScore, failBehavior })&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;MCP: 48-tool server on PyPI (&lt;code&gt;@moltrust/openclaw&lt;/code&gt; v0.1.0)&lt;/li&gt;
&lt;li&gt;A2A: active thread at a2aproject/A2A#1628; referenced in OpenClaw RFC #49971 for agent identity binding&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;F5 — Provenance-oriented completion records&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Interaction Proof Records (IPRs) use sequential dual-signature: the responder signs over the initiator's signature, not a parallel scheme. This means fabricating a bilateral proof requires controlling two distinct signing keys.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"InteractionProof"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"id"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"&amp;lt;uuid-v4&amp;gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"outcome"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"completed"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"outcomeHash"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"sha256:&amp;lt;SHA-256 of canonical outcome object&amp;gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"proofInitiator"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"proofValue"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"&amp;lt;initiator-sig&amp;gt;"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"proofResponder"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"proofValue"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"&amp;lt;responder-sig-over-initiator-sig&amp;gt;"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Proofs are Merkle batch-anchored on Base L2.&lt;/p&gt;




&lt;h2&gt;
  
  
  Verify It Yourself
&lt;/h2&gt;

&lt;p&gt;TechSpec v0.8 is anchored at Base L2 Block 44638521:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://basescan.org/tx/0x0b36c7718632fa71bff67e22fdd3615408243b3c178819a9f1e340d526378d65
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Decode the calldata — it contains &lt;code&gt;MolTrust/DocumentIntegrity/1 SHA256:cbf10c2e...&lt;/code&gt;. Recompute the SHA-256 of the PDF. They match. No proprietary tooling required.&lt;/p&gt;




&lt;h2&gt;
  
  
  What We Add Beyond the Five Features
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Capability&lt;/th&gt;
&lt;th&gt;AIP&lt;/th&gt;
&lt;th&gt;MolTrust&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Trust scoring&lt;/td&gt;
&lt;td&gt;✗&lt;/td&gt;
&lt;td&gt;0–100, endorsement graph + sybil detection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Behavioral continuity&lt;/td&gt;
&lt;td&gt;✗&lt;/td&gt;
&lt;td&gt;Principal DID continuity across re-registrations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sybil resistance&lt;/td&gt;
&lt;td&gt;✗&lt;/td&gt;
&lt;td&gt;Dual-sig proofs + x402 cost + Jaccard detection&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;On-chain anchoring&lt;/td&gt;
&lt;td&gt;✗&lt;/td&gt;
&lt;td&gt;Base L2, any block explorer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Offline verification&lt;/td&gt;
&lt;td&gt;Python/Rust reference impl&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;@moltrust/verify&lt;/code&gt; v1.1.0, no API calls&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;W3C alignment&lt;/td&gt;
&lt;td&gt;Custom token format&lt;/td&gt;
&lt;td&gt;DID Core v1.0 + VC Data Model 2.0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  In Production
&lt;/h2&gt;

&lt;p&gt;aeoess — an A2A-based agent platform — runs trust verification through MolTrust with a live webhook integration for grade changes and revocation events.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Relationship
&lt;/h2&gt;

&lt;p&gt;AIP formalizes the constraint model with precision. MolTrust provides the operational infrastructure. A production agent economy needs both.&lt;/p&gt;

&lt;p&gt;Full conformance report (feature matrix, test vectors TV-001–TV-005, bash verification recipe):&lt;br&gt;
👉 &lt;a href="https://github.com/MoltyCel/moltrust-api/blob/main/CONFORMANCE.md" rel="noopener noreferrer"&gt;CONFORMANCE.md on GitHub&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Reference implementation: &lt;a href="https://api.moltrust.ch" rel="noopener noreferrer"&gt;api.moltrust.ch&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;MolTrust is open source (Apache 2.0). Contact: &lt;a href="mailto:info@moltrust.ch"&gt;info@moltrust.ch&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>agents</category>
      <category>identity</category>
      <category>web3</category>
      <category>security</category>
    </item>
    <item>
      <title>MolTrust OpenClaw Plugin v1.0.0 — Agent Trust Verification for OpenClaw</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Sat, 11 Apr 2026 10:20:21 +0000</pubDate>
      <link>https://dev.to/moltycel/moltrust-openclaw-plugin-v100-agent-trust-verification-for-openclaw-m9j</link>
      <guid>https://dev.to/moltycel/moltrust-openclaw-plugin-v100-agent-trust-verification-for-openclaw-m9j</guid>
      <description>&lt;h1&gt;
  
  
  MolTrust OpenClaw Plugin v1.0.0 — Agent Trust Verification for OpenClaw
&lt;/h1&gt;

&lt;p&gt;&lt;em&gt;Published by MolTrust / CryptoKRI GmbH · April 2026&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;OpenClaw agents can hold wallets, execute payments, and install skills autonomously. That's powerful — and it's exactly why trust verification matters. In early 2026, hundreds of malicious skills were identified on ClawHub: credential stealers, data exfiltration tools, prompt injection attacks. MolTrust adds a cryptographic trust layer to address this directly.&lt;/p&gt;

&lt;h2&gt;
  
  
  Install
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;openclaw plugins &lt;span class="nb"&gt;install&lt;/span&gt; @moltrust/openclaw
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Restart your Gateway. That's it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it does
&lt;/h2&gt;

&lt;p&gt;Once active, your OpenClaw agent gets two tools and two slash commands:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Tools (available to the LLM):&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;moltrust_verify&lt;/code&gt; — verify any agent's W3C DID identity before delegating tasks or payments&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;moltrust_trust_score&lt;/code&gt; — get a 0–100 reputation score combining on-chain signals, Verifiable Credentials, and behavioral history&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Slash commands (work in any channel):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;/trust did:moltrust:abc123     — verify a DID
/trustscore 0x3802...          — score by wallet (free, no key needed)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;CLI:&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;openclaw moltrust status           &lt;span class="c"&gt;# check API connectivity&lt;/span&gt;
openclaw moltrust verify &amp;lt;did&amp;gt;     &lt;span class="c"&gt;# verify a DID&lt;/span&gt;
openclaw moltrust score &amp;lt;&lt;span class="nb"&gt;id&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;       &lt;span class="c"&gt;# get trust score&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  How trust scores work
&lt;/h2&gt;

&lt;p&gt;Scores combine four signals:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Behavioral&lt;/strong&gt; — task success rate, policy violations, interaction history&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;On-chain credentials&lt;/strong&gt; — W3C Verifiable Credentials anchored on Base L2, JWKS-verified&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;On-chain activity&lt;/strong&gt; — x402 payment events, IPR anchoring (800+ records, Merkle-based)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Endorsement graph&lt;/strong&gt; — MoltGraph 2-hop propagation with 45-day half-life decay and Sybil detection&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Scores are cached for 5 minutes. Self-reported scores are always re-verified server-side — a client cannot spoof its own score.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Score&lt;/th&gt;
&lt;th&gt;Grade&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;80–100&lt;/td&gt;
&lt;td&gt;A&lt;/td&gt;
&lt;td&gt;Trusted&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;60–79&lt;/td&gt;
&lt;td&gt;B&lt;/td&gt;
&lt;td&gt;Generally trustworthy&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;40–59&lt;/td&gt;
&lt;td&gt;C&lt;/td&gt;
&lt;td&gt;Proceed with caution&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;0–39&lt;/td&gt;
&lt;td&gt;D/F&lt;/td&gt;
&lt;td&gt;High risk&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Configuration
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"plugins"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"entries"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"moltrust"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"enabled"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"config"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="nl"&gt;"apiKey"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"mt_live_..."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="nl"&gt;"minTrustScore"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;40&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="nl"&gt;"verifyOnStart"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="nl"&gt;"agentDid"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"did:moltrust:your-agent-did"&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Get a free API key at &lt;a href="https://api.moltrust.ch" rel="noopener noreferrer"&gt;api.moltrust.ch&lt;/a&gt;.&lt;br&gt;&lt;br&gt;
&lt;strong&gt;Free tier:&lt;/strong&gt; wallet shadow scores require no API key — just &lt;code&gt;/trustscore 0x...&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this matters for the agent economy
&lt;/h2&gt;

&lt;p&gt;As agent-to-agent commerce grows — x402 micropayments, A2A delegation, MCP tool calls — the question &lt;em&gt;"should I trust this agent?"&lt;/em&gt; becomes infrastructure-level. Transport-layer trust (HTTPS, OAuth) covers authorization but not agent identity or behavioral history.&lt;/p&gt;

&lt;p&gt;MolTrust is the W3C DID/VC-based answer:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Open standard&lt;/strong&gt; — W3C DIDs and Verifiable Credentials, not proprietary&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;On-chain anchoring&lt;/strong&gt; — Base L2, tamper-evident audit trail&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No vendor lock-in&lt;/strong&gt; — any registry provider can implement the same API contract&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Composable&lt;/strong&gt; — works alongside x402, A2A, MCP without replacing them&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The plugin is MIT licensed. Source on GitHub: &lt;a href="https://github.com/MoltyCel/moltrust-openclaw" rel="noopener noreferrer"&gt;MoltyCel/moltrust-openclaw&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Links
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;📦 npm: &lt;a href="https://npmjs.com/package/@moltrust/openclaw" rel="noopener noreferrer"&gt;&lt;code&gt;@moltrust/openclaw&lt;/code&gt;&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;🔧 API: &lt;a href="https://api.moltrust.ch" rel="noopener noreferrer"&gt;api.moltrust.ch&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📖 Docs: &lt;a href="https://moltrust.ch/developers" rel="noopener noreferrer"&gt;moltrust.ch/developers&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📄 Protocol Whitepaper v0.8: &lt;a href="https://moltrust.ch/MolTrust_Protocol_Whitepaper_v0.8.pdf" rel="noopener noreferrer"&gt;moltrust.ch/MolTrust_Protocol_Whitepaper_v0.8.pdf&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;🏷️ Badge: &lt;a href="https://moltrust.ch/badge/" rel="noopener noreferrer"&gt;moltrust.ch/badge/{did}&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;




&lt;p&gt;&lt;em&gt;MolTrust is a W3C DID/Verifiable Credential trust infrastructure for AI agents, built by CryptoKRI GmbH (Zürich). Live at &lt;a href="https://moltrust.ch" rel="noopener noreferrer"&gt;moltrust.ch&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>security</category>
      <category>blockchain</category>
    </item>
    <item>
      <title>How we made MolTrust A2A v0.3 conformant</title>
      <dc:creator>Lars</dc:creator>
      <pubDate>Sat, 11 Apr 2026 03:10:53 +0000</pubDate>
      <link>https://dev.to/moltycel/how-we-made-moltrust-a2a-v03-conformant-e3f</link>
      <guid>https://dev.to/moltycel/how-we-made-moltrust-a2a-v03-conformant-e3f</guid>
      <description>&lt;p&gt;The A2A protocol's Agent Card is how agents discover each other's capabilities. It's a JSON file at &lt;code&gt;/.well-known/agent-card.json&lt;/code&gt; — a structured business card for your agent.&lt;/p&gt;

&lt;p&gt;MolTrust had a minimal version. Here's what A2A v0.3 conformant looks like — 5 skills, structured capabilities, a custom trust-score extension.&lt;/p&gt;

&lt;h2&gt;
  
  
  Key structural changes
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;code&gt;version&lt;/code&gt; means A2A protocol version ("0.3"), not API version&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;provider&lt;/code&gt; is a required object with organization name&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;capabilities&lt;/code&gt; is structured with extensions support&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;skills&lt;/code&gt; replaces flat capabilities with queryable declarations&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;securitySchemes&lt;/code&gt; follows OpenAPI 3.0 format&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The MolTrust extension
&lt;/h2&gt;

&lt;p&gt;A2A v0.3 supports custom extensions via &lt;code&gt;capabilities.extensions&lt;/code&gt;. We use this to tell clients how to integrate trust scoring — an orchestrator that reads this knows how to gate agent interactions on trust score without reading our docs.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's still missing
&lt;/h2&gt;

&lt;p&gt;A2A has authorization schemes on its roadmap but hasn't specified them yet. We'll define how AAE tokens travel in A2A task metadata once that lands.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;curl https://api.moltrust.ch/.well-known/agent-card.json | python3 &lt;span class="nt"&gt;-m&lt;/span&gt; json.tool
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Full TechSpec (Section 8.8): &lt;a href="https://moltrust.ch" rel="noopener noreferrer"&gt;moltrust.ch&lt;/a&gt;&lt;br&gt;
GitHub: &lt;a href="https://github.com/MoltyCel/moltrust-protocol" rel="noopener noreferrer"&gt;github.com/MoltyCel/moltrust-protocol&lt;/a&gt;&lt;/p&gt;

</description>
      <category>a2a</category>
      <category>agentidentity</category>
      <category>webdev</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
