diff --git a/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/01-landing.webp b/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/01-landing.webp new file mode 100644 index 0000000..64f14de Binary files /dev/null and b/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/01-landing.webp differ diff --git a/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/02-three-hosts.webp b/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/02-three-hosts.webp new file mode 100644 index 0000000..b7361b8 Binary files /dev/null and b/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/02-three-hosts.webp differ diff --git a/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/03-attack-fail-closed.webp b/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/03-attack-fail-closed.webp new file mode 100644 index 0000000..198cc15 Binary files /dev/null and b/public/assets/img/blog/agent-mcp-exact-ref-2026-10-09/03-attack-fail-closed.webp differ diff --git a/public/llms.txt b/public/llms.txt index 8bd5ffe..ece3e6e 100644 --- a/public/llms.txt +++ b/public/llms.txt @@ -22,9 +22,10 @@ Current packages: crates.io Traverse at 0.14.0; npm `traverse-embedder-web@0.14. - [What does “the agent proposes; the runtime decides” mean?](https://traverse-framework.com/questions/what-does-agent-proposes-runtime-decides-mean.html): boundary in one page — agents search/plan/suggest; runtime validates, executes or denies, leaves a trace. - [What is one shared runtime.wasm?](https://traverse-framework.com/questions/what-is-one-shared-runtime-wasm.html): embedders are clients; honest consumer list. - [The agent freestyled a $2.4M wire. The runtime said no.](https://traverse-framework.com/blog/agent-freestyle-blocked.html): project direction in one scene — agent proposes, runtime decides (deny + trace). +- [Agent speaks MCP. Exact pin kills the freestyle.](https://traverse-framework.com/blog/agent-mcp-exact-ref.html): v0.14.0 weekly demo — an agent calls MCP-shaped tools (façade over `ExactModelBrowserHost` under Node, not the Mode A `traverse-mcp` binary) against the signed `digits-mlp-1.0.0` package; Browser + Node bit-identical; tamper → `digest_mismatch`, empty trust → `key_untrusted`, rights lie → `rights_mismatch`; test-only key (prod signing #1567). Not catalog `model.execute`. Not Hugging Face. - [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html): v0.14.0 weekly demo — signed `digits-mlp-1.0.0` exact-ref package, same bytes on Browser + Node (`ExactModelBrowserHost`); tamper → `digest_mismatch`; test-only key (prod signing #1567). Not catalog `model.execute`. Not Hugging Face. - [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html): v0.13.0 multi-host — identical `core.authorize@1.2.0` bytes on Browser + Node; agent treasury cheat still denied. -- Weekly demos (public write-ups; repo still private): [signed exact-ref digits](https://traverse-framework.com/blog/signed-exact-ref-digits.html) · [same-wasm multi-host](https://traverse-framework.com/blog/same-wasm-multi-host.html) · [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html) · [How do I run the deny demo?](https://traverse-framework.com/questions/how-do-i-run-the-agent-blocked-weekly-demo.html). Note: `traverse-framework/weekly-demos` is **not publicly cloneable yet** (tracked in [.github#30](https://github.com/traverse-framework/.github/issues/30)) — prefer the blogs until that lands. Access-only tree for this week: `weekly-demos/2026-10-02-signed-exact-ref`. +- Weekly demos (public write-ups; repo still private): [agent MCP exact-ref](https://traverse-framework.com/blog/agent-mcp-exact-ref.html) · [signed exact-ref digits](https://traverse-framework.com/blog/signed-exact-ref-digits.html) · [same-wasm multi-host](https://traverse-framework.com/blog/same-wasm-multi-host.html) · [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html) · [How do I run the deny demo?](https://traverse-framework.com/questions/how-do-i-run-the-agent-blocked-weekly-demo.html). Note: `traverse-framework/weekly-demos` is **not publicly cloneable yet** (tracked in [.github#30](https://github.com/traverse-framework/.github/issues/30)) — prefer the blogs until that lands. Access-only tree for this week: `weekly-demos/2026-10-09-agent-mcp-exact-ref`. - [Platforms](https://traverse-framework.com/platforms.html): native + browser shipped; Swift/Kotlin/.NET published, pre-1.0, In progress (not Certified); edge planned; cloud non-goal. ## Start here @@ -37,7 +38,7 @@ Current packages: crates.io Traverse at 0.14.0; npm `traverse-embedder-web@0.14. ## Building with an agent -- **Direction (same as Required reading above):** [signed exact-ref digits](https://traverse-framework.com/blog/signed-exact-ref-digits.html) · [same-wasm multi-host](https://traverse-framework.com/blog/same-wasm-multi-host.html) · [deny demo blog](https://traverse-framework.com/blog/agent-freestyle-blocked.html) · [what-is-real-today](https://traverse-framework.com/what-is-real-today.html) · [run the deny demo (blog-first; weekly-demos not public yet)](https://traverse-framework.com/questions/how-do-i-run-the-agent-blocked-weekly-demo.html). +- **Direction (same as Required reading above):** [agent MCP exact-ref](https://traverse-framework.com/blog/agent-mcp-exact-ref.html) · [signed exact-ref digits](https://traverse-framework.com/blog/signed-exact-ref-digits.html) · [same-wasm multi-host](https://traverse-framework.com/blog/same-wasm-multi-host.html) · [deny demo blog](https://traverse-framework.com/blog/agent-freestyle-blocked.html) · [what-is-real-today](https://traverse-framework.com/what-is-real-today.html) · [run the deny demo (blog-first; weekly-demos not public yet)](https://traverse-framework.com/questions/how-do-i-run-the-agent-blocked-weekly-demo.html). - [For AI Agents](https://traverse-framework.com/agents.html): the real MCP tool list (ten commands: describe_server, list_content_groups, describe_content_group, list_entrypoints, search_capabilities, describe_entrypoint, validate_entrypoint, execute_entrypoint, render_execution_report, shutdown), the discover-inspect-execute-trace flow, and the honest limits (stdio is the packaged bootstrap today; in-process library functions exist on traverse-mcp, but there is no separate HTTP MCP listener as a packaged product). - [traverse-framework/claude-skills](https://github.com/traverse-framework/claude-skills): Claude Skills for building apps with Traverse — starting with `traverse-capability-author` (plus extractor and workflow-planner), which checks the registry before authoring, produces contract + WASM, and validates against the real traverse-cli — including this platform's current execution limitations. - [How do I author a capability in plain English?](https://traverse-framework.com/questions/how-do-i-author-a-capability-in-plain-english.html): Claude skill `traverse-capability-author` — interview → registry check → contract → WASM → human-reviewed PR; under the hood still Rust→WASM; manual Rust is secondary. @@ -77,7 +78,7 @@ Current packages: crates.io Traverse at 0.14.0; npm `traverse-embedder-web@0.14. ## Optional -- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html) (deprecation and revocation leave the contract in place; ranges skip the marker; exact pins in `traverse-registry` 0.27.0 still resolve with lifecycle status, registry#632, #631 closed; runtime refusal is traverse#1598, not shipped in v0.14.0). Also: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; published exact-ref is native+web+Swift ExactModelHost on `swift-host-v0.14.0-4`; Kotlin and .NET ExactModelHost are on main, not in Maven/NuGet 0.14.0, #1651; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html). +- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [Agent speaks MCP. Exact pin kills the freestyle.](https://traverse-framework.com/blog/agent-mcp-exact-ref.html) (v0.14.0 weekly demo; Browser+Node+MCP-shaped agent façade; three fail-closed attacks; test-only key). Also: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html) (deprecation and revocation leave the contract in place; ranges skip the marker; exact pins in `traverse-registry` 0.27.0 still resolve with lifecycle status, registry#632, #631 closed; runtime refusal is traverse#1598, not shipped in v0.14.0). Also: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; published exact-ref is native+web+Swift ExactModelHost on `swift-host-v0.14.0-4`; Kotlin and .NET ExactModelHost are on main, not in Maven/NuGet 0.14.0, #1651; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html). - [Discover](https://traverse-framework.com/discover.html): a live browser demo that pulls the public registry and executes a reviewed plan locally. Read [what it proves](https://traverse-framework.com/blog/what-discover-proves.html) before quoting it. - [Compare: vs microservices](https://traverse-framework.com/compare/vs-microservices.html), [vs serverless](https://traverse-framework.com/compare/vs-serverless.html), [vs function calling](https://traverse-framework.com/compare/vs-function-calling.html), [vs agent runtimes](https://traverse-framework.com/compare/vs-agent-runtimes.html), [vs WASM runtimes](https://traverse-framework.com/compare/vs-wasm-runtimes.html), [vs cross-platform frameworks](https://traverse-framework.com/compare/vs-cross-platform-frameworks.html) - [About](https://traverse-framework.com/about.html): project history and motivation. diff --git a/src/pages/blog/agent-mcp-exact-ref.astro b/src/pages/blog/agent-mcp-exact-ref.astro new file mode 100644 index 0000000..de22393 --- /dev/null +++ b/src/pages/blog/agent-mcp-exact-ref.astro @@ -0,0 +1,192 @@ +--- +import SubpageLayout from '@layouts/SubpageLayout.astro'; + +const _body = ` +
+
+
+ + + Demo + Agents + Models +
+

Agent speaks MCP. Exact pin kills the freestyle.

+ +
+
+ +
+
+ +
+ +

Last week a signed model ran bit-identical on Browser and Node. This week an agent gets the same package through MCP-shaped tool calls — and tries to cheat. It tampers a WASM byte, empties the trust roots, and lies about rights. Every attempt fails closed with a stable reason. The legitimate classify still matches Browser and Node byte for byte.

+ +
+ Short version: one signed digits-mlp-1.0.0 package, one manifest pin, one shared runtime.wasm. Browser, Node, and an agent over MCP-shaped JSON-RPC all hit the same ExactModelBrowserHost from traverse-embedder-web@0.14.0. Tamper → digest_mismatch. Empty trust → key_untrusted. Rights lie → rights_mismatch. The agent proposes; the runtime decides. +
+ +

Public proof is this write-up and the screenshots. The runnable folder weekly-demos/2026-10-09-agent-mcp-exact-ref is for people who already have access (access required, repo private). weekly-demos is still not publicly cloneable (.github#30). There is no public-clone CTA.

+ +
+ Agent MCP exact-ref demo landing: agent freestyle blocked banner, Browser host, Node proof and Agent MCP transcript columns +
Landing: the agent-freestyle banner, then three columns — Browser host, Node proof, Agent MCP transcript — on one pin digest.
+
+ +

What the agent gets

+ +

The agent sees MCP-shaped tools: exact_model_register, exact_model_execute, exact_model_rights. JSON-RPC initialize, then tools/call. Behind them is the published ExactModelBrowserHost running under Node — the same host and the same package bytes the Browser column uses.

+ +

Be precise about what that column is. It is an in-process MCP-shaped façade over the published web exact-ref host. It is not the checksum-pinned Mode A traverse-mcp binary. Pinning and verifying that packaged binary is the longer-term story, not this week’s proof.

+ +

What happened

+ +
+ + + + + + + + + + + + +
CheckResult
Node classifyDigits 0 → 0, 7 → 7, 4 → 4. Output frames match the conformance fixture byte for byte (hexMatch).
Browser ↔ NodeLabel 0 on the Browser host is bit-identical to the Node case.
Agent MCP executeexact_model_execute → predicted 0, same output_frame_hex, hexMatch.
Agent: tamper one WASM byteFail closed. model_incompatible / digest_mismatch.
Agent: empty trust rootsFail closed. model_incompatible / key_untrusted.
Agent: rights liePin claims commercial_use: forbidden against a package that says otherwise. Fail closed. model_incompatible / rights_mismatch.
+
+ +
+ Three hosts agree: digit 0 predicted 0, Browser, Node and Agent MCP output hex bit-identical +
Three hosts agree: Browser ↔ Node ↔ Agent MCP on the same output hex for label 0.
+
+ +
+ Agent freestyle fail-closed: ExactModelError digest_mismatch after a one-byte WASM tamper, plus key_untrusted and rights_mismatch in the MCP transcript +
Freestyle fail-closed: one WASM byte swapped → digest_mismatch. The MCP transcript also shows key_untrusted and rights_mismatch.
+
+ +

Why the pin wins

+ +

The agent controls its tool arguments. It does not control the pin, the signature, or the host’s trust roots. The pin binds the SHA-256 of the manifest bytes. An Ed25519 model.sig.json must verify against a key the host trusts. The signed package’s rights must match what the pin declares. Break any one and nothing executes. One shared runtime.wasm; hosts are UI + I/O. Discover → execute → trace.

+ +

Facts for agents

+ +
+
    +
  • Theme: Agent speaks MCP. Exact pin kills the freestyle (week of 2026-10-09).
  • +
  • Public proof: this post and its screenshots. Runnable tree (access required, repo private): 2026-10-09-agent-mcp-exact-ref. Not a public clone — .github#30.
  • +
  • Product pins: Traverse v0.14.0 @ 4dac877c2fe0b28491848016747850ae31327ebc. npm traverse-embedder-web@0.14.0.
  • +
  • Model: traverse.digits-mlp@1.0.0 (digits-mlp-1.0.0). Manifest schema 2.0.0. Governing spec 138-governed-exact-model-execution.
  • +
  • Manifest / pin sha256: 3068f3ae464fbbb43b45b089ab225a1371060a94a214c10629b4d8e402e8eadf
  • +
  • WASM sha256: 6eeea06029ce4210842edfe70d7e0d8d7e926953ead5f18a0dca3c351ad5dc88
  • +
  • Agent column: MCP-shaped JSON-RPC tools (exact_model_register, exact_model_execute, exact_model_rights) over the published ExactModelBrowserHost under Node. Not the Mode A traverse-mcp binary.
  • +
  • Smoke: 0→0, 7→7, 4→4 on Node (hexMatch); Browser label 0 bit-identical to Node; MCP execute matches. Tamper → digest_mismatch; empty trust → key_untrusted; rights lie → rights_mismatch.
  • +
  • Signing key: test-only fixture. Production signing is traverse#1567. Do not trust this key in a real host.
  • +
  • Not claimed: Hugging Face. Catalog model.execute (the catalog still has none). A checksum-pinned Mode A traverse-mcp binary. Swift, Kotlin, or .NET exact-ref execute on the published 0.14.0 pins. Unreleased main work. A separate runtime.
  • +
  • Lead claim: one shared runtime.wasm. Hosts = UI + I/O. Discover → execute → trace. The agent proposes; the runtime decides.
  • +
+
+ +

Same signed bytes. Three callers. The agent can ask for anything — only the exact pin runs.

+ +
+ + + +
+
+ +
+
+

Agent proposes. Pin decides.

+

Browser, Node, and an MCP-shaped agent share one signed model package. Tamper, empty trust, or a rights lie fails closed.

+
+ For AI agents → + Last week’s demo → + Weekly demos are blog-first → +
+
+
+`; +--- + + + + diff --git a/src/pages/blog/index.astro b/src/pages/blog/index.astro index a29e4c5..c242c7f 100644 --- a/src/pages/blog/index.astro +++ b/src/pages/blog/index.astro @@ -2,6 +2,7 @@ import SubpageLayout from '@layouts/SubpageLayout.astro'; const posts = [ + { href: '/blog/agent-mcp-exact-ref.html', title: 'Agent speaks MCP. Exact pin kills the freestyle.', desc: 'Featured · Oct 9 · Weekly demo: an agent calls MCP-shaped tools over ExactModelBrowserHost against the signed digits-mlp-1.0.0 package. Browser + Node bit-identical; tamper → digest_mismatch, empty trust → key_untrusted, rights lie → rights_mismatch. Traverse v0.14.0. Test-only key. Not the Mode A traverse-mcp binary.' }, { href: '/blog/you-dont-edit-a-published-capability.html', title: "You don't edit a published capability. You mark it.", desc: 'Featured · Oct 8 · Deprecation and revocation leave the contract in place. Ranges skip the marker. Exact pins in traverse-registry 0.27.0 still resolve with lifecycle status (registry#632). Runtime refusal is traverse#1598, not shipped in v0.14.0.' }, { href: '/blog/model-rights-are-data.html', title: 'Model rights are data, not a README', desc: 'Featured · Oct 6 · AI model rights from contract to host: offline publish checks, signed registry rights record, host trust roots, and what is still open.' }, { href: '/blog/signed-exact-ref-digits.html', title: 'Signed model. Exact pin. Bit-identical hosts.', desc: 'Featured · Weekly demo: signed digits-mlp-1.0.0 exact-ref package, same bytes on Browser + Node via ExactModelBrowserHost; tamper fail-closed (digest_mismatch). Traverse v0.14.0. Test-only key.' },