CAIN-42 CAIN Studio

CAIN-42 invariant · E31

E31-MK-security_test: security_test: artifacts carry provenance and untested ones stay UNVERIFIED

Held · CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric

Last reviewed 2026-10-01

held   niche Transactions, markets & economics · family marketplace

What this rule means

CAIN-42 must always satisfy: security_test: artifacts carry provenance and untested ones stay UNVERIFIED. It is one of 252 invariants checked for CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric. An invariant is a rule the system may never break, whatever an agent or attacker does; the test suite tries to break it across many scenarios and records the result.

Recorded detail

{'body': {'category': 'security_test', 'name': 'x', 'digest': 'dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd', 'publisher': 'uerBkHnsrge6laVewU+bvN52zW36by7rZfLnDthTdH8='}, 'signature_b64': 'ZEQQpeojfPrgVygx2UGiRh1PUkyW9d

Verify it in your browser

Your browser downloads the bundle's SHA256SUMS manifest and the file(s) behind this page, hashes them with SHA-256 locally (WebCrypto), and compares. A match shows the record you are reading is the published one; it does not by itself prove who published it (see the signed claims registry and the bundle verifier for that).

Check it yourself

Browse the raw bundle · How to reproduce it · SHA-256 manifest

Scope: An in-process TESTED library; not hosted; not wired into the gateway, MCPGate or the clusters.

Related rules

← E31-MK-evidence_validator · all 252 · E31-MK-agent_connector →

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem