Evidence library · niche
Tools, MCP, protocols & adapters
How agents reach tools, APIs and each other, safely. 684 tested invariants.
Last reviewed 2026-10-01
684 of 684 held
Test families in this niche
adapter (270) · protocol_domain (56) · discovery (36) · abi (28) · interchange (28) · universal_action (20) · routing (19) · sdk (19) · gateway (19) · gip_carrier (16) · channel (14) · overlay_protocol (13) · uact (12) · route (12) · runtime_adapter (12) · agency_graph (12) · runtime_swap (9) · message_class (9) · runtime_binding (8) · protocol_conformance (8) · operation_kind (8) · edge (6) · abi_error (5) · action (5) · carrier (3) · radar (3) · telemetry (2) · moat (2) · competitive_gap (2) · risk (1) · translation (1) · out_of_band (1) · reassessment (1) · integrity (1) · developer (1) · gap_detector (1) · ip (1) · lab (1) · physical_hybrid (1) · protocol (1)
Where these come from
- CAIN-42 Evolution 25 -- Universal Machine Agency Fabric: 270
- CAIN-42 Evolution 33 -- Governed Agentic Operating Fabric: 109
- CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric: 63
- CAIN-42 Evolution 34 -- Proof-Carrying Machine Agency: 40
- CAIN-42 Evolution 27 -- Agentic Internet Control Plane: 36
- CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric: 24
- CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric: 23
- CAIN-42 Evolution 32 -- Governed Autonomy Learning Fabric: 22
- CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric: 21
- CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform: 19
- CAIN-42 Evolution 41 -- Machine Agency Exchange Fabric: 18
- CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric: 16
- CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric: 7
- CAIN-42 Evolution 21 -- Governed Open-Ended Intelligence Fabric: 5
- CAIN-42 Evolution 23 -- Governed Meta-Intelligence Fabric: 3
- CAIN-42 Evolution 28 -- Portable Machine Agency & Execution Identity: 3
- CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency: 2
- CAIN-42 Evolution 19 -- Governed Autonomy Operating Fabric: 1
- CAIN-42 Evolution 20 -- Governed Agentic Civilization Fabric: 1
- CAIN-42 Evolution 39 -- Governed Agent Factory: 1
Rules 301–450 of 684
| ID | Rule | Bundle | Result |
|---|---|---|---|
| I-OOB-gateway-unenforced | gateway without enforcer UNENFORCED | E26 | held |
| I-REASSESS-runtime_change | trigger runtime_change | E26 | held |
| I-RIB-same | unchanged binding valid | E26 | held |
| I-RIB-agent | changed agent invalidates | E26 | held |
| I-RIB-runtime | changed runtime invalidates | E26 | held |
| I-RIB-model | changed model invalidates | E26 | held |
| I-RIB-configuration | changed configuration invalidates | E26 | held |
| I-RIB-capabilities | changed capabilities invalidates | E26 | held |
| I-RIB-deployment | changed deployment invalidates | E26 | held |
| I-RIB-environment | changed environment invalidates | E26 | held |
| I-DISC-0 | discovery grants no authority | E27 | held |
| I-DISC-1 | discovery grants no authority | E27 | held |
| I-DISC-2 | discovery grants no authority | E27 | held |
| I-DISC-3 | discovery grants no authority | E27 | held |
| I-DISC-4 | discovery grants no authority | E27 | held |
| I-DISC-5 | discovery grants no authority | E27 | held |
| I-DISC-6 | discovery grants no authority | E27 | held |
| I-DISC-7 | discovery grants no authority | E27 | held |
| I-DISC-8 | discovery grants no authority | E27 | held |
| I-DISC-9 | discovery grants no authority | E27 | held |
| I-ROUTE-configure | route configure | E27 | held |
| I-ROUTE-create | route create | E27 | held |
| I-ROUTE-credential | route credential | E27 | held |
| I-ROUTE-delegate | route delegate | E27 | held |
| I-ROUTE-delete | route delete | E27 | held |
| I-ROUTE-deploy | route deploy | E27 | held |
| I-ROUTE-destroy | route destroy | E27 | held |
| I-ROUTE-execute | route execute | E27 | held |
| I-ROUTE-list | route list | E27 | held |
| I-ROUTE-notify | route notify | E27 | held |
| I-ROUTE-observe | route observe | E27 | held |
| I-ROUTE-pay | route pay | E27 | held |
| I-ROUTE-query | route query | E27 | held |
| I-ROUTE-read | route read | E27 | held |
| I-ROUTE-send | route send | E27 | held |
| I-ROUTE-submit | route submit | E27 | held |
| I-ROUTE-transfer | route transfer | E27 | held |
| I-ROUTE-write | route write | E27 | held |
| I-TELEM-tool | telemetry tool | E27 | held |
| I-TELEM-mcp | telemetry mcp | E27 | held |
| I-EDGE-FAIL_CLOSED | mode FAIL_CLOSED does not allow by default | E27 | held |
| I-EDGE-FAIL_SAFE | mode FAIL_SAFE does not allow by default | E27 | held |
| I-EDGE-CACHE_LIMITED | mode CACHE_LIMITED does not allow by default | E27 | held |
| I-EDGE-DEGRADED | mode DEGRADED does not allow by default | E27 | held |
| I-EDGE-OFFLINE_VERIFIABLE | mode OFFLINE_VERIFIABLE does not allow by default | E27 | held |
| I-EDGE-offline-valid | valid offline authorization allows | E27 | held |
| E28-I28 | every protocol carrier round-trips the envelope byte-identically | E28 | held |
| E28-I29 | a carrier altered in transit never yields a valid envelope | E28 | held |
| E28-I30 | an unknown protocol has no carrier | E28 | held |
| E30-UMA-principal | the UMA digest binds 'principal' | E30 | held |
| E30-UMA-identity | the UMA digest binds 'identity' | E30 | held |
| E30-UMA-intent | the UMA digest binds 'intent' | E30 | held |
| E30-UMA-context | the UMA digest binds 'context' | E30 | held |
| E30-UMA-observation | the UMA digest binds 'observation' | E30 | held |
| E30-UMA-memory | the UMA digest binds 'memory' | E30 | held |
| E30-UMA-model | the UMA digest binds 'model' | E30 | held |
| E30-UMA-runtime | the UMA digest binds 'runtime' | E30 | held |
| E30-UMA-capability | the UMA digest binds 'capability' | E30 | held |
| E30-UMA-delegation | the UMA digest binds 'delegation' | E30 | held |
| E30-UMA-policy | the UMA digest binds 'policy' | E30 | held |
| E30-UMA-authority | the UMA digest binds 'authority' | E30 | held |
| E30-UMA-risk | the UMA digest binds 'risk' | E30 | held |
| E30-UMA-consequence | the UMA digest binds 'consequence' | E30 | held |
| E30-UMA-transaction | the UMA digest binds 'transaction' | E30 | held |
| E30-UMA-environment | the UMA digest binds 'environment' | E30 | held |
| E30-UMA-action | the UMA digest binds 'action' | E30 | held |
| E30-UMA-execution | the UMA digest binds 'execution' | E30 | held |
| E30-UMA-outcome | the UMA digest binds 'outcome' | E30 | held |
| E30-UMA-evidence | the UMA digest binds 'evidence' | E30 | held |
| E30-SDK-SEALED | an SDK-wrapped tool runs only inside the E8 boundary for an allowed call | E30 | held |
| E31-GIP-mcp | CAIN-GIP carrier mcp round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-a2a | CAIN-GIP carrier a2a round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-http | CAIN-GIP carrier http round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-rest | CAIN-GIP carrier rest round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-grpc | CAIN-GIP carrier grpc round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-websocket | CAIN-GIP carrier websocket round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-event_bus | CAIN-GIP carrier event_bus round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-message_queue | CAIN-GIP carrier message_queue round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-cli | CAIN-GIP carrier cli round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-browser | CAIN-GIP carrier browser round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-computer_use | CAIN-GIP carrier computer_use round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-local_ipc | CAIN-GIP carrier local_ipc round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-cloud_api | CAIN-GIP carrier cloud_api round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-agent_runtime | CAIN-GIP carrier agent_runtime round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-model_runtime | CAIN-GIP carrier model_runtime round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-GIP-workflow_engine | CAIN-GIP carrier workflow_engine round-trips or is reported NOT IMPLEMENTED | E31 | held |
| E31-PC-real_proof_verifies | CAIN-GIP real_proof_verifies on every carrier | E31 | held |
| E31-PC-carrier_roundtrip | CAIN-GIP carrier_roundtrip on every carrier | E31 | held |
| E31-PC-carrier_occupied | CAIN-GIP carrier_occupied on every carrier | E31 | held |
| E31-PC-gip_blocks_separate | CAIN-GIP gip_blocks_separate on every carrier | E31 | held |
| E31-PC-transit_tamper | CAIN-GIP transit_tamper on every carrier | E31 | held |
| E31-PC-wrong_carrier | CAIN-GIP wrong_carrier on every carrier | E31 | held |
| E31-PC-protocol_bound | CAIN-GIP protocol_bound on every carrier | E31 | held |
| E31-PC-failure_proof_verifies | CAIN-GIP failure_proof_verifies on every carrier | E31 | held |
| E32-RUNTIME-python | python swap never inherits authority | E32 | held |
| E32-RUNTIME-node_v8 | node_v8 swap never inherits authority | E32 | held |
| E32-RUNTIME-container | container swap never inherits authority | E32 | held |
| E32-RUNTIME-os | os swap never inherits authority | E32 | held |
| E32-RUNTIME-browser | browser swap never inherits authority | E32 | held |
| E32-RUNTIME-cloud_runtime | cloud_runtime swap never inherits authority | E32 | held |
| E32-RUNTIME-agent_framework | agent_framework swap never inherits authority | E32 | held |
| E32-RUNTIME-tool_runtime | tool_runtime swap never inherits authority | E32 | held |
| E32-RUNTIME-orchestration_engine | orchestration_engine swap never inherits authority | E32 | held |
| E32-OVERLAY-mcp | the promoted overlay applies over mcp | E32 | held |
| E32-OVERLAY-a2a | the promoted overlay applies over a2a | E32 | held |
| E32-OVERLAY-http | the promoted overlay applies over http | E32 | held |
| E32-OVERLAY-rest | the promoted overlay applies over rest | E32 | held |
| E32-OVERLAY-grpc | the promoted overlay applies over grpc | E32 | held |
| E32-OVERLAY-websocket | the promoted overlay applies over websocket | E32 | held |
| E32-OVERLAY-event_bus | the promoted overlay applies over event_bus | E32 | held |
| E32-OVERLAY-message_queue | the promoted overlay applies over message_queue | E32 | held |
| E32-OVERLAY-cli | the promoted overlay applies over cli | E32 | held |
| E32-OVERLAY-browser | the promoted overlay applies over browser | E32 | held |
| E32-OVERLAY-computer_use | the promoted overlay applies over computer_use | E32 | held |
| E32-OVERLAY-local_ipc | the promoted overlay applies over local_ipc | E32 | held |
| E32-OVERLAY-cloud_api | the promoted overlay applies over cloud_api | E32 | held |
| E33-KIND-send_message | send_message is executed only through E8 | E33 | held |
| E33-KIND-invoke_tool | invoke_tool is executed only through E8 | E33 | held |
| E33-KIND-call_api | call_api is executed only through E8 | E33 | held |
| E33-KIND-modify_policy | modify_policy is routed to E32 CAINEvolutionPromotionGate | E33 | held |
| E33-KIND-change_runtime | change_runtime is routed to E32 CAINSwapGovernance | E33 | held |
| E33-KIND-control_physical_actuator | control_physical_actuator is executed only through E8 | E33 | held |
| E33-KIND-create_organization | create_organization is routed to E29 MachineOrganizationBudget (human) | E33 | held |
| E33-KIND-propose_governance_evolution | propose_governance_evolution is routed to E32 CAINEvolutionPromotionGate | E33 | held |
| E33-ROUTE-low_risk | route low_risk keeps its required controls | E33 | held |
| E33-ROUTE-high_risk | route high_risk keeps its required controls | E33 | held |
| E33-ROUTE-physical | route physical keeps its required controls | E33 | held |
| E33-ROUTE-financial | route financial keeps its required controls | E33 | held |
| E33-ROUTE-privileged | route privileged keeps its required controls | E33 | held |
| E33-ROUTE-research | route research keeps its required controls | E33 | held |
| E33-ROUTE-code_execution | route code_execution keeps its required controls | E33 | held |
| E33-ROUTE-deployment | route deployment keeps its required controls | E33 | held |
| E33-ROUTE-memory_mutation | route memory_mutation keeps its required controls | E33 | held |
| E33-ROUTE-policy_mutation | route policy_mutation keeps its required controls | E33 | held |
| E33-ROUTE-governance_mutation | route governance_mutation keeps its required controls | E33 | held |
| E33-ROUTE-communication | route communication keeps its required controls | E33 | held |
| E33-CHANNEL-a2a | channel a2a is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-mcp | channel mcp is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-http | channel http is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-rest | channel rest is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-websocket | channel websocket is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-event_bus | channel event_bus is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-message_queue | channel message_queue is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-local_ipc | channel local_ipc is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-file | channel file is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-database | channel database is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-shared_memory | channel shared_memory is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-browser | channel browser is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-collaboration | channel collaboration is classified, consequential use only if governed | E33 | held |
| E33-CHANNEL-cloud_api | channel cloud_api is classified, consequential use only if governed | E33 | held |
Other niches
Consensus & distributed systems · Attacks, threats & containment · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem