CAIN-42 CAIN Studio

Evidence library · niche

Tools, MCP, protocols & adapters

How agents reach tools, APIs and each other, safely. 684 tested invariants.

Last reviewed 2026-10-01

684 of 684 held

Where this niche's rules come from

Test families in this niche

adapter (270) · protocol_domain (56) · discovery (36) · abi (28) · interchange (28) · universal_action (20) · routing (19) · sdk (19) · gateway (19) · gip_carrier (16) · channel (14) · overlay_protocol (13) · uact (12) · route (12) · runtime_adapter (12) · agency_graph (12) · runtime_swap (9) · message_class (9) · runtime_binding (8) · protocol_conformance (8) · operation_kind (8) · edge (6) · abi_error (5) · action (5) · carrier (3) · radar (3) · telemetry (2) · moat (2) · competitive_gap (2) · risk (1) · translation (1) · out_of_band (1) · reassessment (1) · integrity (1) · developer (1) · gap_detector (1) · ip (1) · lab (1) · physical_hybrid (1) · protocol (1)

Where these come from

Rules 301–450 of 684

IDRuleBundleResult
I-OOB-gateway-unenforcedgateway without enforcer UNENFORCEDE26held
I-REASSESS-runtime_changetrigger runtime_changeE26held
I-RIB-sameunchanged binding validE26held
I-RIB-agentchanged agent invalidatesE26held
I-RIB-runtimechanged runtime invalidatesE26held
I-RIB-modelchanged model invalidatesE26held
I-RIB-configurationchanged configuration invalidatesE26held
I-RIB-capabilitieschanged capabilities invalidatesE26held
I-RIB-deploymentchanged deployment invalidatesE26held
I-RIB-environmentchanged environment invalidatesE26held
I-DISC-0discovery grants no authorityE27held
I-DISC-1discovery grants no authorityE27held
I-DISC-2discovery grants no authorityE27held
I-DISC-3discovery grants no authorityE27held
I-DISC-4discovery grants no authorityE27held
I-DISC-5discovery grants no authorityE27held
I-DISC-6discovery grants no authorityE27held
I-DISC-7discovery grants no authorityE27held
I-DISC-8discovery grants no authorityE27held
I-DISC-9discovery grants no authorityE27held
I-ROUTE-configureroute configureE27held
I-ROUTE-createroute createE27held
I-ROUTE-credentialroute credentialE27held
I-ROUTE-delegateroute delegateE27held
I-ROUTE-deleteroute deleteE27held
I-ROUTE-deployroute deployE27held
I-ROUTE-destroyroute destroyE27held
I-ROUTE-executeroute executeE27held
I-ROUTE-listroute listE27held
I-ROUTE-notifyroute notifyE27held
I-ROUTE-observeroute observeE27held
I-ROUTE-payroute payE27held
I-ROUTE-queryroute queryE27held
I-ROUTE-readroute readE27held
I-ROUTE-sendroute sendE27held
I-ROUTE-submitroute submitE27held
I-ROUTE-transferroute transferE27held
I-ROUTE-writeroute writeE27held
I-TELEM-tooltelemetry toolE27held
I-TELEM-mcptelemetry mcpE27held
I-EDGE-FAIL_CLOSEDmode FAIL_CLOSED does not allow by defaultE27held
I-EDGE-FAIL_SAFEmode FAIL_SAFE does not allow by defaultE27held
I-EDGE-CACHE_LIMITEDmode CACHE_LIMITED does not allow by defaultE27held
I-EDGE-DEGRADEDmode DEGRADED does not allow by defaultE27held
I-EDGE-OFFLINE_VERIFIABLEmode OFFLINE_VERIFIABLE does not allow by defaultE27held
I-EDGE-offline-validvalid offline authorization allowsE27held
E28-I28every protocol carrier round-trips the envelope byte-identicallyE28held
E28-I29a carrier altered in transit never yields a valid envelopeE28held
E28-I30an unknown protocol has no carrierE28held
E30-UMA-principalthe UMA digest binds 'principal'E30held
E30-UMA-identitythe UMA digest binds 'identity'E30held
E30-UMA-intentthe UMA digest binds 'intent'E30held
E30-UMA-contextthe UMA digest binds 'context'E30held
E30-UMA-observationthe UMA digest binds 'observation'E30held
E30-UMA-memorythe UMA digest binds 'memory'E30held
E30-UMA-modelthe UMA digest binds 'model'E30held
E30-UMA-runtimethe UMA digest binds 'runtime'E30held
E30-UMA-capabilitythe UMA digest binds 'capability'E30held
E30-UMA-delegationthe UMA digest binds 'delegation'E30held
E30-UMA-policythe UMA digest binds 'policy'E30held
E30-UMA-authoritythe UMA digest binds 'authority'E30held
E30-UMA-riskthe UMA digest binds 'risk'E30held
E30-UMA-consequencethe UMA digest binds 'consequence'E30held
E30-UMA-transactionthe UMA digest binds 'transaction'E30held
E30-UMA-environmentthe UMA digest binds 'environment'E30held
E30-UMA-actionthe UMA digest binds 'action'E30held
E30-UMA-executionthe UMA digest binds 'execution'E30held
E30-UMA-outcomethe UMA digest binds 'outcome'E30held
E30-UMA-evidencethe UMA digest binds 'evidence'E30held
E30-SDK-SEALEDan SDK-wrapped tool runs only inside the E8 boundary for an allowed callE30held
E31-GIP-mcpCAIN-GIP carrier mcp round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-a2aCAIN-GIP carrier a2a round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-httpCAIN-GIP carrier http round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-restCAIN-GIP carrier rest round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-grpcCAIN-GIP carrier grpc round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-websocketCAIN-GIP carrier websocket round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-event_busCAIN-GIP carrier event_bus round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-message_queueCAIN-GIP carrier message_queue round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-cliCAIN-GIP carrier cli round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-browserCAIN-GIP carrier browser round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-computer_useCAIN-GIP carrier computer_use round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-local_ipcCAIN-GIP carrier local_ipc round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-cloud_apiCAIN-GIP carrier cloud_api round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-agent_runtimeCAIN-GIP carrier agent_runtime round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-model_runtimeCAIN-GIP carrier model_runtime round-trips or is reported NOT IMPLEMENTEDE31held
E31-GIP-workflow_engineCAIN-GIP carrier workflow_engine round-trips or is reported NOT IMPLEMENTEDE31held
E31-PC-real_proof_verifiesCAIN-GIP real_proof_verifies on every carrierE31held
E31-PC-carrier_roundtripCAIN-GIP carrier_roundtrip on every carrierE31held
E31-PC-carrier_occupiedCAIN-GIP carrier_occupied on every carrierE31held
E31-PC-gip_blocks_separateCAIN-GIP gip_blocks_separate on every carrierE31held
E31-PC-transit_tamperCAIN-GIP transit_tamper on every carrierE31held
E31-PC-wrong_carrierCAIN-GIP wrong_carrier on every carrierE31held
E31-PC-protocol_boundCAIN-GIP protocol_bound on every carrierE31held
E31-PC-failure_proof_verifiesCAIN-GIP failure_proof_verifies on every carrierE31held
E32-RUNTIME-pythonpython swap never inherits authorityE32held
E32-RUNTIME-node_v8node_v8 swap never inherits authorityE32held
E32-RUNTIME-containercontainer swap never inherits authorityE32held
E32-RUNTIME-osos swap never inherits authorityE32held
E32-RUNTIME-browserbrowser swap never inherits authorityE32held
E32-RUNTIME-cloud_runtimecloud_runtime swap never inherits authorityE32held
E32-RUNTIME-agent_frameworkagent_framework swap never inherits authorityE32held
E32-RUNTIME-tool_runtimetool_runtime swap never inherits authorityE32held
E32-RUNTIME-orchestration_engineorchestration_engine swap never inherits authorityE32held
E32-OVERLAY-mcpthe promoted overlay applies over mcpE32held
E32-OVERLAY-a2athe promoted overlay applies over a2aE32held
E32-OVERLAY-httpthe promoted overlay applies over httpE32held
E32-OVERLAY-restthe promoted overlay applies over restE32held
E32-OVERLAY-grpcthe promoted overlay applies over grpcE32held
E32-OVERLAY-websocketthe promoted overlay applies over websocketE32held
E32-OVERLAY-event_busthe promoted overlay applies over event_busE32held
E32-OVERLAY-message_queuethe promoted overlay applies over message_queueE32held
E32-OVERLAY-clithe promoted overlay applies over cliE32held
E32-OVERLAY-browserthe promoted overlay applies over browserE32held
E32-OVERLAY-computer_usethe promoted overlay applies over computer_useE32held
E32-OVERLAY-local_ipcthe promoted overlay applies over local_ipcE32held
E32-OVERLAY-cloud_apithe promoted overlay applies over cloud_apiE32held
E33-KIND-send_messagesend_message is executed only through E8E33held
E33-KIND-invoke_toolinvoke_tool is executed only through E8E33held
E33-KIND-call_apicall_api is executed only through E8E33held
E33-KIND-modify_policymodify_policy is routed to E32 CAINEvolutionPromotionGateE33held
E33-KIND-change_runtimechange_runtime is routed to E32 CAINSwapGovernanceE33held
E33-KIND-control_physical_actuatorcontrol_physical_actuator is executed only through E8E33held
E33-KIND-create_organizationcreate_organization is routed to E29 MachineOrganizationBudget (human)E33held
E33-KIND-propose_governance_evolutionpropose_governance_evolution is routed to E32 CAINEvolutionPromotionGateE33held
E33-ROUTE-low_riskroute low_risk keeps its required controlsE33held
E33-ROUTE-high_riskroute high_risk keeps its required controlsE33held
E33-ROUTE-physicalroute physical keeps its required controlsE33held
E33-ROUTE-financialroute financial keeps its required controlsE33held
E33-ROUTE-privilegedroute privileged keeps its required controlsE33held
E33-ROUTE-researchroute research keeps its required controlsE33held
E33-ROUTE-code_executionroute code_execution keeps its required controlsE33held
E33-ROUTE-deploymentroute deployment keeps its required controlsE33held
E33-ROUTE-memory_mutationroute memory_mutation keeps its required controlsE33held
E33-ROUTE-policy_mutationroute policy_mutation keeps its required controlsE33held
E33-ROUTE-governance_mutationroute governance_mutation keeps its required controlsE33held
E33-ROUTE-communicationroute communication keeps its required controlsE33held
E33-CHANNEL-a2achannel a2a is classified, consequential use only if governedE33held
E33-CHANNEL-mcpchannel mcp is classified, consequential use only if governedE33held
E33-CHANNEL-httpchannel http is classified, consequential use only if governedE33held
E33-CHANNEL-restchannel rest is classified, consequential use only if governedE33held
E33-CHANNEL-websocketchannel websocket is classified, consequential use only if governedE33held
E33-CHANNEL-event_buschannel event_bus is classified, consequential use only if governedE33held
E33-CHANNEL-message_queuechannel message_queue is classified, consequential use only if governedE33held
E33-CHANNEL-local_ipcchannel local_ipc is classified, consequential use only if governedE33held
E33-CHANNEL-filechannel file is classified, consequential use only if governedE33held
E33-CHANNEL-databasechannel database is classified, consequential use only if governedE33held
E33-CHANNEL-shared_memorychannel shared_memory is classified, consequential use only if governedE33held
E33-CHANNEL-browserchannel browser is classified, consequential use only if governedE33held
E33-CHANNEL-collaborationchannel collaboration is classified, consequential use only if governedE33held
E33-CHANNEL-cloud_apichannel cloud_api is classified, consequential use only if governedE33held

1 2 3 4 5

Other niches

Consensus & distributed systems · Attacks, threats & containment · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem