CAIN-42 CAIN Studio

Evidence library · niche

Tools, MCP, protocols & adapters

How agents reach tools, APIs and each other, safely. 684 tested invariants.

Last reviewed 2026-10-01

684 of 684 held

Where this niche's rules come from

Test families in this niche

adapter (270) · protocol_domain (56) · discovery (36) · abi (28) · interchange (28) · universal_action (20) · routing (19) · sdk (19) · gateway (19) · gip_carrier (16) · channel (14) · overlay_protocol (13) · uact (12) · route (12) · runtime_adapter (12) · agency_graph (12) · runtime_swap (9) · message_class (9) · runtime_binding (8) · protocol_conformance (8) · operation_kind (8) · edge (6) · abi_error (5) · action (5) · carrier (3) · radar (3) · telemetry (2) · moat (2) · competitive_gap (2) · risk (1) · translation (1) · out_of_band (1) · reassessment (1) · integrity (1) · developer (1) · gap_detector (1) · ip (1) · lab (1) · physical_hybrid (1) · protocol (1)

Where these come from

Rules 451–600 of 684

IDRuleBundleResult
E33-MSGCLASS-informationala informational message grants no authorityE33held
E33-MSGCLASS-evidentiarya evidentiary message grants no authorityE33held
E33-MSGCLASS-instructionala instructional message grants no authorityE33held
E33-MSGCLASS-delegateda delegated message grants no authorityE33held
E33-MSGCLASS-negotiateda negotiated message grants no authorityE33held
E33-MSGCLASS-contractuala contractual message grants no authorityE33held
E33-MSGCLASS-authorization_relateda authorization_related message grants no authorityE33held
E33-MSGCLASS-security_sensitivea security_sensitive message grants no authorityE33held
E33-MSGCLASS-policy_sensitivea policy_sensitive message grants no authorityE33held
E33-ABI-identifyABI identify fails closed on malformed/forged/unknown inputE33held
E33-ABI-authorizeABI authorize fails closed on malformed/forged/unknown inputE33held
E33-ABI-check_capabilityABI check_capability fails closed on malformed/forged/unknown inputE33held
E33-ABI-evaluate_riskABI evaluate_risk fails closed on malformed/forged/unknown inputE33held
E33-ABI-request_executionABI request_execution fails closed on malformed/forged/unknown inputE33held
E33-ABI-produce_proofABI produce_proof fails closed on malformed/forged/unknown inputE33held
E33-ABI-verify_proofABI verify_proof fails closed on malformed/forged/unknown inputE33held
E33-ABI-record_evidenceABI record_evidence fails closed on malformed/forged/unknown inputE33held
E33-ABI-revokeABI revoke fails closed on malformed/forged/unknown inputE33held
E33-ABI-replayABI replay fails closed on malformed/forged/unknown inputE33held
E33-ABI-conformABI conform fails closed on malformed/forged/unknown inputE33held
E33-ABI-recoverABI recover fails closed on malformed/forged/unknown inputE33held
E33-ABI-delegateABI delegate fails closed on malformed/forged/unknown inputE33held
E33-ABI-commitABI commit fails closed on malformed/forged/unknown inputE33held
E33-ABIERR-ABI_VERSION_UNSUPPORTEDABI_VERSION_UNSUPPORTED is returned, never an allowE33held
E33-ABIERR-ABI_OP_UNKNOWNABI_OP_UNKNOWN is returned, never an allowE33held
E33-ABIERR-ABI_ARGUMENT_MISSINGABI_ARGUMENT_MISSING is returned, never an allowE33held
E33-ABIERR-ABI_MALFORMEDABI_MALFORMED is returned, never an allowE33held
E33-ABIERR-ABI_UNAUTHENTICATEDABI_UNAUTHENTICATED is returned, never an allowE33held
E33-RUNTIME-generic_llm_agentgeneric_llm_agent is classified ENFORCED with a stated basisE33held
E33-RUNTIME-mcp_agentmcp_agent is classified ENFORCED with a stated basisE33held
E33-RUNTIME-a2a_agenta2a_agent is classified ENFORCED with a stated basisE33held
E33-RUNTIME-coding_agentcoding_agent is classified PARTIAL with a stated basisE33held
E33-RUNTIME-browser_agentbrowser_agent is classified PARTIAL with a stated basisE33held
E33-RUNTIME-computer_use_agentcomputer_use_agent is classified PARTIAL with a stated basisE33held
E33-RUNTIME-workflow_agentworkflow_agent is classified UNKNOWN with a stated basisE33held
E33-RUNTIME-multi_agent_systemmulti_agent_system is classified PARTIAL with a stated basisE33held
E33-RUNTIME-research_agentresearch_agent is classified SIMULATED with a stated basisE33held
E33-RUNTIME-physical_robotic_systemphysical_robotic_system is classified UNKNOWN with a stated basisE33held
E33-RUNTIME-enterprise_automationenterprise_automation is classified UNKNOWN with a stated basisE33held
E33-RUNTIME-cloud_agentcloud_agent is classified PARTIAL with a stated basisE33held
E33-SDK-identifySDK identify is a signed ABI callE33held
E33-SDK-authorizeSDK authorize is a signed ABI callE33held
E33-SDK-check_capabilitySDK check_capability is a signed ABI callE33held
E33-SDK-evaluate_riskSDK evaluate_risk is a signed ABI callE33held
E33-SDK-request_executionSDK request_execution is a signed ABI callE33held
E33-SDK-commitSDK commit is a signed ABI callE33held
E33-SDK-produce_proofSDK produce_proof is a signed ABI callE33held
E33-SDK-verify_proofSDK verify_proof is a signed ABI callE33held
E33-SDK-record_evidenceSDK record_evidence is a signed ABI callE33held
E33-SDK-revokeSDK revoke is a signed ABI callE33held
E33-SDK-delegateSDK delegate is a signed ABI callE33held
E33-SDK-replaySDK replay is a signed ABI callE33held
E33-SDK-conformSDK conform is a signed ABI callE33held
E33-SDK-recoverSDK recover is a signed ABI callE33held
E33-GATEWAY-mcpgateway surface mcp states its real statusE33held
E33-GATEWAY-a2agateway surface a2a states its real statusE33held
E33-GATEWAY-httpgateway surface http states its real statusE33held
E33-GATEWAY-apigateway surface api states its real statusE33held
E33-GATEWAY-toolsgateway surface tools states its real statusE33held
E33-GATEWAY-browsergateway surface browser states its real statusE33held
E33-GATEWAY-computer_usegateway surface computer_use states its real statusE33held
E33-GATEWAY-cloudgateway surface cloud states its real statusE33held
E33-GATEWAY-codegateway surface code states its real statusE33held
E33-GATEWAY-databasesgateway surface databases states its real statusE33held
E33-GATEWAY-financial_systemsgateway surface financial_systems states its real statusE33held
E33-GATEWAY-physical_interfacesgateway surface physical_interfaces states its real statusE33held
E33-DISCOVERY-policypolicy discovery records must be signedE33held
E33-DISCOVERY-identityidentity discovery records must be signedE33held
E33-DISCOVERY-verificationverification discovery records must be signedE33held
E33-DISCOVERY-proofproof discovery records must be signedE33held
E33-DISCOVERY-conformanceconformance discovery records must be signedE33held
E33-DISCOVERY-trust_domaintrust_domain discovery records must be signedE33held
E33-DISCOVERY-enforcement_boundaryenforcement_boundary discovery records must be signedE33held
E33-DISCOVERY-incidentincident discovery records must be signedE33held
E33-GAP-unknown_channelthe gap detector knows unknown_channelE33held
E34-PROTOCOL-mcpprotocol mcp is classified SUPPORTED with a basisE34held
E34-PROTOCOL-a2aprotocol a2a is classified SUPPORTED with a basisE34held
E34-PROTOCOL-httpprotocol http is classified SUPPORTED with a basisE34held
E34-PROTOCOL-restprotocol rest is classified SUPPORTED with a basisE34held
E34-PROTOCOL-grpcprotocol grpc is classified SUPPORTED with a basisE34held
E34-PROTOCOL-websocketprotocol websocket is classified SUPPORTED with a basisE34held
E34-PROTOCOL-event_busprotocol event_bus is classified SUPPORTED with a basisE34held
E34-PROTOCOL-cliprotocol cli is classified SUPPORTED with a basisE34held
E34-PROTOCOL-local_ipcprotocol local_ipc is classified PARTIALLY_SUPPORTED with a basisE34held
E34-PROTOCOL-cloud_apiprotocol cloud_api is classified PARTIALLY_SUPPORTED with a basisE34held
E34-PROTOCOL-browserprotocol browser is classified PARTIALLY_SUPPORTED with a basisE34held
E34-PROTOCOL-computer_useprotocol computer_use is classified PARTIALLY_SUPPORTED with a basisE34held
E34-PROTOCOL-physicalprotocol physical is classified UNSUPPORTED with a basisE34held
E34-PROTOCOL-unknown_transportprotocol unknown_transport is classified UNKNOWN with a basisE34held
E34-SDK-pythonSDK target python states its real statusE34held
E34-SDK-typescriptSDK target typescript states its real statusE34held
E34-SDK-goSDK target go states its real statusE34held
E34-SDK-restSDK target rest states its real statusE34held
E34-SDK-grpcSDK target grpc states its real statusE34held
E34-GATEWAY-MCPgateway surface MCP states its real statusE34held
E34-GATEWAY-A2Agateway surface A2A states its real statusE34held
E34-GATEWAY-cloudgateway surface cloud states its real statusE34held
E34-GATEWAY-codegateway surface code states its real statusE34held
E34-GATEWAY-databasegateway surface database states its real statusE34held
E34-GATEWAY-financialgateway surface financial states its real statusE34held
E34-GATEWAY-physicalgateway surface physical states its real statusE34held
E34-PROTOCOL2-mcpprotocol mcp never carries authority across a domainE34held
E34-PROTOCOL2-a2aprotocol a2a never carries authority across a domainE34held
E34-PROTOCOL2-httpprotocol http never carries authority across a domainE34held
E34-PROTOCOL2-restprotocol rest never carries authority across a domainE34held
E34-PROTOCOL2-grpcprotocol grpc never carries authority across a domainE34held
E34-PROTOCOL2-websocketprotocol websocket never carries authority across a domainE34held
E34-PROTOCOL2-event_busprotocol event_bus never carries authority across a domainE34held
E34-PROTOCOL2-cliprotocol cli never carries authority across a domainE34held
E34-PROTOCOL2-local_ipcprotocol local_ipc never carries authority across a domainE34held
E34-PROTOCOL2-cloud_apiprotocol cloud_api never carries authority across a domainE34held
E34-PROTOCOL2-browserprotocol browser never carries authority across a domainE34held
E34-PROTOCOL2-computer_useprotocol computer_use never carries authority across a domainE34held
E34-PROTOCOL2-physicalprotocol physical never carries authority across a domainE34held
E34-PROTOCOL2-unknown_transportprotocol unknown_transport never carries authority across a domainE34held
E35-DOMAIN-OBSERVATIONthe signed domain OBSERVATION is definedE35held
E35-DOMAIN-PREDICTIONthe signed domain PREDICTION is definedE35held
E35-DOMAIN-RECOMMENDATIONthe signed domain RECOMMENDATION is definedE35held
E35-DOMAIN-POLICY-PROPOSALthe signed domain POLICY-PROPOSAL is definedE35held
E35-DOMAIN-CONTROL-PROPOSALthe signed domain CONTROL-PROPOSAL is definedE35held
E35-DOMAIN-MEMORYthe signed domain MEMORY is definedE35held
E35-DOMAIN-COUNTERFACTUALthe signed domain COUNTERFACTUAL is definedE35held
E35-DOMAIN-SIMULATIONthe signed domain SIMULATION is definedE35held
E35-DOMAIN-EVALUATIONthe signed domain EVALUATION is definedE35held
E35-DOMAIN-RESEARCHthe signed domain RESEARCH is definedE35held
E35-DOMAIN-EVOLUTIONthe signed domain EVOLUTION is definedE35held
E35-DOMAIN-CANARYthe signed domain CANARY is definedE35held
E35-DOMAIN-REGRETthe signed domain REGRET is definedE35held
E35-DOMAIN-CALIBRATIONthe signed domain CALIBRATION is definedE35held
E35-DOMAIN-DEPLOYMENTthe signed domain DEPLOYMENT is definedE35held
E35-DOMAIN-PROFILEthe signed domain PROFILE is definedE35held
E35-DOMAIN-OBLIGATIONthe signed domain OBLIGATION is definedE35held
E35-DOMAIN-POLICYthe signed domain POLICY is definedE35held
E35-DOMAIN-HARNESSthe signed domain HARNESS is definedE35held
E35-DOMAIN-PLANthe signed domain PLAN is definedE35held
E35-DOMAIN-GOALthe signed domain GOAL is definedE35held
E35-DOMAIN-INTENTthe signed domain INTENT is definedE35held
E35-DOMAIN-ACTIONthe signed domain ACTION is definedE35held
E35-DOMAIN-TRAJECTORYthe signed domain TRAJECTORY is definedE35held
E35-DOMAIN-COMMUNICATIONthe signed domain COMMUNICATION is definedE35held
E35-DOMAIN-COLLUSIONthe signed domain COLLUSION is definedE35held
E35-DOMAIN-ECONOMYthe signed domain ECONOMY is definedE35held
E35-DOMAIN-LABORthe signed domain LABOR is definedE35held
E35-DOMAIN-MARKETPLACEthe signed domain MARKETPLACE is definedE35held
E35-DOMAIN-COMPILEthe signed domain COMPILE is definedE35held
E35-DOMAIN-FAILURE-PREDICTIONthe signed domain FAILURE-PREDICTION is definedE35held
E35-DOMAIN-FAILURE-TO-PRODUCTthe signed domain FAILURE-TO-PRODUCT is definedE35held
E35-DOMAIN-ADVERSARIALthe signed domain ADVERSARIAL is definedE35held
E35-DOMAIN-REDTEAMthe signed domain REDTEAM is definedE35held
E35-DOMAIN-BLUETEAMthe signed domain BLUETEAM is definedE35held

1 2 3 4 5

Other niches

Consensus & distributed systems · Attacks, threats & containment · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem