CAIN-42 Evolution 11 proof bundle (e11-intent-governance-2026-09-28) ========================================================== Built 2026-09-28T23:09:03+00:00 at commit 3106ea9e1626871a44d15b879d1a864ca6846e6e. WHAT THIS PROVES - E11 invariants (I1-I20) all hold: 20/20 - CAIN-Agent-Intent-Bench blocked: 20/20 - 36 tests passed, 0 failed: ============================== 36 passed in 0.67s ============================== REPRODUCE python3 -m pytest tests/test_cain42_e11_intent.py tests/test_cain42_e11_adversarial.py \ tests/test_cain42_e11_end_to_end.py -q bin/cain-agent communication audit bin/cain-agent communication bench python3 scripts/cain45/build_evolution11_bundle.py VERIFY (imports NO CAIN-42 code; Python + `cryptography` only) python3 verify_e11.py . LIMITS TESTED library: the intent/communication fabric is part of the L5 kernel library on the operator host; it is not a hosted service and it runs no agents or message bus. | Prompt-injection detection is pattern-based, not perfect semantic detection; a novel phrasing may not be flagged, and a flagged phrase is not proof of malice. | Intent influence and provenance graphs are attribution EVIDENCE, not perfect causal explanations. | Taint is a governance signal (provenance risk), never proof of malicious intent. | Attestation is over software/configuration digests and supplied measurements, NOT hardware attestation. | Cross-domain trust is not automatically established; it requires an explicit trust root and policy. | Transaction guarantees cover the governed evidence/state layer only; external systems are not claimed to support rollback. | No framework adapter is published, so none is described as supported. | No third party has reviewed this bundle; the clean-room verifier shares no CAIN imports but was written by the same operator. | Performance numbers are a single in-process run on the build host with the stated workload. INFORMATION IS NOT AUTHORITY. A MESSAGE IS NOT AUTHORIZATION.