{"id":"e5a8096a-ae56-4768-a3bd-a9ed238adde9","entityType":"agent","slug":"clawhub-aeoess-agent-passport-system","name":"Agent Passport","canonicalUrl":"https://www.xpersona.co/agent/clawhub-aeoess-agent-passport-system","canonicalPath":"/agent/clawhub-aeoess-agent-passport-system","generatedAt":"2026-10-09T15:07:37.186Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:57:45.465Z","emptyReason":null},"description":"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (25 tools covering identity, delegation, enforcement, commerce, reputation). 5,281 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (107 modules, 152 MCP tools) still available under APS_PROFILE=full and the root import. SDK 6.0.1 and MCP 6.0.1 are current on npm, Python 3.0.1 on PyPI, Rust 0.3.0 on crates.io, Go v0.7.0. The 3.3.1 release added Delegated Action Evidence: bilateral pair reconciliation with five mismatch classes, verifier-side revocation observation receipts under a stated freshness contract, Merkle-rooted evidence bundles with a per-axis claim-state report (verify-bundle), spec 4.1 action_ref canonicalization validated by cross-language vectors, and jurisdiction selection records that surface pack conflicts, on top of evidentiary type safety, Wave 1 accountability, Instruction Provenance Receipt, and bilateral receipts.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.7K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17910xrphqzkns9tgwnnxb4wd83ybr9:agent-passport-system","sourceUrl":"https://clawhub.ai/aeoess/agent-passport-system","homepage":"https://clawhub.ai/aeoess/skills/agent-passport-system","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/aeoess/agent-passport-system","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/aeoess/skills/agent-passport-system","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":58,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Agent Passport technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:57:45.465Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:57:45.465Z","emptyReason":null},"stars":null,"forks":null,"downloads":2719,"packageName":null,"latestVersion":"6.0.1","tractionLabel":"2.7K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:57:45.465Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T11:57:45.465Z","lastCrawledAt":"2026-10-09T11:57:45.465Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T11:57:45.465Z","lastVerifiedAt":null,"highlights":[{"version":"6.0.1","createdAt":"2026-09-08T02:46:09.078Z","changelog":"agent-passport-system 6.0.1 - Expanded SDK and server support: new Python (3.0.1), Rust (0.3.0), and Go (v0.7.0) SDKs. - Essential MCP toolset increased from 20 to 25 tools; total tools expanded from 150 to 152. - Test coverage increased to 5,281 tests. - Notable 3.3.1 features now documented: Delegated Action Evidence, bilateral reconciliation workflows, verifier-side revocation observation, Merkle-rooted evidence bundles, and improved cross-language validation. - SKILL.md revised with up-to-date workflows, install info, and tool listings. - `skill-card.md` file removed.","fileCount":4,"zipByteSize":7217},{"version":"5.9.2","createdAt":"2026-06-11T03:07:12.877Z","changelog":"- Increased total test coverage from 3,615 to 3,791 tests. - Reduced module count from 127 to 107 in the full surface area, improving maintainability. - Documentation updates: clarified install instructions and added Go SDK info. - Removed deprecated file: skill-card.md. - Updated SDK npm package reference to version 2.6.0 (was 2.6.0-alpha.9).","fileCount":4,"zipByteSize":6330},{"version":"5.9.1","createdAt":"2026-06-03T15:03:28.491Z","changelog":"- Increased total automated tests from 2,586 to 3,615, enhancing reliability. - Updated MCP tool count in essential and full profiles (now “all 150 tools”). - Updated version references and test coverage in documentation to reflect recent releases (“pre-release 2.6.0-alpha.0” to “2.6.0-alpha.9”; MCP v3.1.1 to v3.2.1). - Minor documentation clarifications and corrections. - Removed legacy file: skill-card.md.","fileCount":4,"zipByteSize":6230},{"version":"5.9.0","createdAt":"2026-05-04T04:26:17.023Z","changelog":"**Evidentiary type safety primitives and framework improvements.** - Added evidentiary type safety features: claim/evidence registry, claim verifier, contestation cascade. - Test coverage increased to 2,586. - Expanded module count (127 modules). - Updated MCP profile, remains at 150 tools. - Alpha release 2.6.0-alpha.0 introduces these evidentiary primitives on top of existing accountability features. - Minor updates to description and technical details for accuracy.","fileCount":4,"zipByteSize":6413},{"version":"5.8.0","createdAt":"2026-05-01T06:15:17.813Z","changelog":"**Major expansion with new accountability primitives and increased tool/test coverage.** - Adds Wave 1 accountability primitives: action, authority-boundary, custody, contestability, bundle. - Introduces Instruction Provenance Receipt support. - Adds bilateral receipts via in-toto Decision Receipt v0.1 predicate (npm alpha 2.5.0). - MCP tool count increased to 150; test coverage now at 2,536 tests. - Documentation updated to reflect new surface area and features.","fileCount":3,"zipByteSize":4758},{"version":"5.6.1","createdAt":"2026-04-23T08:11:55.517Z","changelog":"- Updated test count in documentation from 2,366 to 2,410 - Updated total MCP tool count from 142 to 150 for full surface area - No functional changes; documentation and metadata only","fileCount":3,"zipByteSize":4728},{"version":"5.6.0","createdAt":"2026-04-23T07:31:07.249Z","changelog":"- Test coverage increased: now 2,410 tests (was 2,366). - MCP tool count expanded: 150 tools now available under full profile (was 142). - Added notice about pre-release 2.3.0-alpha with bilateral receipts (in-toto Decision Receipt v0.1 predicate). - Documentation updates to reflect expanded tests and tool availability.","fileCount":3,"zipByteSize":4728},{"version":"5.5.0","createdAt":"2026-04-21T00:34:17.978Z","changelog":"- Increased MCP tool count to 142 (previously 132); module count is now 124. - Updated test count to 2,366. - Documentation updated to reflect new MCP tool and module counts, and revised installation details. - Minor documentation and version alignment throughout SKILL.md.","fileCount":3,"zipByteSize":4658}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17910xrphqzkns9tgwnnxb4wd83ybr9:agent-passport-system","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17910xrphqzkns9tgwnnxb4wd83ybr9:agent-passport-system` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/aeoess/agent-passport-system before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T15:07:37.183Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-aeoess-agent-passport-system/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T11:57:45.465Z","emptyReason":null},"readme":"Skill: Agent Passport\n\nOwner: aeoess\n\nSummary: Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (25 tools covering identity, delegation, enforcement, commerce, reputation). 5,281 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (107 modules, 152 MCP tools) still available under APS_PROFILE=full and the root import. SDK 6.0.1 and MCP 6.0.1 are current on npm, Python 3.0.1 on PyPI, Rust 0.3.0 on crates.io, Go v0.7.0. The 3.3.1 release added Delegated Action Evidence: bilateral pair reconciliation with five mismatch classes, verifier-side revocation observation receipts under a stated freshness contract, Merkle-rooted evidence bundles with a per-axis claim-state report (verify-bundle), spec 4.1 action_ref canonicalization validated by cross-language vectors, and jurisdiction selection records that surface pack conflicts, on top of evidentiary type safety, Wave 1 accountability, Instruction Provenance Receipt, and bilateral receipts.\n\nTags: latest:6.0.1\n\nVersion history:\n\nv6.0.1 | 2026-09-08T02:46:09.078Z | auto\n\nagent-passport-system 6.0.1\n\n- Expanded SDK and server support: new Python (3.0.1), Rust (0.3.0), and Go (v0.7.0) SDKs.\n- Essential MCP toolset increased from 20 to 25 tools; total tools expanded from 150 to 152.\n- Test coverage increased to 5,281 tests.\n- Notable 3.3.1 features now documented: Delegated Action Evidence, bilateral reconciliation workflows, verifier-side revocation observation, Merkle-rooted evidence bundles, and improved cross-language validation.\n- SKILL.md revised with up-to-date workflows, install info, and tool listings.\n- `skill-card.md` file removed.\n\nv5.9.2 | 2026-06-11T03:07:12.877Z | auto\n\n- Increased total test coverage from 3,615 to 3,791 tests.\n- Reduced module count from 127 to 107 in the full surface area, improving maintainability.\n- Documentation updates: clarified install instructions and added Go SDK info.\n- Removed deprecated file: skill-card.md.\n- Updated SDK npm package reference to version 2.6.0 (was 2.6.0-alpha.9).\n\nv5.9.1 | 2026-06-03T15:03:28.491Z | auto\n\n- Increased total automated tests from 2,586 to 3,615, enhancing reliability.\n- Updated MCP tool count in essential and full profiles (now “all 150 tools”).\n- Updated version references and test coverage in documentation to reflect recent releases (“pre-release 2.6.0-alpha.0” to “2.6.0-alpha.9”; MCP v3.1.1 to v3.2.1).\n- Minor documentation clarifications and corrections.\n- Removed legacy file: skill-card.md.\n\nv5.9.0 | 2026-05-04T04:26:17.023Z | auto\n\n**Evidentiary type safety primitives and framework improvements.**\n\n- Added evidentiary type safety features: claim/evidence registry, claim verifier, contestation cascade.\n- Test coverage increased to 2,586.\n- Expanded module count (127 modules).\n- Updated MCP profile, remains at 150 tools.\n- Alpha release 2.6.0-alpha.0 introduces these evidentiary primitives on top of existing accountability features.\n- Minor updates to description and technical details for accuracy.\n\nv5.8.0 | 2026-05-01T06:15:17.813Z | auto\n\n**Major expansion with new accountability primitives and increased tool/test coverage.**\n\n- Adds Wave 1 accountability primitives: action, authority-boundary, custody, contestability, bundle.\n- Introduces Instruction Provenance Receipt support.\n- Adds bilateral receipts via in-toto Decision Receipt v0.1 predicate (npm alpha 2.5.0).\n- MCP tool count increased to 150; test coverage now at 2,536 tests.\n- Documentation updated to reflect new surface area and features.\n\nv5.6.1 | 2026-04-23T08:11:55.517Z | auto\n\n- Updated test count in documentation from 2,366 to 2,410\n- Updated total MCP tool count from 142 to 150 for full surface area\n- No functional changes; documentation and metadata only\n\nv5.6.0 | 2026-04-23T07:31:07.249Z | auto\n\n- Test coverage increased: now 2,410 tests (was 2,366).\n- MCP tool count expanded: 150 tools now available under full profile (was 142).\n- Added notice about pre-release 2.3.0-alpha with bilateral receipts (in-toto Decision Receipt v0.1 predicate).\n- Documentation updates to reflect expanded tests and tool availability.\n\nv5.5.0 | 2026-04-21T00:34:17.978Z | auto\n\n- Increased MCP tool count to 142 (previously 132); module count is now 124.\n- Updated test count to 2,366.\n- Documentation updated to reflect new MCP tool and module counts, and revised installation details.\n- Minor documentation and version alignment throughout SKILL.md.\n\nv1.46.0 | 2026-04-17T00:13:03.159Z | auto\n\nVersion 1.46.0 of agent-passport-system\n\n- No file changes detected in this version.\n- Functionality, interfaces, documentation, and dependencies remain unchanged.\n- No new features, fixes, or breaking changes introduced.\n\nv1.45.0 | 2026-04-16T23:03:33.944Z | auto\n\nVersion 1.45.0 of agent-passport-system\n\n- No file changes were detected for this release.\n- No new features, bug fixes, or documentation updates are present in this version.\n\nv1.44.0 | 2026-04-16T20:50:47.515Z | auto\n\nagent-passport-system v1.44.0\n\n- No changes detected in this version.\n- All documentation and features remain consistent with previous release.\n\nv1.42.0 | 2026-04-14T21:32:25.960Z | auto\n\n- Increased total number of tests from 2,552 to 2,764, improving reliability and coverage.\n- SKILL.md updated to reflect the new test count.\n- No functional or API changes.\n\nv1.41.0 | 2026-04-11T04:35:21.670Z | user\n\nNanook PDR v2.19 adapter batch: applyTemporalDecay, confidenceBreakdown, BehavioralFingerprint, computeReputationDrift + ring buffer, extractSessions, computeProbeIdentity, verifyProbeIdentity, computeConsistencyScore\n\nv5.4.0 | 2026-04-10T18:30:20.516Z | auto\n\n- Updated reported number of tests in docs from 2,552 to 2,591.\n- No functional or API changes—documentation (SKILL.md) only.\n\nv5.3.0 | 2026-04-10T03:21:56.970Z | auto\n\n- Test coverage increased from 2,535 to 2,552 tests\n- \"4-gate checkout\" updated to \"5-gate checkout\" in commerce workflow\n- Minor updates to documentation and description for consistency\n- No changes to modules, tool count, or framework adapters\n\nv6.0.0 | 2026-04-08T19:44:01.392Z | auto\n\nVersion 6.0.0\n\n- Added observation governance features: telemetry scopes, derivation rights, behavioral memory\n- Updated description and metadata to reflect new capabilities\n- Increased total test count to 2,535\n- Improved documentation on data lifecycle and governance\n- No changes to commands, workflows, or API\n\nv5.2.0 | 2026-04-07T22:45:08.816Z | auto\n\nVersion 5.2.0 of agent-passport-system\n\n- No file changes detected in this release.\n- No updates to documentation, features, or dependencies.\n- All modules, APIs, and tools remain unchanged from the previous version.\n\nv5.1.0 | 2026-04-07T20:20:10.384Z | auto\n\nNo user-facing or internal changes detected in this release.\n\n- Version bump only; contents remain identical to previous version.\n- No file or documentation updates.\n\nv2.4.0 | 2026-04-07T03:03:58.806Z | auto\n\nagent-passport-system 2.4.0\n\n- Increased MCP tools count from 131 to 132\n- Increased test coverage from 2,486 to 2,497 tests\n- Framework adapters list updated from 7 to 8 (added Gonka)\n- SKILL.md updated for tool/adapters/test counts and descriptions\n\nv2.3.0 | 2026-04-07T00:31:53.045Z | auto\n\n- Added Gonka framework adapter for decentralized GPU compute governance.\n- Updated total test count to 2,486.\n- Revised description and data to reflect 8 framework adapters (now includes Gonka).\n- No code changes; documentation updated in SKILL.md.\n\nv2.2.0 | 2026-04-06T22:17:33.226Z | auto\n\n- Added support for 7 framework adapters, including Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, and A2A, enabling one-function governance integration.\n- Updated test count to 2,468 and MCP tools to 131.\n- Expanded documentation with a new \"Framework adapters\" section detailing usage examples and adapter functions.\n- Minor corrections and enhancements to module/tool listings and API documentation.\n\nv1.36.0 | 2026-04-06T22:14:33.405Z | auto\n\nNo user-visible changes.  \nVersion bump only; no file or functionality updates detected.\n\nv1.35.0 | 2026-04-06T18:42:42.721Z | auto\n\n- Increased test coverage from 2,180 to 2,306 tests.\n- No changes to files, workflows, features, or modules since the last version.\n- Documentation updated to reflect current test counts.\n\nv1.34.0 | 2026-04-06T04:02:51.485Z | auto\n\n- Increased MCP tools from 125 to 131.\n- Expanded total test count from 2,180 to 2,306.\n- Updated description and key facts to reflect new module, tool, and test totals.\n- No changes to usage or programmatic API.\n\nv1.33.0 | 2026-04-05T17:09:22.885Z | auto\n\nNo changes detected in this version.\n\n- Version 1.33.0 was published with no modifications to files or documentation.\n\nv5.0.0 | 2026-04-04T00:51:19.042Z | auto\n\nagent-passport-system 5.0.0 introduces broader identity provider support and improved enforcement/audit features.\n\n- Added support for bring-your-own identity (did:key, did:web, SPIFFE, OAuth, did:aps).\n- Enhanced gateway enforcement, monotonic narrowing, cascade revocation, and cryptographic audit trails.\n- Increased module count to 103 and test coverage to 2,180 tests.\n- Expanded description and documentation to emphasize enforcement, accountability, and interoperability.\n- No breaking changes to core workflows or MCP toolset.\n\nv4.7.0 | 2026-04-02T22:07:55.001Z | auto\n\n- Increased module count from 97 to 99 (core modules: 67, v2 constitutional: 32)\n- Raised test coverage from 2,009 to 2,057 tests\n- Updated installation instructions to reflect new module numbers\n- No changes to MCP tool count or documented workflows\n\nv4.6.0 | 2026-04-02T17:21:17.945Z | auto\n\n- Increased SDK module count from 96 to 97 and core modules from 64 to 65.\n- Updated total tests from 1,987 to 2,009.\n- Documentation now reflects updated module and test numbers.\n- No changes to MCP tools or workflows.\n\nv4.5.0 | 2026-04-01T23:03:25.459Z | auto\n\n- Increased module count from 95 to 96.\n- Expanded test coverage from 1,956 to 1,987 tests.\n- Updated documentation to reflect module and test count changes.\n- No functional or API changes documented in this update.\n\nv4.4.0 | 2026-04-01T05:00:10.543Z | auto\n\n- Increased test coverage to 1,956 tests (was 1,941).\n- Documentation updated to reflect the new test total.\n- No changes to features, modules, or MCP tools.\n\nv4.3.0 | 2026-04-01T02:00:40.161Z | auto\n\n- Test coverage increased from 1,929 to 1,941 tests.\n- Documentation updated to reflect latest test counts.\n- No changes to features, modules, API, or tools.\n\nv4.2.0 | 2026-03-31T15:34:45.680Z | auto\n\n- Updated metadata formatting in SKILL.md for environment variables and network hosts.\n- Clarified that GITHUB_TOKEN is optional and only used for register_agora_public.\n- Simplified network and environment information for easier integration.\n- No changes to functionality or core documentation content.\n\nv4.1.0 | 2026-03-31T15:19:17.567Z | auto\n\n- Updated test coverage from 1,919 to 1,929 tests in the documentation.\n- No other changes to features or functionality; documentation update only.\n\nv4.0.0 | 2026-03-31T07:43:47.397Z | auto\n\nagent-passport-system 4.0.0 is a major update with significant protocol and toolchain expansion.\n\n- Increased to 95 modules, 125 MCP tools, and 1,919 tests for broader coverage.\n- Adds encrypted agent-to-agent communication, trust scoring, and institutional governance features.\n- Expanded CLI and MCP coverage: new governance, data attribution, and Intent Network tools.\n- Passport architecture now includes four trust grades with transparent attestation signals.\n- Improved documentation: clearer install/workflow instructions and API usage.\n- No breaking changes to previous core CLI, but protocol and module surface are much broader.\n\nv3.1.0 | 2026-03-13T19:28:48.676Z | auto\n\nVersion 3.1.0\n\n- Added environment variable documentation for GITHUB_TOKEN, specifying it is only required for public Agora registration (not for core features).\n- Added network requirement documentation for optional remote MCP server and Intent Network API.\n- Clarified local Ed25519 key storage, emphasizing `.passport/agent.json` contains the private key and recommending adding `.passport/` to `.gitignore`.\n- Updated documentation to specify that `register_agora_public` requires GITHUB_TOKEN, with other features unaffected.\n- No code or functional changes; documentation and metadata improvements only.\n\nv3.0.0 | 2026-03-12T18:11:32.076Z | user\n\nv1.13.0: 534 tests, 61 MCP tools, 17 modules. Intent Network (agent-to-agent matching). ProxyGateway (enforcement boundary). Principal Identity (DID/VC, A2A, EU AI Act).\n\nv2.1.0 | 2026-03-06T19:06:12.088Z | user\n\n313 tests (84 suites, 20 files). Remote MCP at mcp.aeoess.com/sse. New: W3C DID (did:aps), Verifiable Credentials, A2A Protocol Bridge, EU AI Act compliance.\n\nv2.0.0 | 2026-03-04T01:51:47.911Z | user\n\n8 layers, 264 tests, 38 MCP tools. Full rewrite.\n\nv1.0.0 | 2026-02-24T19:10:51.608Z | user\n\nInitial release: cryptographic identity (Ed25519), scoped delegation, Human Values Floor governance, Merkle proof accountability, Agent Agora communication, and Layer 5 intent architecture (roles, tradeoff rules, deliberative consensus) for autonomous AI agents. 65 tests, zero heavy dependencies. Apache-2.0.\n\nArchive index:\n\nArchive v6.0.1: 4 files, 7217 bytes\n\nFiles: _meta.json (140b), example_calls.md (1266b), skill-card.md (2513b), SKILL.md (11082b)\n\nFile v6.0.1:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (25 tools covering identity, delegation, enforcement, commerce, reputation). 5,281 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (107 modules, 152 MCP tools) still available under APS_PROFILE=full and the root import. SDK 6.0.1 and MCP 6.0.1 are current on npm, Python 3.0.1 on PyPI, Rust 0.3.0 on crates.io, Go v0.7.0. The 3.3.1 release added Delegated Action Evidence: bilateral pair reconciliation with five mismatch classes, verifier-side revocation observation receipts under a stated freshness contract, Merkle-rooted evidence bundles with a per-axis claim-state report (verify-bundle), spec 4.1 action_ref canonicalization validated by cross-language vectors, and jurisdiction selection records that surface pack conflicts, on top of evidentiary type safety, Wave 1 accountability, Instruction Provenance Receipt, and bilateral receipts.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access: one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK: /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server: APS_PROFILE=essential is the default\ngo get github.com/aeoess/agent-passport-go@v0.7.0   # Go SDK, byte-parity subset (passport, delegation, attribution, completion, in-toto, values)\npip install agent-passport-system==3.0.1             # Python SDK\ncargo add agent-passport-system@0.3.0                # Rust SDK, library crate agent_passport\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 152 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (152 total)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (11 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | catalog of 250+ tool targets (subject to the upstream Composio registry and local configuration) |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Composition-check receipt (CompositionCheckV0)\n\nA chain of individually rule-legal delegations can compose to a globally-unsafe target that per-hop monotonic narrowing cannot detect (each delegation narrows scope correctly, but the composed chain routes to an unsafe aggregate). The SDK carries proof that an external attestor ran a composition-hazard check; detection of the hazards is private gateway intelligence and is not in the SDK.\n\n```typescript\nimport { CompositionCheckV0 } from 'agent-passport-system'\n\nconst result = CompositionCheckV0.verifyCompositionCheck(receipt, context)\n// verifies the anchor: signature, binding to (chain_hash, action_ref, context_hash),\n// freshness, attestor trust. Surfaces independence_is_second_anchor corroborated from the\n// caller's trust context, never the receipt's self-declaration.\n```\n\nThe verifier checks the anchor, not the composition. It evaluates no policy and emits no aggregate `safe` verdict: a per-check `pass` means only that the named attestor reported pass for the named profile over the bound context, never global safety. `gateway_self` is always weak (one trust domain); only a context-corroborated `independent_registered` attestor is a second anchor, mirroring how RAP-v0 gates its strong claim on `domains >= 2`. Conformance vectors in `conformance/composition-check/v0/`.\n\n`traceBeneficiary().verified` is a real cryptographic check: true only when the receipt signature verifies at the chain tail and every delegation hop passes `verifyDelegation`. The separate `resolved` field carries lookup-success semantics (the lineage maps to known records) without making a cryptographic claim.\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer**: bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 25 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 14 constraint dimensions\n- **5,281 tests** including 38 adversarial scenarios. These are a developer-authored internal evaluation, not an independent red-team or neutral third-party adversarial harness.\n- **Zero heavy dependencies**: Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 107 modules, 152 MCP tools, available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- crates.io: https://crates.io/crates/agent-passport-system\n- Go: https://pkg.go.dev/github.com/aeoess/agent-passport-go\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://agent-passport.org/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v6.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"6.0.1\",\n  \"publishedAt\": 1788835569078\n}\n\nFile v6.0.1:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json against my trusted issuer list and tell me what the result establishes\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task, built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team: when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nFile v6.0.1:skill-card.md\n\n## Description:\n\nAgent Passport provides identity, delegation, enforcement, commerce, reputation, and audit-trail workflows for AI agents through SDK, CLI, and MCP interfaces.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[aeoess](https://clawhub.ai/user/aeoess)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to create and verify agent passports, delegate scoped authority, record signed work receipts, enforce commerce and policy checks, and generate audit evidence.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Setup can run mutable npm or MCP code.\n\nMitigation: Use pinned package versions, inspect packages before running npx, and run setup in a least-privilege environment.\n\nRisk: The skill can create local agent key material and configuration.\n\nMitigation: Protect .passport/agent.json like a private key, keep it out of version control, and limit file access to trusted users.\n\nRisk: MCP setup can change local Claude Desktop or Cursor configuration.\n\nMitigation: Review the exact configuration changes before enabling the MCP server.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/aeoess/skills/agent-passport-system)\n- [npm SDK package](https://www.npmjs.com/package/agent-passport-system)\n- [npm MCP package](https://www.npmjs.com/package/agent-passport-system-mcp)\n- [PyPI package](https://pypi.org/project/agent-passport-system/)\n- [crates.io package](https://crates.io/crates/agent-passport-system)\n- [Go package documentation](https://pkg.go.dev/github.com/aeoess/agent-passport-go)\n- [Project documentation](https://agent-passport.org/llms-full.txt)\n- [Project paper](https://doi.org/10.5281/zenodo.18749779)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, code examples, and configuration instructions]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce local identity files, signed delegations, signed receipts, Merkle proofs, and MCP or editor setup guidance.]\n\n## Skill Version(s):\n\n6.0.1 (source: server release evidence and artifact metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v5.9.2: 4 files, 6330 bytes\n\nFiles: _meta.json (140b), example_calls.md (1239b), skill-card.md (3134b), SKILL.md (8665b)\n\nFile v5.9.2:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 3,791 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (107 modules, 150 MCP tools) still available under APS_PROFILE=full and the root import. SDK 2.6.0 on npm adds evidentiary type safety primitives (claim/evidence registry, claim verifier, contestation cascade) on top of Wave 1 accountability (action, authority-boundary, custody, contestability, bundle), Instruction Provenance Receipt, and bilateral receipts via in-toto Decision Receipt v0.1 predicate.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access: one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK: /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server: APS_PROFILE=essential is the default\ngo get github.com/aeoess/agent-passport-go@v0.2.0-alpha.1   # Go SDK, byte-parity subset (passport, delegation, attribution, completion, in-toto, values)\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 150 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (150 total on v3.2.1)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer**: bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 14 constraint dimensions\n- **3,791 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies**: Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 107 modules, 150 MCP tools, available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v5.9.2:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"5.9.2\",\n  \"publishedAt\": 1781147232877\n}\n\nFile v5.9.2:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nFile v5.9.2:skill-card.md\n\n## Description: <br>\nAgent Passport helps agents use cryptographic identity, scoped delegation, gateway enforcement, commerce controls, trust scoring, and signed audit receipts. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[aeoess](https://clawhub.ai/user/aeoess) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to issue agent identities, delegate scoped authority, enforce policy boundaries, record signed work receipts, and audit multi-agent activity. It is most relevant when agent systems need accountable delegation, commerce controls, reputation signals, or cryptographic provenance for actions. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Generated passport files can contain private key material and signed identity data. <br>\nMitigation: Protect .passport/agent.json like a private SSH key and avoid committing it to source control. <br>\nRisk: Setup can modify local agent-tool configuration and connect to remote MCP or Intent Network services. <br>\nMitigation: Review Claude Desktop and Cursor configuration changes and install only when external agent identity or governance services are intended. <br>\nRisk: Delegation, checkout, public Agora posting, and intent-policy changes can have authority or spending impact. <br>\nMitigation: Require explicit confirmation before delegation, checkout, public posting, or policy changes. <br>\n\n\n## Reference(s): <br>\n- [ClawHub listing](https://clawhub.ai/aeoess/agent-passport-system) <br>\n- [Agent Passport System npm package](https://www.npmjs.com/package/agent-passport-system) <br>\n- [Agent Passport System MCP npm package](https://www.npmjs.com/package/agent-passport-system-mcp) <br>\n- [Remote MCP endpoint](https://mcp.aeoess.com/sse) <br>\n- [Intent Network API](https://api.aeoess.com) <br>\n- [Agent Passport documentation](https://aeoess.com/llms-full.txt) <br>\n- [Agent Passport paper](https://doi.org/10.5281/zenodo.18749779) <br>\n- [Agent Passport System PyPI package](https://pypi.org/project/agent-passport-system/) <br>\n- [Project repository link from artifact](https://github.com/aeoess/agent-passport-system) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with CLI examples, TypeScript snippets, MCP setup commands, and generated identity, delegation, receipt, and proof artifacts.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May direct agents to create .passport/agent.json, signed delegations, signed receipts, Merkle proofs, and Claude Desktop or Cursor MCP configuration.] <br>\n\n## Skill Version(s): <br>\n5.9.2 (source: server release metadata and artifact _meta.json) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v5.9.1: 4 files, 6230 bytes\n\nFiles: _meta.json (140b), example_calls.md (1239b), skill-card.md (2873b), SKILL.md (8557b)\n\nFile v5.9.1:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 3,615 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (127 modules, 150 MCP tools) still available under APS_PROFILE=full and the root import. Pre-release 2.6.0-alpha.9 on npm (alpha tag) adds evidentiary type safety primitives (claim/evidence registry, claim verifier, contestation cascade) on top of Wave 1 accountability (action, authority-boundary, custody, contestability, bundle), Instruction Provenance Receipt, and bilateral receipts via in-toto Decision Receipt v0.1 predicate.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 150 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (150 total on v3.2.1)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 14 constraint dimensions\n- **3,615 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 127 modules, 150 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v5.9.1:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"5.9.1\",\n  \"publishedAt\": 1780499008491\n}\n\nFile v5.9.1:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nFile v5.9.1:skill-card.md\n\n## Description: <br>\nAgent Passport provides agent identity, scoped delegation, enforcement, audit receipts, and trust governance for AI agent workflows. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[aeoess](https://clawhub.ai/user/aeoess) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to create agent passports, delegate authority with limits, enforce policy boundaries, record signed work receipts, and audit multi-agent activity. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Generated passport key material can authorize agent actions if exposed. <br>\nMitigation: Protect the generated .passport key file like an SSH key and restrict filesystem access to trusted users and runtimes. <br>\nRisk: The full MCP profile exposes a broad tool surface. <br>\nMitigation: Use the essential MCP profile unless a workflow explicitly requires the full profile. <br>\nRisk: Optional OAuth tokens, GITHUB_TOKEN, and commerce or payment permissions can expand the impact of misuse. <br>\nMitigation: Provide credentials only for intended workflows, scope them narrowly, and avoid granting payment permissions unless required. <br>\nRisk: Remote MCP and API use sends workflow activity to external services. <br>\nMitigation: Use remote endpoints only in environments where those network connections and data flows are approved. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/aeoess/agent-passport-system) <br>\n- [Publisher profile](https://clawhub.ai/user/aeoess) <br>\n- [npm package](https://www.npmjs.com/package/agent-passport-system) <br>\n- [MCP npm package](https://www.npmjs.com/package/agent-passport-system-mcp) <br>\n- [PyPI package](https://pypi.org/project/agent-passport-system/) <br>\n- [Documentation](https://aeoess.com/llms-full.txt) <br>\n- [Paper](https://doi.org/10.5281/zenodo.18749779) <br>\n- [Remote MCP endpoint](https://mcp.aeoess.com/sse) <br>\n- [Intent Network API](https://api.aeoess.com) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline code, shell commands, JSON-like records, and configuration guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May produce key material, signed passports, signed delegations, receipts, Merkle proofs, MCP tool calls, and audit summaries.] <br>\n\n## Skill Version(s): <br>\n5.9.1 (source: ClawHub release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v5.9.0: 4 files, 6413 bytes\n\nFiles: _meta.json (140b), example_calls.md (1239b), skill-card.md (3309b), SKILL.md (8557b)\n\nFile v5.9.0:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 2,586 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (127 modules, 150 MCP tools) still available under APS_PROFILE=full and the root import. Pre-release 2.6.0-alpha.0 on npm (alpha tag) adds evidentiary type safety primitives (claim/evidence registry, claim verifier, contestation cascade) on top of Wave 1 accountability (action, authority-boundary, custody, contestability, bundle), Instruction Provenance Receipt, and bilateral receipts via in-toto Decision Receipt v0.1 predicate.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 142 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (150 total on v3.1.1)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 14 constraint dimensions\n- **2,586 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 127 modules, 150 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v5.9.0:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"5.9.0\",\n  \"publishedAt\": 1777868777023\n}\n\nFile v5.9.0:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nFile v5.9.0:skill-card.md\n\n## Description: <br>\nAgent Passport is an enforcement and accountability layer for AI agents that provides cryptographic identity, scoped delegation, constraint enforcement, spending controls, trust scoring, and signed audit trails. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[aeoess](https://clawhub.ai/user/aeoess) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to install and operate Agent Passport System for agent identity, scoped delegation, signed work receipts, compliance audits, MCP setup, and commerce guardrails. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The security evidence recommends review because the skill grants broad MCP, delegation, checkout, public-posting, and private-key authority with limited scoping guidance. <br>\nMitigation: Install only from trusted aeoess packages and services, prefer the essential MCP profile, inspect client configuration changes, and require explicit approval before spending, checkout creation, delegation, GitHub-token use, or public Agora posting. <br>\nRisk: The skill can create `.passport/agent.json`, which contains agent identity material that should be treated like a private key. <br>\nMitigation: Protect `.passport/agent.json`, keep it out of source control, and rotate or revoke affected credentials if the file is exposed. <br>\nRisk: Optional GitHub-token and remote-service flows can perform externally visible actions such as public Agora registration or posting. <br>\nMitigation: Use the minimum required credentials, review prompts and tool calls before execution, and disable optional token-backed flows when they are not needed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/aeoess/agent-passport-system) <br>\n- [npm: agent-passport-system](https://www.npmjs.com/package/agent-passport-system) <br>\n- [npm: agent-passport-system-mcp](https://www.npmjs.com/package/agent-passport-system-mcp) <br>\n- [PyPI: agent-passport-system](https://pypi.org/project/agent-passport-system/) <br>\n- [Agent Passport Documentation](https://aeoess.com/llms-full.txt) <br>\n- [Agent Passport Paper](https://doi.org/10.5281/zenodo.18749779) <br>\n- [Remote MCP Endpoint](https://mcp.aeoess.com/sse) <br>\n- [GitHub Repository](https://github.com/aeoess/agent-passport-system) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands, TypeScript snippets, JSON-like configuration guidance, and operational instructions] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May produce commands that install npm packages, configure MCP clients, create local identity files, delegate authority, post to remote services, or use optional GitHub credentials.] <br>\n\n## Skill Version(s): <br>\n5.9.0 (source: release evidence and artifact _meta.json) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v5.8.0: 3 files, 4758 bytes\n\nFiles: _meta.json (140b), example_calls.md (1239b), SKILL.md (8457b)\n\nFile v5.8.0:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 2,536 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (124 modules, 150 MCP tools) still available under APS_PROFILE=full and the root import. Pre-release 2.5.0-alpha on npm (alpha tag) adds Wave 1 accountability primitives (action, authority-boundary, custody, contestability, bundle), Instruction Provenance Receipt, and bilateral receipts via in-toto Decision Receipt v0.1 predicate.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 142 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (150 total on v3.1.1)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 15 constraint dimensions\n- **2,536 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 124 modules, 150 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v5.8.0:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"5.8.0\",\n  \"publishedAt\": 1777616117813\n}\n\nFile v5.8.0:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nArchive v5.6.1: 3 files, 4728 bytes\n\nFiles: _meta.json (140b), example_calls.md (1239b), SKILL.md (8356b)\n\nFile v5.6.1:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 2,410 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (124 modules, 150 MCP tools) still available under APS_PROFILE=full and the root import. Pre-release 2.3.0-alpha on npm (alpha tag) adds bilateral receipts via in-toto Decision Receipt v0.1 predicate.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 142 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (142 total on v3.0.0 @next, v2.27.0 @latest has 154)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 15 constraint dimensions\n- **2,366 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 124 modules, 142 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v5.6.1:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"5.6.1\",\n  \"publishedAt\": 1776931915517\n}\n\nFile v5.6.1:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nArchive v5.6.0: 3 files, 4728 bytes\n\nFiles: _meta.json (140b), example_calls.md (1239b), SKILL.md (8356b)\n\nFile v5.6.0:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 2,410 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (124 modules, 150 MCP tools) still available under APS_PROFILE=full and the root import. Pre-release 2.3.0-alpha on npm (alpha tag) adds bilateral receipts via in-toto Decision Receipt v0.1 predicate.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 142 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (142 total on v3.0.0 @next, v2.27.0 @latest has 154)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 15 constraint dimensions\n- **2,366 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 124 modules, 142 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v5.6.0:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"5.6.0\",\n  \"publishedAt\": 1776929467249\n}\n\nFile v5.6.0:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nArchive v5.5.0: 3 files, 4658 bytes\n\nFiles: _meta.json (140b), example_calls.md (1239b), SKILL.md (8244b)\n\nFile v5.5.0:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 2,366 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (124 modules, 142 MCP tools) still available under APS_PROFILE=full and the root import.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 142 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (142 total on v3.0.0 @next, v2.27.0 @latest has 154)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 15 constraint dimensions\n- **2,366 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 124 modules, 142 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v5.5.0:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"5.5.0\",\n  \"publishedAt\": 1776731657978\n}\n\nFile v5.5.0:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nArchive v1.46.0: 3 files, 4630 bytes\n\nFiles: _meta.json (141b), example_calls.md (1239b), SKILL.md (8203b)\n\nFile v1.46.0:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 2,764 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (103 modules, 132 MCP tools) still available under APS_PROFILE=full and the root import.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 132 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (132 total)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 15 constraint dimensions\n- **2,764 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 103 modules, 132 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v1.46.0:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"1.46.0\",\n  \"publishedAt\": 1776384783159\n}\n\nFile v1.46.0:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"\n\nArchive v1.45.0: 3 files, 4629 bytes\n\nFiles: _meta.json (141b), example_calls.md (1239b), SKILL.md (8203b)\n\nFile v1.45.0:SKILL.md\n\n---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (20 tools covering identity, delegation, enforcement, commerce, reputation). 2,764 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (103 modules, 132 MCP tools) still available under APS_PROFILE=full and the root import.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access — one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK — /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server — APS_PROFILE=essential is the default\n```\n\nMinimal SDK import (lead with the curated essentials):\n\n```typescript\nimport {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'\n```\n\nMinimal MCP install (essential profile is the default; `APS_PROFILE=full` for all 132 tools):\n\n```bash\nnpx agent-passport-system-mcp\n```\n\nRemote MCP (zero install): `https://mcp.aeoess.com/sse`\n\n## Core workflow\n\n### 1. Create identity → returns passport + keypair\n\n```bash\nnpx agent-passport join --name my-agent --owner alice\n```\n\nOutput: `.passport/agent.json` with Ed25519 keypair, signed passport, values attestation. Treat like an SSH key.\n\n### 2. Delegate authority → returns signed delegation\n\n```bash\nnpx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24\n```\n\nOutput: signed delegation with scope, spend limit, max depth, expiry. Authority can only narrow at each transfer.\n\n### 3. Record work → returns signed receipt\n\n```bash\nnpx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\"\n```\n\nOutput: Ed25519-signed receipt traceable to a human through the delegation chain.\n\n### 4. Prove contributions → returns Merkle proof\n\n```bash\nnpx agent-passport prove --beneficiary alice\n```\n\nOutput: Merkle root + inclusion proofs. 100K receipts provable with ~17 hashes.\n\n## MCP tools (132 total)\n\nSetup: `npx agent-passport-system-mcp setup` (auto-configures Claude Desktop + Cursor)\n\n**Identity & trust (12 tools):**\ngenerate_keys, identify, issue_passport, verify_issuer, verify_passport, create_principal, endorse_agent, get_passport_grade, list_issuance_records, get_behavioral_sequence, verify_endorsement, revoke_endorsement\n\n**Delegation & revocation (5):**\ncreate_delegation, verify_delegation, revoke_delegation, sub_delegate, create_v2_delegation\n\n**Commerce & wallets (4):**\ncommerce_preflight, get_commerce_spend, request_human_approval, create_checkout\n\n**Coordination (11):**\ncreate_task_brief, assign_agent, accept_assignment, submit_evidence, review_evidence, handoff_evidence, get_evidence, submit_deliverable, complete_task, get_my_role, get_task_detail\n\n**Communication (7):**\nsend_message, check_messages, broadcast, list_agents, post_agora_message, register_agora_agent, register_agora_public\n\n**Governance & policy (12):**\nload_values_floor, attest_to_floor, create_intent, evaluate_intent, create_policy_context, create_agent_context, execute_with_context, create_charter, sign_charter, verify_charter, create_approval_request, add_approval_signature\n\n**Data attribution (10):**\nregister_data_source, create_access_receipt, create_derivation_receipt, create_decision_lineage_receipt, record_training_use, check_data_access, check_purpose_permitted, check_retention_expired, query_contributions, generate_compliance_report\n\n**Intent Network (5):**\npublish_intent_card, remove_intent_card, search_matches, request_intro, respond_to_intro\n\n## Framework adapters (8)\n\nOne-function governance for every major agent framework. Each wraps tool/task execution with APS delegation checks and Ed25519-signed receipts.\n\n```typescript\nimport {\n  governLangChainTool,              // LangChain/LangGraph\n  governCrewTask,                   // CrewAI\n  governMCPToolCall,                // Any MCP server\n  governIBACIntent,                 // IBAC (Cedar/OPA)\n  passportToA2ACard,                // A2A Agent Cards\n} from 'agent-passport-system'\n\n// Also available as standalone packages:\n// npm install @aeoess/stripe-governance\n// npm install @aeoess/composio-governance\n```\n\n| Adapter | Function | What it wraps |\n|---------|----------|--------------|\n| LangChain | `governLangChainTool()` | BaseTool.invoke() |\n| CrewAI | `governCrewTask()` | Crew task execution |\n| MCP | `governMCPToolCall()` | Any MCP tool call |\n| IBAC/Cedar | `governIBACIntent()` | Cedar/OPA policy tuples |\n| A2A | `passportToA2ACard()` | Agent Card ↔ passport bridge |\n| Stripe | `governMPPPayment()` | Stripe agent payments |\n| Composio | `governComposioAction()` | 250+ tool integrations |\n| Gonka | `governGonkaInference()` | Decentralized GPU compute |\n\n## Programmatic API\n\n```typescript\nimport {\n  joinSocialContract,   // → { passport, keyPair, attestation }\n  createDelegation,     // → signed Delegation\n  processToolCall,      // → { permitted, constraintResults, receipt }\n  cascadeRevoke,        // → { revoked: string[], receipts }\n  computePassportGrade, // → 0 | 1 | 2 | 3\n  createIssuanceContext, // → IssuanceContext with evidence + assessment\n} from 'agent-passport-system'\n```\n\n## Passport grades (attestation architecture)\n\n| Grade | Meaning | Trust signal |\n|-------|---------|-------------|\n| 0 | Bare Ed25519 keypair | Unverified |\n| 1 | Issuer countersigned | AEOESS processed |\n| 2 | Runtime-bound + challenge-response | Infrastructure-attested |\n| 3 | Runtime + verified human principal | Full chain of trust |\n\nGrade travels with the passport. Any consumer reads it without understanding scoring internals.\n\n## Key facts\n\n- **Enforcement and accountability layer** — bring your own identity, gateway does the rest\n- **SDK `/core` subpath**: 24 curated functions for 90% of integrations\n- **MCP `essential` profile**: 20 tools by default (identity, delegation, enforcement, commerce, reputation)\n- **Policy eval <2ms**, 403 ops/sec, 15 constraint dimensions\n- **2,764 tests** including 50 adversarial attack scenarios\n- **Zero heavy dependencies** — Node.js crypto + uuid only\n- **Apache-2.0** license\n- *Full surface area: 103 modules, 132 MCP tools — available under `APS_PROFILE=full` and the root `agent-passport-system` import.*\n\n## Links\n\n- npm: https://www.npmjs.com/package/agent-passport-system\n- MCP: https://www.npmjs.com/package/agent-passport-system-mcp\n- PyPI: https://pypi.org/project/agent-passport-system/\n- GitHub: https://github.com/aeoess/agent-passport-system\n- Docs: https://aeoess.com/llms-full.txt\n- Paper: https://doi.org/10.5281/zenodo.18749779\n\nFile v1.45.0:_meta.json\n\n{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"1.45.0\",\n  \"publishedAt\": 1776380613944\n}\n\nFile v1.45.0:example_calls.md\n\n# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json and tell me if I can trust this agent\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task — built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team — when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\"","readmeExcerpt":"Skill: Agent Passport Owner: aeoess Summary: Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint en","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npm install agent-passport-system        # SDK: /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server: APS_PROFILE=essential is the default\ngo get github.com/aeoess/agent-passport-go@v0.7.0   # Go SDK, byte-parity subset (passport, delegation, attribution, completion, in-toto, values)\npip install agent-passport-system==3.0.1             # Python SDK\ncargo add agent-passport-system@0.3.0                # Rust SDK, library crate agent_passport"},{"language":"typescript","snippet":"import {\n  createPassport, createDelegation,\n  evaluateIntent, commercePreflight, generateKeyPair\n} from 'agent-passport-system/core'"},{"language":"bash","snippet":"npx agent-passport-system-mcp"},{"language":"bash","snippet":"npx agent-passport join --name my-agent --owner alice"},{"language":"bash","snippet":"npx agent-passport delegate --to <publicKey> --scope web_search,commerce --limit 500 --depth 1 --hours 24"},{"language":"bash","snippet":"npx agent-passport work --scope web_search --type research --result success --summary \"Found 3 sources\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agent-passport-system\ndescription: \"Enforcement and accountability layer for AI agents. Bring your own identity (did:key, did:web, SPIFFE, OAuth, did:aps). Gateway enforcement boundary, monotonic narrowing, cascade revocation, spending controls, data lifecycle, observation governance (telemetry scopes, derivation rights, behavioral memory). Use when agents need scoped delegation, trust scoring, constraint enforcement, or cryptographic audit trails. SDK leads with the /core subpath (24 curated functions), MCP leads with APS_PROFILE=essential (25 tools covering identity, delegation, enforcement, commerce, reputation). 5,281 tests. 8 framework adapters: Stripe, Composio, IBAC/Cedar, LangChain, CrewAI, MCP, A2A, Gonka. Full surface area (107 modules, 152 MCP tools) still available under APS_PROFILE=full and the root import. SDK 6.0.1 and MCP 6.0.1 are current on npm, Python 3.0.1 on PyPI, Rust 0.3.0 on crates.io, Go v0.7.0. The 3.3.1 release added Delegated Action Evidence: bilateral pair reconciliation with five mismatch classes, verifier-side revocation observation receipts under a stated freshness contract, Merkle-rooted evidence bundles with a per-axis claim-state report (verify-bundle), spec 4.1 action_ref canonicalization validated by cross-language vectors, and jurisdiction selection records that surface pack conflicts, on top of evidentiary type safety, Wave 1 accountability, Instruction Provenance Receipt, and bilateral receipts.\"\nmetadata:\n  clawdbot:\n    emoji: \"🔑\"\n    requires:\n      bins: [\"npx\"]\n      env: [\"GITHUB_TOKEN (optional, only for register_agora_public)\"]\n    network:\n      - \"mcp.aeoess.com (remote MCP server, SSE mode)\"\n      - \"api.aeoess.com (Intent Network API)\"\n    install:\n      - id: node\n        kind: node\n        package: agent-passport-system\n        bins: [\"agent-passport\"]\n        label: \"Install Agent Passport System\"\n---\n\n# Agent Passport System\n\n## When to use this skill\n\n- Agent needs cryptographic identity (Ed25519 passport)\n- Delegate authority between agents with scope, spend limits, depth controls\n- Revoke access: one call kills all downstream delegations\n- Run agent commerce with 5-gate checkout (passport, delegation, merchant, spend)\n- Coordinate multi-agent tasks (assign, evidence, review, deliver)\n- Track data contributions with Merkle proofs\n- Encrypt agent-to-agent communication (E2E, forward secrecy)\n- Score agent trust (Bayesian reputation, passport grades 0-3)\n- Enforce values compliance (8 principles, graduated enforcement)\n- Found institutions with charters, offices, approval policies\n\n## Install\n\n```bash\nnpm install agent-passport-system        # SDK: /core subpath is the curated default\nnpm install agent-passport-system-mcp    # MCP server: APS_PROFILE=essential is the default\ngo get github.com/aeoess/agent-passport-go@v0.7.0   # Go SDK, byte-parity subset (passport, delegation, attribution, completion, in-toto, values)\npip install agent-passport-system==3.0.1             # Python S"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn780jv20fjwp08gw7vmveqz1581rbsv\",\n  \"slug\": \"agent-passport-system\",\n  \"version\": \"6.0.1\",\n  \"publishedAt\": 1788835569078\n}"},{"path":"example_calls.md","content":"# Example Calls\n\n## Create a new agent identity\n\"Create a passport for my research agent called 'scout' owned by me with code_execution and web_search capabilities\"\n\n## Verify another agent\n\"Verify the passport at ./other-agent.json against my trusted issuer list and tell me what the result establishes\"\n\n## Delegate authority\n\"Delegate code_execution and web_search to this agent with a $500 spend limit, 1 level of sub-delegation allowed, expires in 24 hours\"\n\n## Record completed work\n\"Record that I successfully completed a code_execution task, built the authentication module\"\n\n## Generate contribution proofs\n\"Generate Merkle proofs of all my work for beneficiary alice\"\n\n## Audit compliance\n\"Audit my agent's compliance against the values floor\"\n\n## Post to the Agent Agora\n\"Register my agent in the Agora and post an announcement that the sprint is complete\"\n\n## Read Agora messages\n\"Show me all messages in the Agent Agora and list active topics\"\n\n## Check agent status\n\"Show my current agent status, delegation count, and receipt history\"\n\n## Advanced: Intent Architecture\n\"Help me set up tradeoff rules for my agent team: when quality and speed conflict, prefer quality until 2x time cost, then prefer speed. Create an intent document with these rules.\""},{"path":"skill-card.md","content":"## Description:\n\nAgent Passport provides identity, delegation, enforcement, commerce, reputation, and audit-trail workflows for AI agents through SDK, CLI, and MCP interfaces.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[aeoess](https://clawhub.ai/user/aeoess)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to create and verify agent passports, delegate scoped authority, record signed work receipts, enforce commerce and policy checks, and generate audit evidence.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Setup can run mutable npm or MCP code.\n\nMitigation: Use pinned package versions, inspect packages before running npx, and run setup in a least-privilege environment.\n\nRisk: The skill can create local agent key material and configuration.\n\nMitigation: Protect .passport/agent.json like a private key, keep it out of version control, and limit file access to trusted users.\n\nRisk: MCP setup can change local Claude Desktop or Cursor configuration.\n\nMitigation: Review the exact configuration changes before enabling the MCP server.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/aeoess/skills/agent-passport-system)\n- [npm SDK package](https://www.npmjs.com/package/agent-passport-system)\n- [npm MCP package](https://www.npmjs.com/package/agent-passport-system-mcp)\n- [PyPI package](https://pypi.org/project/agent-passport-system/)\n- [crates.io package](https://crates.io/crates/agent-passport-system)\n- [Go package documentation](https://pkg.go.dev/github.com/aeoess/agent-passport-go)\n- [Project documentation](https://agent-passport.org/llms-full.txt)\n- [Project paper](https://doi.org/10.5281/zenodo.18749779)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands, code examples, and configuration instructions]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May produce local identity files, signed delegations, signed receipts, Merkle proofs, and MCP or editor setup guidance.]\n\n## Skill Version(s):\n\n6.0.1 (source: server release evidence and artifact metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1813,"uniquenessScore":42,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T11:57:45.465Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T11:57:45.465Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T15:07:37.186Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}