diff --git a/assets/product-matrix.svg b/assets/product-matrix.svg index 7615b4e..c9cf194 100644 --- a/assets/product-matrix.svg +++ b/assets/product-matrix.svg @@ -1,184 +1,148 @@ - - WasmAgent — The Trusted Agent OS - WasmAgent — open infrastructure for provable AI agents. Core spine (marked ★): the wasmagent-js runtime and symkernel verification backend emit and check Ed25519-signed AEP evidence, sedimented into agent-trust-infra trust artifacts and EU AI Act compliance; wasmagent-py is the planned Python runtime sibling. Adjacent repos — the wasmagent-proxy gateway and the trace-pipeline / wasmagent-train-replay evidence pipelines — extend the spine and move to community maintenance once their roadmaps land. Product, research, and reference surfaces: open-agent-audit, fresharena, bscode. All anchored by the .github org hub. + + WasmAgent — open infrastructure for provable AI agents + WasmAgent organized as a tiered tree. Core (the platform): wasmagent-js runtime, wasmagent-protocol canonical AEP + compliance schemas, symkernel verification, agent-trust-infra trust and EU AI Act compliance, plus the planned wasmagent-py Python runtime. Official tooling (CLI, devtools, examples) and Apps (playground, desktop, editor extensions) are planned tiers reserved in the tree. Evidence surfaces extend Core and move to community maintenance once their roadmaps land: wasmagent-proxy gateway, trace-pipeline, wasmagent-train-replay. Research: fresharena. Product, reference and hub: open-agent-audit (Trustavo), bscode, and the .github org portal. - - - - - - - - - - - - + + + + + + + - + - WasmAgent — open infrastructure for provable AI agents - ★ Core spine (sustained) · Adjacent (fades to community) · Product / Research / Reference — a Trusted Agent OS - - - - - - GATEWAY - wasmagent-proxy - · 🚧 in progress - Proxy-Wasm (Rust) for Envoy · Istio · Kong · Consul — intercepts Agent/MCP/A2A HTTP traffic - x-aep-recording-mode header · Ed25519 DSSE AEP records · validation → delta → full policy - joins wasmagent-js mcp-firewall via shared trace_id for full gateway-to-tool-call causal graph - - - - - - - - - - - - RUNTIME - wasmagent-js - - WASM kernels: QuickJS · Pyodide · Wasmtime · Remote - MCP gateway · attestation · AEP emitter · capability manifests - Adapters: A2A · AG-UI · AI SDK · Claude Agent SDK - Packages (v1.x) - @wasmagent/core · cli · aep · compliance - mcp-gateway · mcp-attestation · devtools - evals-runner · kernel-* · mcp-firewall - capability-compiler · otel-exporter - - - - VERIF. - symkernel - - 🚧 in progress - cel-go rules - wazero sandbox - Z3 SMT proofs - - - - RUNTIME (PLANNED) ★ - wasmagent-py - Python agent runtime - AEP · MCP policy - symkernel adapter - - - - - - - - - - - - - - - - - - WORKLOAD - bscode - Cloudflare Workers coding agent · AEP evidence - Deny capabilities · output_taint_labels · RolloutProvenance - - - EVALUATION - fresharena - Dynamic, verifiable, adversarial evaluation protocol - FAEP schema · submit-then-test · Public Immunity Pool - - - - - - - - - - EVIDENCE PIPELINE - trace-pipeline - · pip install evomerge - eval_trust · AgentTrustScore · paired statistics - training-data admission gate · wasmagent-js v1.x AEP schema - - - EVIDENCE PIPELINE · GPU TRAINING - wasmagent-train-replay - - PyTorch Flight Recorder · cross-rank PROV-DM causal graph - EpochEvidenceBundle (Ed25519) · tensor-origin tracing · replay CLI - - 🚧 in progress - - - - - - - - - - TRUST ARTIFACTS - agent-trust-infra - - AgentBOM · MCP Posture · Trust Passport - trust-cli · EU AI Act Annex IV mapping (draft, 20/29) - Deadline: 2026-08-02 (Article 11, high-risk AI) - - - AUDIT - open-agent-audit - Enterprise audit reports · AEP v0.3 · trustavo.com - @openagentaudit/core · adapters · schema - OWASP Agentic Top 10 · NIST AI RMF · EU AI Act - - - - - - - - - Legend: - - Runtime - - Planned - - Gateway - - Evidence Pipeline - - Trust Artifacts - - Audit - - Verification - - HTTP (bidirectional) - - - = core spine (sustained investment) 🚧 = in progress 📋 = planned Adjacent repos (proxy, pipelines) → community maintenance once roadmaps land - - - - - - PROJECT HOME & ORG HUB - .github · wasmagent - Org profile · roadmap · RFC registry · claims · release ledger · github.com/WasmAgent + WasmAgent — open infrastructure for provable AI agents + One question, end to end: can you prove the agent ran correctly? + + + + + + ★ CORE — THE PLATFORM + Evidence · Protocol · Verification · Trust — sustained, long-term investment + + + + + + + + + + wasmagent-js + RUNTIME + WASM kernels · MCP gateway + AEP emitter · where evidence is born + + wasmagent-protocol + PROTOCOL + Canonical AEP + compliance schemas + npm @wasmagent/protocol · PyPI + + symkernel + VERIFICATION 🚧 + cel-go · wazero sandbox · Z3 SMT + proving it ran correctly + + agent-trust-infra + TRUST & COMPLIANCE + AgentBOM · MCP Posture · Passport + EU AI Act Annex IV · 2026-08-02 + + + 📋 planned: wasmagent-py — Python runtime sibling, same AEP schema · AEP is the connective standard across Core + + + + + + 🛠 OFFICIAL TOOLING + CLI · devtools · examples · starters — 📋 planned, reserved in the tree (no public repos yet) + + + + + + 🔌 EVIDENCE SURFACES + Extend Core to a surface · move to community maintenance once their roadmaps land (not retired) + + + + + + + + wasmagent-proxy 🚧 + Gateway — Proxy-Wasm (Rust) evidence engine + Envoy · Istio · Kong — signed AEP records + + trace-pipeline + evomerge — trace-to-training backend + admission gate · consumes wasmagent-protocol + + wasmagent-train-replay 🚧 + Causal evidence for distributed GPU training + PROV-DM graph · EpochEvidenceBundle · replay + + + + + + + 🧪 RESEARCH + Grounds the platform in results + + + + fresharena + Dynamic, verifiable, adversarial evaluation + FAEP · submit-then-test · paper in prep + + + + 📦 PRODUCT · REFERENCE · HUB + + + + + + open-agent-audit + AUDIT PRODUCT + Enterprise audit · AEP + trustavo.com + + bscode + REFERENCE WORKLOAD + Coding agent on CF Workers + AEP evidence export + + .github + ORG HUB + Portal · roadmap · RFC + claims · release ledger + + + + + + 🎮 APPS + playground · desktop · editor extensions · demos — 📋 planned, reserved in the tree (no public repos yet) + + + + + + How to read this tree + ★ Core = sustained investment, the platform's identity · 🔌 Evidence surfaces → community maintenance once roadmaps land (not retired) + 🚧 = in progress · 📋 = planned (dashed tiers have no public repos yet) · AEP (Agent Evidence Protocol) is the standard connecting every tier + + + + WASMAGENT PLATFORM + Open infrastructure for provable AI agents + Runtime emits signed evidence → symkernel verifies → agent-trust-infra proves compliance → github.com/WasmAgent diff --git a/docs/project-index.json b/docs/project-index.json index 2b30be9..49c9836 100644 --- a/docs/project-index.json +++ b/docs/project-index.json @@ -22,7 +22,8 @@ "reference-workload": "Reference workload / Golden Path fixture producer, not a general product.", "org-hub": "Org portal and governance.", "internal": "Internal automation or operations; ships no public product.", - "planned-workload": "Planned reference workload; repo not yet created." + "planned-workload": "Planned reference workload; repo not yet created.", + "official-tooling": "Official supporting tool downstream of the core spine (CLI, devtools, examples). Planned surface." }, "categories": { "project-home": "Public landing page that directs readers to the org hub.", @@ -35,7 +36,8 @@ "evaluation": "Adversarial evaluation protocol.", "internal-tool": "Internal automation or operations; ships no public product.", "verification": "Symbolic verification and sandbox execution backend.", - "gateway": "Network-boundary evidence engine (Proxy-Wasm)." + "gateway": "Network-boundary evidence engine (Proxy-Wasm).", + "protocol": "Cross-repository schema/contract specifications (single canonical source)." }, "repos": [ { @@ -61,6 +63,17 @@ "latest_version": "1.20.0", "focus": "core-spine" }, + { + "name": "wasmagent-protocol", + "category": "protocol", + "role": "Protocol", + "status": "shipped", + "visibility": "public", + "in_profile": true, + "focus": "core-spine", + "summary": "Canonical JSON Schemas for the Agent Evidence Protocol (AEP) and the compliance contract family. Single source of truth consumed by wasmagent-js and trace-pipeline; published as @wasmagent/protocol (npm) and wasmagent-protocol (PyPI).", + "url": "https://github.com/WasmAgent/wasmagent-protocol" + }, { "name": "bscode", "category": "workload", diff --git a/docs/repository-boundaries.md b/docs/repository-boundaries.md index 31fcead..72950eb 100644 --- a/docs/repository-boundaries.md +++ b/docs/repository-boundaries.md @@ -25,15 +25,21 @@ The maturity tiers above answer *"how stable is this repo?"* A second, orthogonal axis answers *"how central is it to the mission, and what happens to it long-term?"* — captured by the `focus` field in `docs/project-index.json`: -- **Core spine** — `wasmagent-js`, `symkernel`, `agent-trust-infra`, and planned - `wasmagent-py`. Evidence, verification, trust. Sustained investment; these - define the org's identity. -- **Adjacent** — `wasmagent-proxy`, `trace-pipeline`, `wasmagent-train-replay`. - Extend the spine to a surface. Their **exit condition** (per the "Adding a new - repository" rule) is *roadmap complete → community maintenance*, not - archival: code, schemas, and history stay in place. -- **Product / research / reference** — `open-agent-audit`, `fresharena`, - `bscode`. Downstream surfaces, governed by their own repo scope. +The org is organized as a tree (Core → Official tooling → Evidence surfaces +→ Research → Product/Apps), captured by the `focus` field: + +- **⭐ Core** — `wasmagent-js`, `wasmagent-protocol`, `symkernel`, + `agent-trust-infra`, and planned `wasmagent-py`. Runtime, protocol, + verification, trust. Sustained investment; these define the org's identity. +- **🛠 Official tooling** — CLI, devtools, examples. Planned; reserved in the + tree, no public repos yet. +- **🔌 Evidence surfaces** — `wasmagent-proxy`, `trace-pipeline`, + `wasmagent-train-replay`. Extend Core to a surface. Their **exit condition** + (per the "Adding a new repository" rule) is *roadmap complete → community + maintenance*, not archival: code, schemas, and history stay in place. +- **🧪 Research** — `fresharena`. +- **📦 Product / reference / hub** — `open-agent-audit`, `bscode`, `.github`. +- **🎮 Apps** — playground, desktop, editor extensions. Planned. A repo's focus changing (e.g. adjacent → community-maintained) is an architecture-review event, like any change to org-wide structure. diff --git a/docs/roadmap.md b/docs/roadmap.md index afc61c7..6c84701 100644 --- a/docs/roadmap.md +++ b/docs/roadmap.md @@ -19,17 +19,22 @@ Repositories are ranked by how close they sit to that mission, orthogonal to the maturity tiers in [`repository-boundaries.md`](repository-boundaries.md): -- **Core spine** (`wasmagent-js`, `symkernel`, `agent-trust-infra`, and the - planned `wasmagent-py`) — evidence emission, verification, and trust artifacts. - Sustained long-term investment. AEP is their connective standard, sedimented - from the shipping runtime rather than designed up front. -- **Adjacent** (`wasmagent-proxy`, `trace-pipeline`, `wasmagent-train-replay`) — - extend the spine to specific surfaces. Once their roadmaps land they move to - **community maintenance**; they are not retired, and their code and evidence - schemas stay put. -- **Product / research / reference** (`open-agent-audit`, `fresharena`, - `bscode`) — the commercial audit surface, the research lab, and the reference - workload, all downstream of the spine. +- **⭐ Core** (`wasmagent-js`, `wasmagent-protocol`, `symkernel`, + `agent-trust-infra`, and the planned `wasmagent-py`) — runtime, protocol, + verification, and trust artifacts. Sustained long-term investment. AEP is + their connective standard, sedimented from the shipping runtime and now + versioned in `wasmagent-protocol`. +- **🛠 Official tooling** — CLI, devtools, examples, starters. Planned; no + public repos yet. The tree reserves a home for them. +- **🔌 Evidence surfaces** (`wasmagent-proxy`, `trace-pipeline`, + `wasmagent-train-replay`) — extend Core to specific surfaces. Once their + roadmaps land they move to **community maintenance**; not retired — code and + evidence schemas stay put. +- **🧪 Research** (`fresharena`) — grounds the platform in measured results. +- **📦 Product, reference & hub** (`open-agent-audit`, `bscode`, `.github`) — + the commercial audit surface, the reference workload, and this portal. +- **🎮 Apps** — playground, desktop, editor extensions, demos. Planned; no + public repos yet. The machine-readable `focus` field in [`project-index.json`](project-index.json) is the source of truth for this axis. diff --git a/profile/README.md b/profile/README.md index 435ad0b..389170c 100644 --- a/profile/README.md +++ b/profile/README.md @@ -25,59 +25,79 @@ See [`golden-path/README.md`](../golden-path/README.md) for details. ## Projects WasmAgent is **open infrastructure for _provable_ AI agents** — not another -agent framework. The core spine answers one question end-to-end: *can you prove -the agent ran correctly?* Every other repository is organized around that spine -so a first-time visitor can tell the mission from its supporting cast at a -glance. +agent framework. The mission answers one question end-to-end: *can you prove the +agent ran correctly?* The organization is a **tree**, not a flat list: a **Core** +spine, the **Official tooling** and **Apps** that will grow around it, the +**Research** that feeds it, and the **evidence surfaces** that extend it. A +first-time visitor should tell the mission from its supporting cast at a glance. This section is the human-readable view of [`docs/project-index.json`](../docs/project-index.json), the machine-readable source of truth (see each repo's `focus` field). This repository (`.github`) is the organization's sole public portal. -### Core spine — evidence, verification, trust +### ⭐ Core — the platform -The mission lives here. These repositories receive sustained, long-term -investment. +Evidence, verification, trust. Sustained, long-term investment; these define the +platform's identity. | Repository | Role | | --- | --- | | [wasmagent-js](https://github.com/WasmAgent/wasmagent-js) | **Runtime** · Embedded agent runtime v1.x — WASM kernels (QuickJS, Pyodide, Wasmtime, Remote), MCP gateway + attestation, AEP emitter, capability manifests; adapters for A2A, AG-UI, AI SDK, and Claude Agent SDK. This is where signed evidence is born. | +| [wasmagent-protocol](https://github.com/WasmAgent/wasmagent-protocol) | **Protocol** · Canonical AEP + compliance JSON Schemas — the single source of truth every repo agrees on. Published as `@wasmagent/protocol` (npm) and `wasmagent-protocol` (PyPI). | | [symkernel](https://github.com/WasmAgent/symkernel) | **Verification** 🚧 · Go symbolic verification backend — cel-go lightweight rules, wazero Wasm sandbox hard-isolation, Z3 SMT proofs; HTTP service consumed by wasmagent-js and wasmagent-py. "Proving it ran correctly" is the mission itself. | | [agent-trust-infra](https://github.com/WasmAgent/agent-trust-infra) | **Trust & compliance** · AgentBOM, MCP Posture, and Trust Passport spec, reference impl, and CLI; EU AI Act Annex IV compliance mapping (draft, deadline **2026-08-02**). | -> **`wasmagent-py`** *(planned)* joins the spine as the Python runtime sibling — -> same AEP schema, Criterion/ConstraintIR protocol, and symkernel adapter — so +> **`wasmagent-py`** *(planned)* joins Core as the Python runtime sibling — same +> AEP schema, Criterion/ConstraintIR protocol, and symkernel adapter — so > evidence is emitted wherever agents actually run, not just in JS. > -> **AEP (Agent Evidence Protocol)** is the connective standard across the spine. -> It is sedimented from the shipping runtime rather than designed up front; its -> RFCs live in the [RFC registry](../docs/RFC/README.md), not a standalone repo. +> **AEP (Agent Evidence Protocol)** is the connective standard across Core, +> sedimented from the shipping runtime rather than designed up front and now +> versioned in `wasmagent-protocol`. -### Adjacent — maturing, then handed to the community +### 🛠 Official tooling -These extend the spine to specific surfaces. Once their roadmaps land they move -to **community maintenance** — they are not retired, and their code, evidence +Official supporting tools that will grow around Core — CLI, devtools, examples, +starters. *Planned; no public repos yet.* Tracked so the tree has a home for +them rather than scattering them later. + +### 🔌 Evidence surfaces — maturing, then handed to the community + +These extend Core to a specific surface (gateway, training, pipeline). Once +their roadmaps land they move to **community maintenance** — not retired; code, schemas, and history stay put. | Repository | Role | | --- | --- | | [wasmagent-proxy](https://github.com/WasmAgent/wasmagent-proxy) | **Gateway** 🚧 · Proxy-Wasm (Rust) evidence engine for Envoy, Istio, Kong, Consul — intercepts Agent/MCP/A2A traffic, emits Ed25519-signed AEP records, joins mcp-firewall via shared trace_id | -| [trace-pipeline](https://github.com/WasmAgent/trace-pipeline) | **Evidence pipeline** · `evomerge` — trace-to-training backend: eval_trust paired statistics, AgentTrustScore, training-data admission gate, wasmagent-js v1.x schema compat | +| [trace-pipeline](https://github.com/WasmAgent/trace-pipeline) | **Evidence pipeline** · `evomerge` — trace-to-training backend: eval_trust paired statistics, AgentTrustScore, training-data admission gate, consumes `wasmagent-protocol` | | [wasmagent-train-replay](https://github.com/WasmAgent/wasmagent-train-replay) | **Evidence pipeline** 🚧 · Causal evidence for distributed GPU training — cross-rank PROV-DM provenance graph, Ed25519-signed EpochEvidenceBundles, tensor-origin tracing, deterministic replay CLI | -### Product, research, and reference +### 🧪 Research -Downstream of the spine: the commercial audit surface, the research lab, the -reference workload, and this portal. +Grounds the platform in measured results; interfaces may change as experiments +evolve. + +| Repository | Role | +| --- | --- | +| [fresharena](https://github.com/WasmAgent/fresharena) | **Evaluation** · Dynamic, verifiable, adversarial evaluation — FAEP schema, submit-then-test, Public Immunity Pool; paper in preparation | + +### 📦 Product, reference & hub + +The commercial audit surface, the reference workload, and this portal. | Repository | Role | | --- | --- | | [open-agent-audit](https://github.com/WasmAgent/open-agent-audit) | **Audit product** · Enterprise audit product with AEP adapter; deployed at [trustavo.com](https://trustavo.com) | -| [fresharena](https://github.com/WasmAgent/fresharena) | **Research — evaluation** · Dynamic, verifiable, adversarial evaluation — FAEP schema, submit-then-test, Public Immunity Pool; paper in preparation | | [bscode](https://github.com/WasmAgent/bscode) | **Reference workload** · Coding-agent workload on Cloudflare Workers — AEP evidence export, deny capabilities, output taint labels, RolloutProvenance | | [`.github`](https://github.com/WasmAgent/.github) | **Org hub** · Organization portal — roadmap, claims registry, release ledger, project index, and cross-repo documentation | +### 🎮 Apps + +End-user applications on top of the platform — playground, desktop, editor +extensions, demos. *Planned; no public repos yet.* + ## Vision The broader industry is converging on *Agent Runtime / Agent OS* as the next infrastructure frontier — the layer that moves agents from stateless one-shot calls to long-running, stateful, recoverable systems. We agree with that framing, and we go one step further.