Technical report / Version 2
Agent Manifest: Portable, Hardware-Attestable Identity and Provenance for AI Agents
OPAQUE Systems
Abstract
Agent Manifest proposes a signed record of the artifacts that define an AI agent, including its system prompt, model, policy, tools, retrieval corpus, memory, decision trace, delegation, supply chain, and human approvals. Artifact digests and canonical serialization make changes to the recorded baseline detectable when a verifier has the relevant artifacts and trusted keys. The design composes SPIFFE identities, RFC 8785 canonicalization, Ed25519 signatures, an optional ML-DSA-65 profile, and hardware-attestation bindings. This technical report describes the original model and preserves the recorded Ed25519 software benchmarks, delegation checks, and tamper probes. Signed metadata alone does not prove that the recorded configuration was used during execution. The evaluation does not measure post-quantum performance or establish live hardware provenance; continuous verification of mutable memory and retrieval state is outside its scope. Current SDK behavior and normative requirements are maintained separately.
What this report contributes
A signed baseline for agent artifacts, with recorded Ed25519 benchmarks, delegation checks, and tamper probes.
Evidence and limits
- The saved benchmark run is dated July 1, 2026, on Windows 11, CPython 3.12.10, and an ARMv8 Qualcomm host. It did not record its SDK commit; the inferred revision is 67c21db.
- A rerun at that revision on October 1, 2026 reproduced every size and tamper outcome, but its Level 1 verify median of 3.9 to 4.9 ms did not reproduce the 2.7 ms bound.
- At the evaluated revision the verifier did not check human approval signatures: forged approvals still returned APPROVED. Later SDK revisions verify them.
- Only the Ed25519 profile was measured. Signed artifacts do not establish that those artifacts were used during execution.
The source package preserves the recorded inputs and results. The benchmark was rerun at the inferred revision on October 1, 2026 with the SDK clock frozen at the original run time. No independent replication is claimed.
Read the current specification and implementation guidance. This report describes an earlier design and evaluation; the current specification governs implementation.
Cite this report
Imran Siddique. Agent Manifest: Portable, Hardware-Attestable Identity and Provenance for AI Agents. AgenTrust technical report, version 2, 2026.
Download BibTeX / Download CITATION.cff
@techreport{agentrust2026agentmanifest,
title = {Agent Manifest: Portable, Hardware-Attestable Identity and Provenance for AI Agents},
author = {Imran Siddique},
institution = {AgenTrust},
year = {2026},
type = {Technical report},
note = {Version 2; not peer reviewed},
doi = {10.5281/zenodo.23091277},
url = {https://agentrust-io.com/research/agent-manifest/v2/}
}
Version history
Version 2, October 1, 2026: Corrects the signature pre-image description, the tamper-probe field list, the per-hop delegation figure and the conformance test count, records that the evaluated verifier did not authenticate human approvals, and adds an October 2026 rerun. Results unchanged.
Version 1, September 27, 2026: Separates signed-baseline checks from proof of runtime use, states evaluation limits, and adds the publication scope and patent notice.
Based on a manuscript originally dated June 23, 2026, with later recorded experiments. That manuscript date is not presented as a verified publication date.
File checksums. Published version files are retained; substantive revisions receive a new version.
Questions and corrections
Open an issue in the project repository and identify the report version and section.