Skip to content
LortuArtePublic

About

Process-local budget authorization and replay-aware execution disposition for Python AI-agent tools.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

Β 

History

44 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ AEGIS Core

Execution-Boundary Authorization & Atomic L3 Settlement for AI Agents

Enforce before execution. Verify before settlement.

AEGIS is a security and economic-control layer for high-risk AI-agent tool calls β€” combining atomic budget enforcement, replay-safe authorization, deterministic receipts, SHA-256 action references, Ed25519 signatures, and an isolated atomic L3 settlement layer.

Python Version License Status Security L3

pip install aegis-core-lortuarte-sdk

🚨 The Problem

Autonomous AI agents can initiate payments, purchases, trades, API actions, and other irreversible tool calls concurrently.

A policy decision made too far away from execution can leave room for:

                 AI AGENT
                    β”‚
                    β–Ό
                TOOL INTENT
                    β”‚
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚        β”‚        β”‚
           β–Ό        β–Ό        β–Ό
        CALL #1  CALL #2  CALL #N
           β”‚        β”‚        β”‚
           β””β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”˜
                    β”‚
                    β–Ό
          CONCURRENT STATE RACE
                    β”‚
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚                   β”‚
          β–Ό                   β–Ό
   DUPLICATE EXECUTION     OVERSPEND

AEGIS moves the authorization boundary directly in front of tool execution.

                  AI AGENT
                     β”‚
                     β–Ό
                 TOOL INTENT
                     β”‚
                     β–Ό
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚      πŸ›‘οΈ AEGIS       β”‚
           β”‚  AUTHORIZATION GATE β”‚
           β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                      β”‚
                β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”
                β”‚           β”‚
                β–Ό           β–Ό
 execution_permitted: True   execution_permitted: False
                β”‚                       β”‚
                β–Ό                       β–Ό
          EXECUTE TOOL                πŸ›‘ BLOCK

The protected tool executes only when receipt["execution_permitted"] is True.


⚑ What AEGIS Does

AEGIS Core 3.4.0 focuses on the economic and authorization boundary between an autonomous agent and a high-risk external action.

πŸ”’ Atomic Budget Enforcement

Concurrent mutations of the process-local ledger are serialized by a lock.

πŸ” Replay-Safe Idempotency

An exact replay of the same authorization returns the historical receipt without consuming the budget again.

Reuse of the same transaction identity with conflicting economic data is denied.

πŸ”— Tool-Call Cryptographic Binding

tool_call_id participates in the authorization identity used to derive the signed action reference.

Changing the tool-call identity changes the resulting action_ref.

πŸ”‘ Signed Authorization Receipts

AEGIS produces deterministic authorization payloads protected by:

Deterministic Payload
        β”‚
        β–Ό
      SHA-256
        β”‚
        β–Ό
      Ed25519
        β”‚
        β–Ό
Signed Authorization Receipt

πŸ§ͺ Tamper Detection

Changing signed authorization data invalidates cryptographic verification.

πŸ›‘ Fail-Closed Behavior

Internal authorization failures deny execution.

An explicitly configured invalid Ed25519 private key aborts startup rather than silently replacing the configured cryptographic identity.

πŸ’° Decimal Monetary Accounting

Economic state uses Python Decimal rather than binary floating-point arithmetic.

AEGIS Core 3.4.0 supports monetary amounts with up to 6 decimal places.

  • Minimum supported positive amount: $0.000001
  • $0.001 micropayments are supported
  • Amounts with more than 6 decimal places fail closed
  • L3 settlement stores value as integer monetary units at a scale of 1,000,000 units per USD

🏦 Atomic L3 Settlement

An isolated settlement layer consumes signed AEGIS authorizations and performs atomic buyer β†’ seller balance transitions using SQLite transactions.


πŸ“¦ Installation

pip install aegis-core-lortuarte-sdk

Requirements:

Python >= 3.8
cryptography

cryptography is installed automatically by the package.


πŸš€ Quickstart

from decimal import Decimal
from aegis import AegisLocalPolicyGate

gate = AegisLocalPolicyGate()

agent_id = "agent-demo-001"

gate.ledger_data[agent_id] = Decimal("10.00")

receipt = gate.evaluar_gasto(
    agent_did=agent_id,
    operation="stripe_charge",
    tool_call_id="payment-001",
    amount_usd="3.00",
)

if receipt["execution_permitted"] is True:
    print("AUTHORIZED")
    # Execute the protected tool here.
else:
    print("BLOCKED")

print(receipt)

Expected authorization:

AUTHORIZED

Economic transition:

$10.00
   β”‚
   β”‚ request $3.00
   β–Ό
 ALLOW
   β”‚
   β–Ό
 $7.00

πŸ›‘οΈ Enforcement Boundary

Assume the remaining budget is:

$7.00

The agent attempts:

$20.00

AEGIS evaluates the action before external execution:

             $7.00 AVAILABLE
                    β”‚
                    β”‚ REQUEST $20.00
                    β–Ό
             β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
             β”‚    DENY     β”‚
             β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜
                    β”‚
                    β–Ό
             budget_exhausted
                    β”‚
                    β–Ό
             πŸ›‘ TOOL BLOCKED

Integration pattern:

receipt = gate.evaluar_gasto(
    agent_did=agent_id,
    operation="stripe_charge",
    tool_call_id="payment-002",
    amount_usd="20.00",
)

if receipt["execution_permitted"] is True:
    result = execute_payment()
else:
    result = "BLOCKED"

The integration layer remains responsible for ensuring the external tool is invoked only when receipt["execution_permitted"] is True.


πŸ” Idempotency & Replay Protection

AEGIS identifies an authorization using the agent and tool-call identity.

First request:

tool_call_id: payment-001
amount:       $3.00

        β”‚
        β–Ό
      ALLOW
        β”‚
        β”œβ”€β”€ budget decreases once
        β”œβ”€β”€ cached: False
        β”œβ”€β”€ execution_permitted: True
        └── signed receipt created

Exact replay:

tool_call_id: payment-001
amount:       $3.00

        β”‚
        β–Ό
   HISTORICAL RECEIPT
        β”‚
        β”œβ”€β”€ same action_ref
        β”œβ”€β”€ cached: True
        β”œβ”€β”€ execution_permitted: False
        └── NO second debit

policy_decision describes the signed historical authorization. External tools must execute only when execution_permitted is True. Exact replays retain the historical receipt but receive no new process-local execution grant.

Conflicting replay:

SAME TRANSACTION ID
        β”‚
        β”œβ”€β”€ original amount: $1.00
        └── new amount:      $100.00
                    β”‚
                    β–Ό
                  DENY
                    β”‚
                    β–Ό
           idempotency_conflict

Validated:

Exact replay does not double-debit        PASS
Same ID + different amount blocked        PASS
Same ID + different operation blocked     PASS
100 same-ID concurrent retries grant one execution    PASS

πŸ” Cryptographic Authorization

AEGIS signs deterministic authorization semantics rather than an unstructured success flag.

             POLICY EVALUATION
                    β”‚
                    β–Ό
          DETERMINISTIC PAYLOAD
                    β”‚
                    β”œβ”€β”€ agent_did
                    β”œβ”€β”€ operation
                    β”œβ”€β”€ amount
                    β”œβ”€β”€ decision
                    └── tool-call binding
                    β”‚
                    β–Ό
                  SHA-256
                    β”‚
                    β–Ό
                  Ed25519
                    β”‚
                    β–Ό
           SIGNED POLICY RECEIPT
                    β”‚
                    β–Ό
                action_ref

Example receipt:

{
    "agent_did": "agent-demo-001",
    "operation": "stripe_charge",
    "amount_usd": "3.00",
    "policy_decision": "allow",
    "policy_attenuations": [],
    "policy_signature": "ed25519:...",
    "action_ref": "...",
    "cached": False,
    "execution_permitted": True
}

action_ref is represented as the 64-character hexadecimal encoding of a 32-byte SHA-256 digest.

SHA-256 digest     32 bytes
        β”‚
        β–Ό
action_ref         64 hexadecimal characters

πŸ§ͺ Tamper Detection

Original signed authorization:

ORIGINAL PAYLOAD
      β”‚
      β”œβ”€β”€ SHA-256
      β”‚
      └── Ed25519
             β”‚
             β–Ό
           VALID βœ“

Modify signed data:

MODIFIED PAYLOAD
      β”‚
      β”œβ”€β”€ different digest
      β”‚
      └── original signature
             β”‚
             β–Ό
          INVALID βœ—

Validated:

Signature verification              PASS
Tampered authorization rejected     PASS

πŸ›‘ Fail-Closed Security

AEGIS is designed to prefer denial over silent authorization when the protected authorization path fails.

          INTERNAL FAILURE
                 β”‚
                 β–Ό
               πŸ›‘ DENY
                 β”‚
                 β–Ό
         TOOL MUST NOT EXECUTE

Validated forced cryptographic failure:

BALANCE BEFORE:       10.00
DECISION:              deny
BALANCE AFTER:        10.00
BALANCE PRESERVED:     True
FAIL-CLOSED:           True
ROLLBACK:              PASS

Configured invalid-key behavior:

CONSTRUCTOR EXCEPTION: ValueError
GATE CREATED:          False

FAIL-CLOSED STARTUP:   True
EMERGENCY RECOVERY:    False
SECURITY MODEL:        INVALID KEY REJECTED

RESULT: PASS

This prevents an invalid configured cryptographic identity from being silently replaced at startup.


πŸ’° Financial-Loss Adversarial Matrix

AEGIS was exercised against a focused matrix of economic failure scenarios.

Scenario Result
Exact replay does not double-debit βœ… PASS
Same ID + different amount blocked βœ… PASS
Same ID + different operation blocked βœ… PASS
Signature failure preserves balance βœ… PASS
Over-budget request blocked without mutation βœ… PASS
Exact-balance authorization βœ… PASS
Zero / negative / non-numeric fail closed βœ… PASS
Excess monetary precision rejected βœ… PASS
DENY does not execute tool βœ… PASS
Signed authorization verifies βœ… PASS
Tampered receipt rejected βœ… PASS
tool_call_id changes action_ref βœ… PASS
TOTAL TESTS: 12
PASS:        12
FAIL:         0

FINAL RESULT: PASS

🧡 Concurrent Double-Spend Protection

A 1,000-request adversarial contention test was executed against a budget capable of funding only one request.

Configuration:

REQUESTS:          1,000
WORKERS:             100
INITIAL BALANCE:   $10.00
AMOUNT EACH:       $10.00

Result:

                 $10 AVAILABLE
                       β”‚
            1,000 COMPETING REQUESTS
                       β”‚
                       β–Ό
                   AEGIS LOCK
                       β”‚
                β”Œβ”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”
                β”‚             β”‚
                β–Ό             β–Ό
           1 Γ— ALLOW      999 Γ— DENY
               β”‚
               β–Ό
           $10 AUTHORIZED
               β”‚
               β–Ό
          FINAL BALANCE $0

Measured result:

Property Result
Allow 1
Deny 999
Authorized total $10.00
Final balance $0.00
Overspend NO
Result PASS

This demonstrates concurrent budget protection inside the current process-local execution model.

It does not demonstrate cross-process or distributed consensus.


🏦 Atomic L3 Settlement

AEGIS includes an isolated L3 settlement layer that consumes a signed authorization before mutating settlement balances.

               AI AGENT
                  β”‚
                  β–Ό
         AEGIS AUTHORIZATION
                  β”‚
            SHA-256 + Ed25519
                  β”‚
                  β–Ό
         SIGNED POLICY RECEIPT
                  β”‚
                  β–Ό
       β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
       β”‚   L3 VERIFICATION    β”‚
       β”‚                      β”‚
       β”‚ βœ“ decision = allow   β”‚
       β”‚ βœ“ payload rebuilt    β”‚
       β”‚ βœ“ action_ref         β”‚
       β”‚ βœ“ Ed25519 signature  β”‚
       β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                  β”‚
                  β–Ό
            BEGIN IMMEDIATE
                  β”‚
            β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”
            β”‚           β”‚
            β–Ό           β–Ό
        DEBIT BUYER  CREDIT SELLER
            β”‚           β”‚
            β””β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”˜
                  β”‚
                  β–Ό
          SETTLEMENT RECORD
                  β”‚
                  β–Ό
                COMMIT

If settlement fails after the transaction begins:

FAILURE
   β”‚
   β–Ό
ROLLBACK
   β”‚
   β–Ό
BALANCES PRESERVED

Validated L3 security matrix:

L3 Property Result
Signed settlement βœ… PASS
Conservation of value βœ… PASS
Exact replay idempotent βœ… PASS
Tampered seller blocked βœ… PASS
Tampered amount blocked βœ… PASS
Atomic rollback βœ… PASS
Concurrent limited-budget settlement βœ… PASS

Concurrent L3 test:

REQUESTS: 100

SETTLED: 1
DENIED:  99

TOTAL: 7
PASS:  7
FAIL:  0

FINAL RESULT: PASS

⚑ Measured Performance

Performance is reported by execution layer.

AEGIS does not use a single latency number to represent different workloads.

Local Benchmark Environment

The following results were measured locally during the current validation run using time.perf_counter_ns().

They are local process measurements and must not be interpreted as Internet or hosted API round-trip latency.

1️⃣ Economic Decision Primitive

Isolates local:

lock
+
Decimal comparison
+
Decimal subtraction
+
quantization
Metric Measured
Minimum 0.400 Β΅s
Median 0.500 Β΅s
P95 1.000 Β΅s
P99 1.300 Β΅s
MEDIAN = 0.000500 ms

2️⃣ Idempotency Cache Hit

Metric Measured
Minimum 2.200 Β΅s
Median 2.400 Β΅s
P95 4.900 Β΅s
P99 7.700 Β΅s
MEDIAN = 0.002400 ms

3️⃣ Full Signed Authorization

Includes the complete local authorization path measured by the benchmark:

validation
    β”‚
    β–Ό
lock
    β”‚
    β–Ό
idempotency
    β”‚
    β–Ό
budget decision
    β”‚
    β–Ό
deterministic payload
    β”‚
    β–Ό
SHA-256
    β”‚
    β–Ό
Ed25519
    β”‚
    β–Ό
receipt
Metric Measured
Minimum 45.200 Β΅s
Median 47.900 Β΅s
Mean 57.363 Β΅s
P95 81.600 Β΅s
P99 153.900 Β΅s
MEDIAN = 0.047900 ms

4️⃣ L3 SQLite In-Memory Settlement

Signed receipt verification + SQLite transactional settlement using :memory:.

Metric Measured
Minimum 133.400 Β΅s
Median 146.550 Β΅s
P95 245.900 Β΅s
P99 393.200 Β΅s
MEDIAN = 0.146550 ms

5️⃣ L3 Local File-Backed SQLite

Signed receipt verification + local file-backed SQLite transaction.

Metric Measured
Minimum 486.600 Β΅s
Median 969.200 Β΅s
Mean 1.022 ms
P95 1.621 ms
P99 2.188 ms
MEDIAN = 0.969200 ms

File-backed SQLite results include the local persistence path, but should not be interpreted as guaranteed physical-disk latency for every operation because SQLite and the operating system may cache I/O.


πŸ“Š Performance Summary

Layer Median P95 P99
⚑ Economic decision primitive 0.500 ¡s 1.000 ¡s 1.300 ¡s
πŸ” Idempotency cache hit 2.400 Β΅s 4.900 Β΅s 7.700 Β΅s
πŸ” Full signed authorization 47.900 Β΅s 81.600 Β΅s 153.900 Β΅s
🏦 L3 SQLite :memory: 146.550 ¡s 245.900 ¡s 393.200 ¡s
πŸ’Ύ L3 local file-backed SQLite 969.200 Β΅s 1.621 ms 2.188 ms

Relative measured cost

SIGNED / DECISION:        95.80Γ—
FILE L3 / MEMORY L3:       6.61Γ—
L3 MEMORY / SIGNED:        3.06Γ—

πŸ”¬ Why the Latency Numbers Are Separated

A previous single latency number can hide which work is actually being measured.

AEGIS therefore reports the layers independently:

0.500 Β΅s
DECISION PRIMITIVE
      β”‚
      β–Ό
2.400 Β΅s
IDEMPOTENCY CACHE HIT
      β”‚
      β–Ό
47.900 Β΅s
FULL SIGNED AUTHORIZATION
      β”‚
      β–Ό
146.550 Β΅s
L3 SQLITE :MEMORY:
      β”‚
      β–Ό
969.200 Β΅s
LOCAL FILE-BACKED SQLITE

These numbers answer different questions.

AEGIS therefore does not present 0.005 ms as a full L3 or end-to-end settlement latency claim.

The current evidence supports low-microsecond local hot paths and a sub-millisecond median for the tested local signed and SQLite settlement paths described above.


🧯 Benchmark Contamination Checks

The final evidence benchmark also isolates common measurement contamination.

Print overhead

Measured write to os.devnull:

NO-PRINT MEDIAN:         0.200 Β΅s
PRINT MEDIAN:            2.400 Β΅s
ADDED MEDIAN COST:       2.200 Β΅s

Intentional sleep(0.001)

REQUESTED SLEEP:         1.000 ms
OBSERVED MEDIAN:         1.696 ms
P95:                     1.941 ms
P99:                     2.251 ms

Therefore intentional sleeps and console/debug work are kept conceptually separate from engine latency claims.


🚫 What These Benchmarks Do NOT Measure

The current benchmark does not measure:

βœ— Client β†’ Internet β†’ Render β†’ client HTTP round-trip

βœ— Multi-process coordination

βœ— Multi-worker shared-state coordination

βœ— Multi-node distributed consensus

βœ— Remote Redis coordination

βœ— Remote PostgreSQL coordination

βœ— Stripe settlement latency

βœ— Blockchain settlement latency

No number for those layers is inferred from the local benchmark.

LOCAL ENGINE PERFORMANCE
          β‰ 
NETWORK ROUND-TRIP
          β‰ 
DISTRIBUTED CONSENSUS
          β‰ 
EXTERNAL FINANCIAL SETTLEMENT

🌐 Independent External Evaluation β€” kube-coder

AEGIS Core 3.4.0 has received a public external source-level evaluation and benchmark in kube-coder issue #573.

The external project-side evaluator inspected the published artifacts and source, verified package hashes, reviewed package behavior, and benchmarked the relevant local execution paths.

Externally reported local measurements

Path Median p95 p99
Process-local signed gate 0.0582 ms 0.1042 ms 0.1260 ms
File-backed settlement, end-to-end 1.1349 ms 3.2434 ms 4.6677 ms

The evaluator described the package as real/readable and did not identify malicious package behavior. The fit decision, however, was not to adopt AEGIS as the dependency for kube-coder Phase 4.

The reasons were architectural and are important:

  • kube-coder's LLM-turn cost is not fully known before the call, while AEGIS 3.4.0 expects a supplied amount before authorization;
  • kube-coder needs shared durable budget state across agent processes, while the AEGIS local gate is process-local;
  • Ed25519 receipts solve a trust-boundary problem that does not exist when policy and enforcement live inside the same trusted process;
  • kube-coder already has an in-process refusal point, so a network-latency race is not the relevant failure mode there.

The same review then recorded AEGIS patterns worth carrying into kube-coder's own Phase 4 design:

  1. durable allow/deny decision receipts;
  2. idempotency with conflict detection;
  3. integer monetary units rather than binary float;
  4. evaluate β†’ record β†’ mutate commit ordering;
  5. fail-closed behavior on internal faults;
  6. attenuated policy outcomes for soft-cap/hard-cap behavior.

Evidence classification:

  • External source review: YES
  • External benchmark: YES
  • External fit assessment: YES
  • Design influence: YES
  • kube-coder adoption: NO
  • kube-coder integration: NO
  • Production validation: NO
  • Institutional endorsement: NO

Full evidence record: EXTERNAL_EVALUATION_KUBE_CODER.md

Primary public sources:


🌍 External Engineering Impact β€” PayMCP

A retry/disconnect failure mode reported by Iraitz / LortuArte was credited in the merged upstream PayMCP PR #52, β€œReturn the paid result on retry instead of running the tool twice.”

The upstream PR documents that a paid tool could execute, the client could disconnect before receiving the result, and a retry could execute the underlying tool again. For tools with side effects, the external action could therefore happen twice even though there was one payment.

PayMCP's merged fix stores and replays the paid result instead of automatically re-executing the consequential tool path.

Evidence classification:

  • Externally credited engineering finding: YES
  • Upstream fix merged: YES
  • Independent confirmation that retry ambiguity can cause duplicate consequential execution: YES
  • AEGIS dependency used by PayMCP: NO
  • AEGIS integration/adoption by PayMCP: NO
  • Production validation or endorsement of AEGIS: NO

This is published as external engineering impact and problem validation, not as an AEGIS adoption claim.

Full evidence record: EXTERNAL_ENGINEERING_IMPACT_PAYMCP.md


πŸ§ͺ Security Evidence

Current focused evidence:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚              AEGIS SECURITY                   β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Cryptographic rollback                  PASS  β”‚
β”‚ Idempotency conflict                    PASS  β”‚
β”‚ tool_call_id binding                    PASS  β”‚
β”‚ Invalid configured key                  PASS  β”‚
β”‚ Fail-closed startup                     PASS  β”‚
β”‚ Ed25519 verification                    PASS  β”‚
β”‚ Tamper detection                        PASS  β”‚
β”‚ DENY β†’ tool not executed                PASS  β”‚
β”‚ Decimal boundary handling               PASS  β”‚
β”‚ Financial-loss matrix             12/12 PASS  β”‚
β”‚ 1,000-request double-spend              PASS  β”‚
β”‚ L3 settlement matrix                7/7 PASS  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

This evidence is intended to be reproducible from the repository rather than accepted as a marketing claim.


🧰 Reproduce the Evidence

Core integration:

python test_integration.py

Enforcement:

python test_enforcement.py

Concurrent budget protection:

python test_concurrency.py

Cryptographic rollback:

python test_signature_failure_rollback.py

Idempotency conflict:

python test_idempotency_conflict.py

Tool-call cryptographic binding:

python test_tool_call_binding.py

Configured-key fail-closed behavior:

python test_key_failure_behavior.py

Financial-loss adversarial matrix:

python test_financial_loss_matrix.py

1,000-request double-spend test:

python test_double_spend_1000.py

L3 settlement security:

python test_l3_settlement.py

Final layered performance evidence:

python benchmark_final_evidence.py

Expected high-level security status:

CORE SECURITY              PASS
FINANCIAL MATRIX      12/12 PASS
DOUBLE-SPEND               PASS
L3 SECURITY            7/7 PASS
PERFORMANCE EVIDENCE    COMPLETE

πŸ—οΈ Current Architecture

                         AI AGENT
                            β”‚
                            β–Ό
                         TOOL INTENT
                            β”‚
                            β–Ό
                β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                β”‚   πŸ›‘οΈ AEGIS CORE     β”‚
                β”‚                      β”‚
                β”‚ Monetary Validation  β”‚
                β”‚ Idempotency          β”‚
                β”‚ Atomic Lock          β”‚
                β”‚ Budget Enforcement   β”‚
                β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                           β”‚
                    β”Œβ”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”
                    β”‚             β”‚
                    β–Ό             β–Ό
                  ALLOW          DENY
                    β”‚             β”‚
                    β”‚             └──────────► πŸ›‘ BLOCK
                    β–Ό
           DETERMINISTIC PAYLOAD
                    β”‚
                    β–Ό
                 SHA-256
                    β”‚
                    β–Ό
                 Ed25519
                    β”‚
                    β–Ό
          SIGNED AUTHORIZATION
                    β”‚
          β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
          β”‚                   β”‚
          β–Ό                   β–Ό
   PROTECTED TOOL       L3 SETTLEMENT
                              β”‚
                              β–Ό
                      VERIFY AUTHORIZATION
                              β”‚
                              β–Ό
                       BEGIN IMMEDIATE
                              β”‚
                     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”
                     β”‚                 β”‚
                     β–Ό                 β–Ό
                   DEBIT             CREDIT
                     β”‚                 β”‚
                     β””β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                              β”‚
                              β–Ό
                            COMMIT

The authorization core and settlement layer are intentionally separated.

That separation makes it possible to benchmark, test, and reason about each boundary independently.


πŸ”¬ Current Security Model

AEGIS currently demonstrates these properties:

1. Enforce Before Execution

Authorization is produced before the integration invokes the protected external tool.

2. Atomic Process-Local Accounting

A lock protects local ledger mutation from concurrent access inside the current process.

3. Replay-Safe Authorization

Exact replay does not consume budget twice.

Conflicting reuse of transaction identity is denied.

4. Deterministic Authorization

Security-relevant authorization data is deterministically serialized before hashing and signing.

5. Cryptographic Verification

SHA-256 and Ed25519 allow downstream verification of authorization integrity.

6. Economic Rollback

Failures in protected authorization and settlement paths preserve economic state when the tested transaction must fail.

7. Atomic Local Settlement

The isolated L3 layer performs transactional buyer β†’ seller mutation and records settlement atomically under the tested SQLite model.


⚠️ Current Scope & Limitations

AEGIS Core 3.4.0 is Beta software.

Current tested scope

βœ“ Process-local authorization
βœ“ Process-local locking
βœ“ Decimal monetary accounting
βœ“ Replay-safe idempotency
βœ“ Idempotency conflict detection
βœ“ Deterministic authorization receipts
βœ“ SHA-256 action references
βœ“ Ed25519 signatures
βœ“ tool_call_id cryptographic binding
βœ“ Fail-closed authorization behavior
βœ“ Invalid configured-key rejection
βœ“ Economic rollback
βœ“ Concurrent local budget enforcement
βœ“ One process-local execution grant across 100 same-ID concurrent retries
βœ“ Atomic SQLite L3 settlement
βœ“ L3 replay protection
βœ“ L3 tamper rejection

Not currently claimed

βœ— Cross-process atomicity

βœ— Shared state across multiple workers

βœ— Multi-node consensus

βœ— Distributed ledger coordination

βœ— Redis-backed distributed locking

βœ— PostgreSQL-backed distributed settlement

βœ— Byzantine fault tolerance

βœ— Blockchain finality

βœ— Stripe settlement guarantees

βœ— Internet-scale production readiness

βœ— Exactly-once external side effects

βœ— Crash recovery after external dispatch

βœ— Automatic reserve / commit / release reconciliation

These are separate production/distributed-system concerns and should not be inferred from the current local evidence.


πŸ”­ Current vs Future Architecture

Current

Agent
  β”‚
  β–Ό
AEGIS Core
  β”‚
  β”œβ”€β”€ authorization
  β”œβ”€β”€ budget control
  β”œβ”€β”€ idempotency
  β”œβ”€β”€ SHA-256
  └── Ed25519
  β”‚
  β–Ό
Signed Receipt
  β”‚
  β–Ό
Local Atomic L3 Settlement

Future / Distributed Direction

                 MULTIPLE AGENTS
                       β”‚
                       β–Ό
                DISTRIBUTED AEGIS
                       β”‚
           β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
           β”‚           β”‚           β”‚
           β–Ό           β–Ό           β–Ό
      Shared State  Coordination  Persistence
           β”‚           β”‚           β”‚
           β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                       β”‚
                       β–Ό
              DISTRIBUTED SETTLEMENT

The distributed architecture is a direction, not a claim about the current implementation.


🎯 Current Position

AEGIS is not an LLM reasoning guardrail.

It operates at the execution boundary:

              AGENT REASONING
                    β”‚
                    β–Ό
                 TOOL INTENT
                    β”‚
                    β–Ό
                 πŸ›‘οΈ AEGIS
                    β”‚
        β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
        β”‚           β”‚           β”‚
        β–Ό           β–Ό           β–Ό
     BUDGET     IDEMPOTENCY  CRYPTOGRAPHY
        β”‚           β”‚           β”‚
        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                    β”‚
                    β–Ό
        execution_permitted True / False
                    β”‚
              β”Œβ”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”
              β”‚           β”‚
              β–Ό           β–Ό
        TOOL EXECUTION     L3
                       SETTLEMENT

The goal is narrow: make economically sensitive agent actions explicitly authorized, cryptographically verifiable, and testable before irreversible execution.


πŸ“‹ Evidence Status

Evidence class Status
Local focused tests βœ… PASS
Local adversarial/concurrency tests βœ… PASS
Reproducible local benchmark suite βœ… Documented
Independent external source review βœ… Completed
Independent external benchmark βœ… Completed
External design influence βœ… Documented
Externally credited engineering finding βœ… PayMCP PR #52 merged
External product integration ❌ Not yet
External production validation ❌ Not yet
Distributed/multiprocess guarantees ❌ Not claimed

The external evidence is intentionally separated from local author-run evidence. See EXTERNAL_EVALUATION_KUBE_CODER.md.


πŸ“¦ Package

Distribution aegis-core-lortuarte-sdk
Version 3.4.0
Python >=3.8
Status Beta
License MIT

Install:

pip install aegis-core-lortuarte-sdk

πŸ“„ License

MIT License.

About

Process-local budget authorization and replay-aware execution disposition for Python AI-agent tools.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages