Skip to content

Threat model

AttackResponse
PDF says pay the attackerUntrusted text cannot widen the mandate; check the directory
Summary says transfer, payload is approveIndependent decoder
Address / amount / calldata change after approvalNew digest; old bundle fails
One shop, three keysOperator policy on the trust registry
Move signatures to another tenant or chainDomain tags and binding fields
Orchestrator swaps a verdictSignature covers the verdict and material fields
Shop for a PASSPinned verifiers, DENY tracking, revision limits
Two calls spend one budgetAtomic claim, or on-chain stateful limit
Submit, lose the HTTP responseIdempotency key, SUBMISSION_UNKNOWN
Risk API downINCONCLUSIVE; do not skip
Key revoked after PASSCheck current epoch at the gate
Agent calls the bank API itselfAgent has no credentials; execution path is locked
Hide the name, keep the addressMinimization, not anonymity

Do not multiply three LLM error rates. The errors are correlated.

Before production: cross-language test vectors, a negative test per row above, concurrency on payment failures, review of every smart-account path, external audit. Those are acceptance criteria, not work this document already did.

The core does not need a token or a chain. An append-only log is enough; anchoring is optional and does not prove the checks were right.

ERC-8004 can supply agent identity or a place to publish results. VAP still owns approval of a specific action.