{"categories":[{"label":"Artificial Intelligence","url":"https://skillfed.io/packages/category/scientific-engineering-artificial-intelligence/11"},{"label":"Security","url":"https://skillfed.io/packages/category/security/3"}],"enrichment":{"capability":"Creates and verifies cryptographically signed Trust Records that prove an AI agent ran under a specific policy in a verified hardware environment, touching classified data and invoking identified tools.","skillfed_tags":["ai-governance","attestation","confidential-computing"],"use_cases":["Prove to regulators or auditors that a financial AI agent ran under approved policy in a confidential environment without exposing operator infrastructure.","Create verifiable compliance records for AI agents processing classified or sensitive data in regulated industries.","Build a transparent governance pipeline where agent execution evidence is independently anchored to a ledger for non-repudiation.","Integrate with confidential computing platforms (AMD SEV-SNP, Intel TDX) to bind agent behavior to hardware attestation.","Enable third-party verification of AI agent behavior without requiring trust in the operator or access to internal logs."],"what_it_does":"agentrust-trace is a Python implementation of TRACE v0.2, an open specification for hardware-attested AI agent governance records. It lets you create signed Trust Records that cryptographically prove what model ran, where it ran (in which TEE), under which policy, what data class it touched, and which tools it called\u2014all bound into a single artifact rooted in silicon attestation. Any third party can verify the record without trusting the operator.\n\nThe package provides TrustRecord objects that capture agent execution context and sign them using cryptographic keys. It builds on IETF standards (RFC 9711 for CBOR Web Token/EAT, RFC 9334 for RATS roles, SCITT for transparency-ledger anchoring) and is designed for CoSAI WS4 interoperability. It's intended to integrate with agent governance frameworks like AGT and cMCP to create end-to-end compliance pipelines for confidential AI workloads.","worth_installing":"Yes, if you are building AI agent governance infrastructure for regulated or high-assurance environments. The package is actively maintained, has no known vulnerabilities, and implements an emerging standard aligned with IETF and OASIS efforts. However, it is in Alpha (v0.2) and explicitly marked for developer preview\u2014do not rely on it in production without reviewing the Limitations page. Install if you are prototyping or evaluating hardware-attested agent compliance; defer if you need stable, production-hardened tooling."},"id":"agentrust-trace","links":{"html":"https://skillfed.io/packages/agentrust-trace","md":"https://skillfed.io/packages/agentrust-trace.md","pypi":"https://pypi.org/project/agentrust-trace/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-09","license_spdx":null,"license_treatment":"permissive","name":"agentrust-trace","python_support":"supports_current","summary":"TRACE v0.2 \u2014 hardware-attested governance records for AI agents"},"popularity":{"monthly_downloads":78719,"position":14415,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"0.9.0"}
