$npx skillfedfor your agent

agentrust-trace

TRACE v0.2 — hardware-attested governance records for AI agents

With conditionsPyPI Artificial IntelligenceReleased Aug 202678.7K downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — agentrust_trace-0.9.0-py3-none-any.whl
v0.9.0 · released 2026-08-09 · Python >=3.11 · 4 runtime deps: cryptography, jsonschema, pydantic, rfc8785

Yes, if you are building AI agent governance infrastructure for regulated or high-assurance environments. The package is actively maintained, has no known vulnerabilities, and implements an emerging standard aligned with IETF and OASIS efforts. However, it is in Alpha (v0.2) and explicitly marked for developer preview—do not rely on it in production without reviewing the Limitations page. Install if you are prototyping or evaluating hardware-attested agent compliance; defer if you need stable, production-hardened tooling.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.11 or later; signing and verification require cryptographic keys (not generated by the library).
  • Active development with a recent release (5 days old).
  • Low install friction with pure-Python wheel distribution.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial use, modification, and distribution with minimal restrictions—suitable for proprietary agent governance pipelines.

last release 2026-08-09 (5 days) · last repo commit 2026-08-14 · 7 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 78,719 downloads/mo, #14,415 on PyPI

Verify before relying

pip install agentrust-trace

from agentrust_trace import TrustRecord, sign_record

record = TrustRecord(
    subject="spiffe://trust.example.org/agent/payments-processor",
    model_id="claude-sonnet-4-6",
    platform="amd-sev-snp",
    policy_hash="sha256:b2c3d4...",
)
signed = sign_record(record, key=signing_key)
  • Whether the library handles SCITT ledger anchoring directly or requires external integration.
  • Scope and maturity of the conformance test suite coverage.
  • Production-readiness timeline and stability guarantees beyond v0.2.
Same gist for agents: .md · .json

What it is and what it does

agentrust-trace is a Python implementation of TRACE v0.2, an open specification for hardware-attested AI agent governance records. It lets you create signed Trust Records that cryptographically prove what model ran, where it ran (in which TEE), under which policy, what data class it touched, and which tools it called—all bound into a single artifact rooted in silicon attestation. Any third party can verify the record without trusting the operator.

The package provides TrustRecord objects that capture agent execution context and sign them using cryptographic keys. It builds on IETF standards (RFC 9711 for CBOR Web Token/EAT, RFC 9334 for RATS roles, SCITT for transparency-ledger anchoring) and is designed for CoSAI WS4 interoperability. It's intended to integrate with agent governance frameworks like AGT and cMCP to create end-to-end compliance pipelines for confidential AI workloads.

Use it for

  • Prove to regulators or auditors that a financial AI agent ran under approved policy in a confidential environment without exposing operator infrastructure.
  • Create verifiable compliance records for AI agents processing classified or sensitive data in regulated industries.
  • Build a transparent governance pipeline where agent execution evidence is independently anchored to a ledger for non-repudiation.
  • Integrate with confidential computing platforms (AMD SEV-SNP, Intel TDX) to bind agent behavior to hardware attestation.
  • Enable third-party verification of AI agent behavior without requiring trust in the operator or access to internal logs.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are building AI agent governance infrastructure for regulated or high-assurance environments.

The package is actively maintained, has no known vulnerabilities, and implements an emerging standard aligned with IETF and OASIS efforts. However, it is in Alpha (v0.2) and explicitly marked for developer preview—do not rely on it in production without reviewing the Limitations page. Install if you are prototyping or evaluating hardware-attested agent compliance; defer if you need stable, production-hardened tooling.

Install

agentrust-trace on PyPI

Before you install

Active development with a recent release (5 days old). Low install friction with pure-Python wheel distribution. Requires current Python versions (3.11+) and four standard dependencies (cryptography, jsonschema, pydantic, rfc8785). Early-stage project (Alpha status) launched June 2026.

Requires Python 3.11 or later; signing and verification require cryptographic keys (not generated by the library).

License in practice

Apache-2.0 permissive license allows commercial use, modification, and distribution with minimal restrictions—suitable for proprietary agent governance pipelines.

Quickstart

pip install agentrust-trace

from agentrust_trace import TrustRecord, sign_record

record = TrustRecord(
    subject="spiffe://trust.example.org/agent/payments-processor",
    model_id="claude-sonnet-4-6",
    platform="amd-sev-snp",
    policy_hash="sha256:b2c3d4...",
)
signed = sign_record(record, key=signing_key)

Verify before relying

  • Whether the library handles SCITT ledger anchoring directly or requires external integration.
  • Scope and maturity of the conformance test suite coverage.
  • Production-readiness timeline and stability guarantees beyond v0.2.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release >=3.11
Install frictionLow. Pure-Python wheel
Runtime dependencies
4 packages
cryptographyjsonschemapydanticrfc8785
MaintenanceActively maintained 5 days since the last release
Last repo commit
First released
Downloads78,719 / month, #14,415 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 3 - AlphaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Topic :: Scientific/Engineering :: Artificial IntelligenceTopic :: SecurityTyping :: Typed

Evidence: agentrust_trace-0.9.0-py3-none-any.whl

Tags

Capabilities
ai agent attestationhardware-attested governancetrust record signingconfidential computing complianceagent policy verificationcryptographic evidence recordstee attestation python
Topics
ai-governanceattestationconfidential-computing
PyPI keywords
ai-governanceattestationconfidential-computingeatratsteetrace

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ai agent attestation”

Give your agent the search over MCP, or paste the wish link into any chat.

More Artificial Intelligence packages

litellm With conditions
PyPI · Artificial Intelligence · released Aug 2026

LiteLLM provides a unified Python interface to call 100+ LLM providers (OpenAI, Anthropic, Gemini, Bedrock, Azure, and others) using OpenAI-compatible API format, available as both a Python SDK and a self-hosted AI Gateway proxy server.

Install it if you need to work with multiple LLM providers or want to centralize LLM routing in your organization.

MITcompiled wheel
682.8Mdownloads / mo
huggingface-hub Worth it
PyPI · Artificial Intelligence · released Aug 2026

Client library and CLI tool for downloading, uploading, and managing models, datasets, and repositories on the Hugging Face Hub platform.

Install it if you work with Hugging Face Hub models or datasets.

Apache-2.0pure Python · 3.10.0+
442.4Mdownloads / mo
langchain Worth it
PyPI · Python Modules · released Aug 2026

LangChain provides a framework for building agents and LLM-powered applications by composing language models, tools, and memory through a unified API that abstracts over multiple model providers.

MITpure Python
315.4Mdownloads / mo
hf-xet With conditions
PyPI · Artificial Intelligence · released Aug 2026

hf-xet provides chunk-based deduplication and efficient file transfer for the Hugging Face Hub, enabling faster uploads and downloads of large files with local disk caching.

Apache-2.0compiled wheel · 3.8+
258.4Mdownloads / mo
tokenizers Worth it
PyPI · Artificial Intelligence · released Apr 2026

Tokenizers converts raw text into token sequences for NLP models, with support for training custom vocabularies and using pre-built tokenizers (BPE, WordPiece) optimized for speed via Rust.

Apache-2.0compiled wheel · 3.10+
222.9Mdownloads / mo
transformers Worth it
PyPI · Artificial Intelligence · released Aug 2026

Transformers provides a unified framework for loading, fine-tuning, and running state-of-the-art pretrained models across text, vision, audio, video, and multimodal tasks using PyTorch, JAX, or TensorFlow.

Install it if you need to run or train any transformer-based model for NLP, vision, audio, or multimodal tasks.

permissive licensepure Python · 3.10.0+
186.6Mdownloads / mo

See also agent_governance_toolkit · agent-governance-toolkit-core · agent-governance-toolkit-cli · ciris-server · claude-tap · pydantic-ai-shields · spec-kitty-events · hol-guard · plugin-scanner · ddapm-test-agent

Further reading