a2aproject / a2aproject/A2A

Proposal: Verifiable Reputation Pointer extension (typed, content-addressed reputation field on the Agent Card)

Aperta
#2,097 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Shell
Stelle
25.7k
Fork
2.6k
Merge medio
3g 6h
PR unite (30g)
16

Descrizione

## Abstract

A data-only extension defining a typed field an `AgentCard` MAY carry: a pointer to an agent's reputation record that is **content-addressed and independently recomputable**, not merely a link a caller has to trust on the issuer's word.

## Motivation

An `AgentCard` can already carry an arbitrary URL to a reputation page in `metadata` or free text. That's insufficient for three reasons the core protocol doesn't currently address:

1. **No commitment to a specific export.** A bare URL can change server-side at any time with no caller-visible signal — no way to confirm the record checked five minutes ago is the same one being served now.
2. **No fork detection.** A server could show different histories to different callers, each individually plausible, with no way to catch it without comparing notes out of band.
3. **No explicit start-of-history marker.** A caller walking a reputation feed backward can't distinguish "this is genuinely where history starts" from "the history before this point was truncated" — both look identical (an absent predecessor).

None of this is achievable with the core protocol or `metadata` alone, since it requires a *typed*, *checkable* contract (a defined verification procedure a caller runs), not just a place to put a string.

## Technical approach

Full RFC 2119 specification + a zero-dependency Python reference implementation, checked against a real, live example (not a synthetic fixture) — this repo:

**https://github.com/babyblueviper1/a2a-ext-reputation-pointer**

The pointer carries `issuer`/`scheme`/`ref`, a `verifyingKey`, an anchored `committedAt`, a content-addressed `headCommitment` chaining the record into an ordered history, a `publishedHeadLocation` (independent locations a caller compares to catch a fork), and an explicit `genesisMarker` (a fixed, checkable constant distinguishing start-of-chain from truncation).

The reference implementation's example is a real `AgentCard` extension declaration pointing at entry #40 of [invinoveritas](https://api.babyblueviper.com/ledger)'s own reputation ledger — the documented root its content-addressed head-chain starts from. `python3 v1/reference-python/verify_reputation_pointer.py` independently recomputes `headCommitment` and `genesisMarker` from the record's own bytes and confirms both are tamper-sensitive.

Originated from a real design discussion: #1962.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Review the linked repository (https://github.com/babyblueviper1/a2a-ext-reputation-pointer) for the full RFC and Python reference implementation. Understand the AgentCard structure and the proposed extension fields (issuer, scheme, ref, verifyingKey, committedAt, headCommitment, publishedHeadLocation, genesisMarker). Run the verification script (python3 v1/reference-python/verify_reputation_pointer.py) against the example to see how the content-addressed reputation record is validated. The goal is to integrate this extension specification into the A2A protocol documentation or codebase.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
python, shell
Ambito
backend-api-design
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
45/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.