Skip to content

Commit 5b0d462

Browse files
Show what the demos and the quickstart actually print (#25)
Both pages describe outcomes in prose and never show the output. For pages whose whole pitch is "don't take the spec on trust, run it", the output is the argument. I ran the published quickstart end to end against cmcp-runtime 0.4.0 and demo 6 against weight-custody-manifest 0.25.0. Both do exactly what the pages say, so nothing here corrects a claim about behaviour. What changes is that a reader can now see it before they install anything. Quickstart: - Step 4 shows the response body the runtime really returns, replacing a one-line prose summary of it. - That body carries a call_id, and the same id lands in the audit chain, which is the thread from the block in step 4 to the signed record in step 5. The page never mentioned it, and it is the point. - Step 5 shows the CRYPTO-001 advisory the CLI prints before the checks. It is not a failure, but it is the first thing on screen and the page did not prepare anyone for it. - Says which version the page was last verified against, and that a step not behaving as written is a bug worth reporting. Demos: - The governance section said "these five govern the tool boundary" above six cards. Demo 10 is in that section and governs model calls, not the tool boundary. - The card times sum to thirteen minutes, not twelve. Fixed in the hero and in the meta, OG and Twitter descriptions. - Dropped export CMCP_BEARER_TOKEN from the quick start: demo.py sets it, as the repo README says. Added --no-pause, without which the runner waits for a keypress before every demo. - Added demo 6's verbatim output. Claude-Session: https://claude.ai/code/session_013EQx4N5BzTQbY8kvXUsdkY Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 81c978a commit 5b0d462

2 files changed

Lines changed: 44 additions & 11 deletions

File tree

‎demos/index.html‎

Lines changed: 28 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,15 @@
44
<meta charset="UTF-8">
55
<meta name="viewport" content="width=device-width, initial-scale=1.0">
66
<title>Model Weight Protection and Agent Governance Demos | AgenTrust</title>
7-
<meta name="description" content="Ten runnable demos for securing AI model weights and governing agent tool and model calls. Run them on your laptop in about twelve minutes, no confidential-computing hardware required.">
7+
<meta name="description" content="Ten runnable demos for securing AI model weights and governing agent tool and model calls. Run them on your laptop in about thirteen minutes, no confidential-computing hardware required.">
88
<link rel="canonical" href="https://agentrust-io.com/demos/">
99
<meta name="robots" content="index, follow">
1010

1111
<!-- Open Graph -->
1212
<meta property="og:type" content="article">
1313
<meta property="og:site_name" content="AgenTrust">
1414
<meta property="og:title" content="Model Weight Protection and Agent Governance Demos">
15-
<meta property="og:description" content="Ten runnable demos for model-weight custody and governed agent tool and model calls. About twelve minutes on your laptop, no special hardware.">
15+
<meta property="og:description" content="Ten runnable demos for model-weight custody and governed agent tool and model calls. About thirteen minutes on your laptop, no special hardware.">
1616
<meta property="og:url" content="https://agentrust-io.com/demos/">
1717
<meta property="og:locale" content="en_US">
1818
<meta property="og:image" content="https://agentrust-io.com/og.png">
@@ -23,7 +23,7 @@
2323
<!-- Twitter -->
2424
<meta name="twitter:card" content="summary_large_image">
2525
<meta name="twitter:title" content="Model Weight Protection and Agent Governance Demos">
26-
<meta name="twitter:description" content="Model-weight custody plus governed agent tool and model calls. Ten runnable demos, about twelve minutes, no special hardware.">
26+
<meta name="twitter:description" content="Model-weight custody plus governed agent tool and model calls. Ten runnable demos, about thirteen minutes, no special hardware.">
2727
<meta name="twitter:image" content="https://agentrust-io.com/og.png">
2828

2929
<!-- Icons -->
@@ -49,7 +49,7 @@
4949
<div class="hero"><div class="wrap">
5050
<span class="eyebrow">Runnable demos</span>
5151
<h1>Don't take the spec<br>on trust. <em>Run it.</em></h1>
52-
<p class="sub">Ten demos, about twelve minutes end to end. Four cover custody of model weights. Five govern what an agent does at the tool boundary. One governs model calls through an OpenAI-compatible endpoint.</p>
52+
<p class="sub">Ten demos, about thirteen minutes end to end. Four cover custody of model weights. Five govern what an agent does at the tool boundary. One governs model calls through an OpenAI-compatible endpoint.</p>
5353
<div><span class="status">Software mode · <code>CMCP_DEV_MODE=1</code> · no special hardware</span></div>
5454
</div></div>
5555

@@ -63,11 +63,32 @@ <h2>Clone it and run all ten</h2>
6363
<div class="code-head"><span class="code-label">Terminal</span><button class="copy">COPY</button></div>
6464
<pre>git clone https://github.com/agentrust-io/demos &amp;&amp; cd demos
6565
pip install -r requirements.txt
66-
export CMCP_BEARER_TOKEN=demo-token
6766
python demo.py <span class="c"># all ten, pausing before each</span>
67+
python demo.py --no-pause <span class="c"># straight through, no prompts</span>
6868
python demo.py 6 <span class="c"># just demo 6</span></pre>
6969
</div>
70-
<p>The requirements install cMCP for demos 1 to 5, Weight Custody Manifest for demos 6 to 9, and the OpenAI client for demo 10. Source: <a href="https://github.com/agentrust-io/demos">github.com/agentrust-io/demos</a>.</p>
70+
<p>The requirements install cMCP for demos 1 to 5, Weight Custody Manifest for demos 6 to 9, and the OpenAI client for demo 10. <code>demo.py</code> sets dev mode and the bearer token for you, so there is nothing to export. Source: <a href="https://github.com/agentrust-io/demos">github.com/agentrust-io/demos</a>.</p>
71+
72+
<p class="meta" style="margin-top:2.25rem;">What demo 6 actually prints, verbatim from a run on <code>weight-custody-manifest 0.25.0</code></p>
73+
<div class="term">
74+
<div class="term-bar"><span class="dot"></span><span class="dot"></span><span class="dot"></span><span class="term-title">python demo-06-weight-custody/run.py</span></div>
75+
<div class="term-body">
76+
<div class="dim">Weight Custody Manifest: possession is not provenance.<br>Real WCM code with a software (mock) attestation provider, no hardware.</div>
77+
<div style="margin-top:0.9rem;">1. The builder signs a manifest binding the exact weight hash</div>
78+
<div class="dim">weights_hash bound : sha256:99b3e4e724d0aa75528b5b2214…</div>
79+
<div>manifest signature : <span class="ok">True</span> (jointly signed builder + custodian)</div>
80+
<div style="margin-top:0.9rem;">2. Attestation gate: the key releases only into the certified stack</div>
81+
<div>gate released key&nbsp;&nbsp;: <span class="ok">True</span></div>
82+
<div style="margin-top:0.9rem;">3. A tampered checkpoint fails before it ever loads</div>
83+
<div class="dim">certified hash&nbsp;&nbsp;&nbsp;&nbsp; : sha256:99b3e4e724d0aa75528b5b2214…<br>downloaded hash&nbsp;&nbsp;&nbsp;&nbsp;: sha256:b3a36b547da3babd1dc9f2b900…</div>
84+
<div>matches manifest&nbsp;&nbsp; : <span class="alert">False -&gt; REFUSE to load</span></div>
85+
<div class="dim">no human reads 2.8T parameters; the hash does the reading.</div>
86+
<div style="margin-top:0.9rem;">4. The fine-tune is the real IP: lineage back to the signed base</div>
87+
<div>lineage verified&nbsp;&nbsp; : <span class="ok">True</span>&nbsp; depth 1&nbsp; root is a base: <span class="ok">True</span></div>
88+
<div class="dim" style="margin-top:0.9rem;">honest scope&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : accountability-grade against an operator who physically<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; owns the silicon (see TEE.fail), not silicon-proof custody.</div>
89+
</div>
90+
</div>
91+
<p class="meta">Hashes are truncated here for width; the run prints them in full. Every demo ends with a scope statement like that last one.</p>
7192
</section>
7293

7394
<section id="weights">
@@ -133,7 +154,7 @@ <h2>Securing model weights</h2>
133154
<section id="governance">
134155
<span class="label">Agent governance</span>
135156
<h2>Governing what an agent does</h2>
136-
<p class="lead-serif">Demos 6 to 9 protect the weights. These five govern the tool boundary: what the agent is allowed to call, under which workflow, with what compliance attributes, and what evidence survives afterwards. Cedar policy is enforced on every call and each session closes with a signed TRACE claim.</p>
157+
<p class="lead-serif">Demos 6 to 9 protect the weights. These six put the policy at the boundary the agent has to cross: five at the tool call, and demo 10 at the model call. What is it allowed to invoke, under which workflow, with what compliance attributes, and what evidence survives afterwards. Cedar is enforced on every call and each session closes with a signed TRACE claim.</p>
137158

138159
<div class="stack">
139160
<div class="card static">

‎quickstart/index.html‎

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -135,6 +135,7 @@ <h2>The quickstart</h2>
135135

136136
<div class="callout">
137137
<p><strong>Before you start.</strong> Python 3.11+ · pip · macOS or Linux · two terminal windows · about ten minutes · no special hardware.</p>
138+
<p style="margin-top:0.6rem;">Every command and every output on this page was last run end to end against <code>cmcp-runtime 0.4.0</code> on 20 August 2026. If a step does not do what it says here, that is a bug and worth <a href="https://github.com/agentrust-io/cmcp/issues" target="_blank" rel="noopener">reporting</a>.</p>
138139
</div>
139140

140141
<div class="steps">
@@ -271,10 +272,17 @@ <h3>Fire a bad action, watch it get blocked</h3>
271272
}'</pre>
272273
</div>
273274
<p class="hint"><code>workflow_id</code> is the only field the runtime reads out of <code>_cmcp</code>. The session id is a label for your own logs: the runtime mints its own session id, which is why step 5 looks it up instead of assuming it.</p>
275+
<div class="term" style="margin-top:1.15rem;">
276+
<div class="term-bar"><span class="dot"></span><span class="dot"></span><span class="dot"></span><span class="term-title">what the runtime returns</span></div>
277+
<div class="term-body">
278+
<div class="dim">HTTP/1.1 <span class="alert">403 Forbidden</span><br>content-type: application/json</div>
279+
<div style="margin-top:0.7rem;">{"jsonrpc":"2.0","error":{"code":-32000,<br>&nbsp;&nbsp;"message":"Request denied by policy",<br>&nbsp;&nbsp;"data":{"error_code":<span class="alert">"POLICY_DENY"</span>,<br>&nbsp;&nbsp;&nbsp;&nbsp;"call_id":"51da9a46-149f-40c4-b83f-82d48fd654bd"}},"id":2}</div>
280+
</div>
281+
</div>
274282
<div class="verdict">
275-
<div class="flag"><span class="check">✓</span> What you'll see — 403 Forbidden</div>
276-
<p>Your policy stops a PII record from leaving on a tool call, <strong>before it reaches Salesforce</strong>, decided by the rule you wrote, enforced where the agent can't tamper with it. That's the barrier most teams can't cross today: shipping an agent you can actually <strong>prove</strong> is governed.</p>
277-
<p style="font-family:var(--at-mono);font-size:0.8rem;">HTTP/1.1 403 Forbidden · "message": "Request denied by policy" · "error_code": "POLICY_DENY"</p>
283+
<div class="flag"><span class="check">✓</span> What just happened</div>
284+
<p>Your policy stopped a PII record from leaving on a tool call, <strong>before it reached Salesforce</strong>, decided by the rule you wrote, enforced where the agent can't tamper with it. That's the barrier most teams can't cross today: shipping an agent you can actually <strong>prove</strong> is governed.</p>
285+
<p>Keep an eye on that <code>call_id</code>. The same id lands in the audit chain, so the deny you just watched is the deny you can hand to someone else in step 5. A refusal nobody can check afterwards is just a log line.</p>
278286
</div>
279287
</div>
280288
</div>
@@ -291,7 +299,11 @@ <h3>Walk away with proof</h3>
291299
curl -s -X POST "http://localhost:8443/sessions/$SID/close" | python3 -m json.tool &gt; claim.json
292300
cmcp verify claim.json</pre>
293301
</div>
294-
<p class="hint">Expected output in dev mode:</p>
302+
<p class="hint">Expected output in dev mode. The <code>CRYPTO-001</code> line comes first and is an advisory, not a failure: it is the CLI saying up front that a software-mode key binding proves nothing about hardware.</p>
303+
<div class="term" style="margin-bottom:1.15rem;">
304+
<div class="term-bar"><span class="dot"></span><span class="dot"></span><span class="dot"></span><span class="term-title">cmcp verify claim.json</span></div>
305+
<div class="term-body"><div class="dim">CRYPTO-001: software-only (dev) mode -- TEE key binding cannot be<br>verified; this claim provides no hardware provenance guarantee</div></div>
306+
</div>
295307
<div class="checks">
296308
<div class="chk"><span>schema</span><span class="pass">PASS ✓</span></div>
297309
<div class="chk"><span>signature</span><span class="pass">PASS ✓</span></div>

0 commit comments

Comments
 (0)