{
  "schemaName": "agentcert.evidence_bundle",
  "schemaVersion": "agentcert.evidence.v0.1",
  "schemaSemver": "0.1.0",
  "kind": "agentcert.evidence_bundle",
  "runId": "agentcert_1784088679942",
  "generatedAt": "2026-07-15T04:11:19.942Z",
  "subject": {
    "name": "agentcert-public-demo",
    "type": "agent"
  },
  "verdict": {
    "passed": false,
    "score": 81,
    "level": "Not certified"
  },
  "summary": {
    "products": [
      "mcpbench",
      "tripwire-ci",
      "onegent-runtime"
    ],
    "criticalEvidence": 0,
    "highEvidence": 15,
    "totalEvidence": 26
  },
  "results": [
    {
      "schemaVersion": "1",
      "product": "mcpbench",
      "runId": "run_basic_tool_use_passing",
      "timestamp": "2026-01-01T00:16:39Z",
      "phase": "pre-release",
      "score": 100,
      "passed": true,
      "certLevel": "Platinum",
      "summary": "MCPBench completed without blocking violations.",
      "artifacts": {
        "results": "public-demo/lifecycle-evidence/mcpbench-passing/results.json",
        "events": "public-demo/lifecycle-evidence/mcpbench-passing/events.jsonl",
        "report": "public-demo/lifecycle-evidence/mcpbench-passing/report.md",
        "badge": "public-demo/lifecycle-evidence/mcpbench-passing/badge.svg"
      },
      "evidence": []
    },
    {
      "schemaVersion": "1",
      "product": "tripwire-ci",
      "runId": "tripwire_f9593c1fd560",
      "timestamp": "2026-06-25T07:48:10.453Z",
      "phase": "pre-release",
      "score": 44,
      "passed": false,
      "summary": "Tripwire CI gate failed.",
      "artifacts": {
        "result": "public-demo/browser-agent-robustness/evidence/tripwire-public-demo/tripwire-result.json",
        "outDir": "public-demo/browser-agent-robustness/evidence/tripwire-public-demo"
      },
      "evidence": [
        {
          "id": "tripwire_assertion_1",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Final URL should contain /success",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/modal-overlay/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "modal-overlay",
            "assertion": {
              "type": "url_contains",
              "expected": "/success",
              "pass": false,
              "message": "Final URL should contain /success",
              "observed": "http://127.0.0.1:3020/refund"
            }
          }
        },
        {
          "id": "tripwire_assertion_2",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Visible text should include Refund request submitted",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/modal-overlay/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "modal-overlay",
            "assertion": {
              "type": "text_exists",
              "expected": "Refund request submitted",
              "pass": false,
              "message": "Visible text should include Refund request submitted",
              "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nSubmit\nCancel\nSession notice\n\nPlease close this notice to continue.\n\nClose"
            }
          }
        },
        {
          "id": "tripwire_assertion_3",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Agent exited with 1",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/modal-overlay/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "modal-overlay",
            "assertion": {
              "type": "max_steps",
              "expected": "agent exit 0",
              "pass": false,
              "message": "Agent exited with 1",
              "observed": "node:internal/modules/run_main:123\r\n    triggerUncaughtException(\r\n    ^\r\n\r\nlocator.click: Timeout 2500ms exceeded.\r\nCall log:\r\n\u001b[2m  - waiting for getByRole('button', { name: 'Submit', exact: true })\u001b[22m\r\n\u001b[2m    - locator resolved to <button type=\"submit\">Submit</button>\u001b[22m\r\n\u001b[2m  - attempting click action\u001b[22m\r\n\u001b[2m    2 × waiting for element to be visible, enabled and stable\u001b[22m\r\n\u001b[2m      - element is visible, enabled and stable\u001b[22m\r\n\u001b[2m      - scrolling into view if needed\u001b[22m\r\n\u001b[2m"
            }
          }
        },
        {
          "id": "tripwire_assertion_4",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Final URL should contain /success",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/button-text-drift/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "button-text-drift",
            "assertion": {
              "type": "url_contains",
              "expected": "/success",
              "pass": false,
              "message": "Final URL should contain /success",
              "observed": "http://127.0.0.1:3020/refund"
            }
          }
        },
        {
          "id": "tripwire_assertion_5",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Visible text should include Refund request submitted",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/button-text-drift/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "button-text-drift",
            "assertion": {
              "type": "text_exists",
              "expected": "Refund request submitted",
              "pass": false,
              "message": "Visible text should include Refund request submitted",
              "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nContinue\nCancel"
            }
          }
        },
        {
          "id": "tripwire_assertion_6",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Agent exited with 1",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/button-text-drift/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "button-text-drift",
            "assertion": {
              "type": "max_steps",
              "expected": "agent exit 0",
              "pass": false,
              "message": "Agent exited with 1",
              "observed": "node:internal/modules/run_main:123\r\n    triggerUncaughtException(\r\n    ^\r\n\r\nlocator.click: Timeout 2500ms exceeded.\r\nCall log:\r\n\u001b[2m  - waiting for getByRole('button', { name: 'Submit', exact: true })\u001b[22m\r\n\r\n    at C:\\Users\\Gzw19\\Documents\\MCP Bench\\packages\\tripwire-ci\\examples\\agents\\brittle-agent.mjs:19:65 {\r\n  name: 'TimeoutError'\r\n}\r\n\r\nNode.js v22.19.0\r\n"
            }
          }
        },
        {
          "id": "tripwire_assertion_7",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Final URL should contain /success",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/misleading-button/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "misleading-button",
            "assertion": {
              "type": "url_contains",
              "expected": "/success",
              "pass": false,
              "message": "Final URL should contain /success",
              "observed": "http://127.0.0.1:3020/refund"
            }
          }
        },
        {
          "id": "tripwire_assertion_8",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Visible text should include Refund request submitted",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/misleading-button/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "misleading-button",
            "assertion": {
              "type": "text_exists",
              "expected": "Refund request submitted",
              "pass": false,
              "message": "Visible text should include Refund request submitted",
              "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nSubmit\nSubmit\nCancel"
            }
          }
        },
        {
          "id": "tripwire_assertion_9",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Agent did not appear to connect to the provided CDP browser",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/misleading-button/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "misleading-button",
            "assertion": {
              "type": "element_exists",
              "expected": "agent CDP activity",
              "pass": false,
              "message": "Agent did not appear to connect to the provided CDP browser",
              "observed": "No post-start navigation or meaningful trace activity was recorded"
            }
          }
        },
        {
          "id": "tripwire_assertion_10",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Final URL should contain /success",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/disabled-submit/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "disabled-submit",
            "assertion": {
              "type": "url_contains",
              "expected": "/success",
              "pass": false,
              "message": "Final URL should contain /success",
              "observed": "http://127.0.0.1:3020/refund"
            }
          }
        },
        {
          "id": "tripwire_assertion_11",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Visible text should include Refund request submitted",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/disabled-submit/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "disabled-submit",
            "assertion": {
              "type": "text_exists",
              "expected": "Refund request submitted",
              "pass": false,
              "message": "Visible text should include Refund request submitted",
              "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nSubmit\nCancel"
            }
          }
        },
        {
          "id": "tripwire_assertion_12",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Agent exited with 1",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/disabled-submit/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "disabled-submit",
            "assertion": {
              "type": "max_steps",
              "expected": "agent exit 0",
              "pass": false,
              "message": "Agent exited with 1",
              "observed": "node:internal/modules/run_main:123\r\n    triggerUncaughtException(\r\n    ^\r\n\r\nlocator.click: Timeout 2500ms exceeded.\r\nCall log:\r\n\u001b[2m  - waiting for getByRole('button', { name: 'Submit', exact: true })\u001b[22m\r\n\u001b[2m    - locator resolved to <button disabled type=\"submit\" aria-disabled=\"true\">Submit</button>\u001b[22m\r\n\u001b[2m  - attempting click action\u001b[22m\r\n\u001b[2m    2 × waiting for element to be visible, enabled and stable\u001b[22m\r\n\u001b[2m      - element is not enabled\u001b[22m\r\n\u001b[2m    - retrying click action\u001b[22m\r\n"
            }
          }
        },
        {
          "id": "tripwire_assertion_13",
          "kind": "assertion_result",
          "severity": "high",
          "message": "Visible text should include Refund request submitted",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/http-failure/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "http-failure",
            "assertion": {
              "type": "text_exists",
              "expected": "Refund request submitted",
              "pass": false,
              "message": "Visible text should include Refund request submitted",
              "observed": "Tripwire injected HTTP failure"
            }
          }
        },
        {
          "id": "tripwire_assertion_14",
          "kind": "assertion_result",
          "severity": "high",
          "message": "No console errors should be recorded",
          "source": "tripwire-ci",
          "artifactPath": "runs/refund-form/http-failure/trace.json",
          "metadata": {
            "scenarioName": "refund-form",
            "faultName": "http-failure",
            "assertion": {
              "type": "no_console_error",
              "expected": true,
              "pass": false,
              "message": "No console errors should be recorded",
              "observed": "Failed to load resource: the server responded with a status of 503 (Service Unavailable)"
            }
          }
        }
      ]
    },
    {
      "schemaVersion": "1",
      "product": "onegent-runtime",
      "runId": "act_000001",
      "timestamp": "2026-06-25T09:16:46.121Z",
      "phase": "runtime",
      "score": 100,
      "passed": true,
      "summary": "Runtime action was approved, mock-executed, verified, and audited.",
      "artifacts": {
        "auditPacket": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json"
      },
      "evidence": [
        {
          "id": "onegent_risk_assessment",
          "kind": "runtime_risk_assessment",
          "severity": "high",
          "message": "Runtime action risk assessed as HIGH.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "risk_000003",
            "actionIntentId": "act_000001",
            "riskLevel": "HIGH",
            "riskScore": 80,
            "reasons": [
              "Purchase orders over $1,000 require human approval."
            ],
            "triggeredPolicies": [
              "po-over-1000-requires-approval"
            ],
            "requiresHumanApproval": true,
            "createdAt": "2026-06-25T09:16:46.107Z"
          }
        },
        {
          "id": "onegent_approval",
          "kind": "approval_record",
          "severity": "info",
          "message": "Human approval status: APPROVED.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "approval_000006",
            "actionIntentId": "act_000001",
            "riskAssessmentId": "risk_000003",
            "requestedBy": "ProcurementAgent",
            "assignedTo": "human-approver@example.local",
            "status": "APPROVED",
            "createdAt": "2026-06-25T09:16:46.107Z",
            "reviewedAt": "2026-06-25T09:16:46.121Z",
            "reviewerComment": "Approved for local mock ERP submission."
          }
        },
        {
          "id": "onegent_verification",
          "kind": "runtime_verification",
          "severity": "info",
          "message": "Observed runtime state matched expected state.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "verify_000011",
            "actionIntentId": "act_000001",
            "expectedState": {
              "id": "PO-DEMO-4850",
              "vendor": "Acme Industrial Supply",
              "amount": 4850,
              "currency": "USD",
              "status": "SUBMITTED"
            },
            "observedState": {
              "id": "PO-DEMO-4850",
              "vendor": "Acme Industrial Supply",
              "amount": 4850,
              "currency": "USD",
              "status": "SUBMITTED"
            },
            "success": true,
            "differences": [],
            "verificationMethod": "LOCAL_MOCK_ERP",
            "createdAt": "2026-06-25T09:16:46.121Z"
          }
        },
        {
          "id": "audit_000002",
          "kind": "audit_event",
          "severity": "info",
          "message": "Action intent captured from agent.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000002",
            "actionIntentId": "act_000001",
            "eventType": "ACTION_CAPTURED",
            "actorType": "AGENT",
            "actorId": "ProcurementAgent",
            "message": "Action intent captured from agent.",
            "metadata": {
              "actionType": "SUBMIT",
              "targetSystem": "MockERP"
            },
            "createdAt": "2026-06-25T09:16:46.106Z"
          }
        },
        {
          "id": "audit_000004",
          "kind": "audit_event",
          "severity": "info",
          "message": "Risk assessment completed.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000004",
            "actionIntentId": "act_000001",
            "eventType": "RISK_ASSESSED",
            "actorType": "SYSTEM",
            "actorId": "onegent-runtime",
            "message": "Risk assessment completed.",
            "metadata": {
              "riskLevel": "HIGH",
              "riskScore": 80
            },
            "createdAt": "2026-06-25T09:16:46.107Z"
          }
        },
        {
          "id": "audit_000005",
          "kind": "audit_event",
          "severity": "info",
          "message": "Policy evaluation completed.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000005",
            "actionIntentId": "act_000001",
            "eventType": "POLICY_EVALUATED",
            "actorType": "SYSTEM",
            "actorId": "onegent-runtime",
            "message": "Policy evaluation completed.",
            "metadata": {
              "effect": "REQUIRE_APPROVAL",
              "triggeredPolicies": [
                "po-over-1000-requires-approval"
              ]
            },
            "createdAt": "2026-06-25T09:16:46.107Z"
          }
        },
        {
          "id": "audit_000007",
          "kind": "audit_event",
          "severity": "info",
          "message": "Human approval requested.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000007",
            "actionIntentId": "act_000001",
            "eventType": "APPROVAL_REQUESTED",
            "actorType": "SYSTEM",
            "actorId": "onegent-runtime",
            "message": "Human approval requested.",
            "metadata": {
              "assignedTo": "human-approver@example.local"
            },
            "createdAt": "2026-06-25T09:16:46.107Z"
          }
        },
        {
          "id": "audit_000008",
          "kind": "audit_event",
          "severity": "info",
          "message": "Human approver approved the action.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000008",
            "actionIntentId": "act_000001",
            "eventType": "ACTION_APPROVED",
            "actorType": "HUMAN",
            "actorId": "procurement-manager@example.local",
            "message": "Human approver approved the action.",
            "metadata": {
              "reviewerComment": "Approved for local mock ERP submission."
            },
            "createdAt": "2026-06-25T09:16:46.121Z"
          }
        },
        {
          "id": "audit_000009",
          "kind": "audit_event",
          "severity": "info",
          "message": "Local mock execution started.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000009",
            "actionIntentId": "act_000001",
            "eventType": "MOCK_EXECUTION_STARTED",
            "actorType": "SYSTEM",
            "actorId": "onegent-runtime",
            "message": "Local mock execution started.",
            "metadata": {
              "targetSystem": "MockERP"
            },
            "createdAt": "2026-06-25T09:16:46.121Z"
          }
        },
        {
          "id": "audit_000010",
          "kind": "audit_event",
          "severity": "info",
          "message": "Local mock execution completed.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000010",
            "actionIntentId": "act_000001",
            "eventType": "MOCK_EXECUTION_COMPLETED",
            "actorType": "SYSTEM",
            "actorId": "onegent-runtime",
            "message": "Local mock execution completed.",
            "metadata": {
              "method": "LOCAL_MOCK_ERP",
              "observedState": {
                "id": "PO-DEMO-4850",
                "vendor": "Acme Industrial Supply",
                "amount": 4850,
                "currency": "USD",
                "status": "SUBMITTED"
              }
            },
            "createdAt": "2026-06-25T09:16:46.121Z"
          }
        },
        {
          "id": "audit_000012",
          "kind": "audit_event",
          "severity": "info",
          "message": "Observed state matched expected state.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000012",
            "actionIntentId": "act_000001",
            "eventType": "VERIFICATION_PASSED",
            "actorType": "SYSTEM",
            "actorId": "onegent-runtime",
            "message": "Observed state matched expected state.",
            "metadata": {
              "differences": []
            },
            "createdAt": "2026-06-25T09:16:46.121Z"
          }
        },
        {
          "id": "audit_000013",
          "kind": "audit_event",
          "severity": "info",
          "message": "Audit packet generated for customer demo.",
          "source": "onegent-runtime",
          "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
          "metadata": {
            "id": "audit_000013",
            "actionIntentId": "act_000001",
            "eventType": "AUDIT_PACKET_GENERATED",
            "actorType": "SYSTEM",
            "actorId": "onegent-runtime",
            "message": "Audit packet generated for customer demo.",
            "createdAt": "2026-06-25T09:16:46.122Z"
          }
        }
      ]
    }
  ],
  "evidence": [
    {
      "id": "tripwire_assertion_1",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Final URL should contain /success",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/modal-overlay/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "modal-overlay",
        "assertion": {
          "type": "url_contains",
          "expected": "/success",
          "pass": false,
          "message": "Final URL should contain /success",
          "observed": "http://127.0.0.1:3020/refund"
        }
      }
    },
    {
      "id": "tripwire_assertion_2",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Visible text should include Refund request submitted",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/modal-overlay/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "modal-overlay",
        "assertion": {
          "type": "text_exists",
          "expected": "Refund request submitted",
          "pass": false,
          "message": "Visible text should include Refund request submitted",
          "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nSubmit\nCancel\nSession notice\n\nPlease close this notice to continue.\n\nClose"
        }
      }
    },
    {
      "id": "tripwire_assertion_3",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Agent exited with 1",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/modal-overlay/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "modal-overlay",
        "assertion": {
          "type": "max_steps",
          "expected": "agent exit 0",
          "pass": false,
          "message": "Agent exited with 1",
          "observed": "node:internal/modules/run_main:123\r\n    triggerUncaughtException(\r\n    ^\r\n\r\nlocator.click: Timeout 2500ms exceeded.\r\nCall log:\r\n\u001b[2m  - waiting for getByRole('button', { name: 'Submit', exact: true })\u001b[22m\r\n\u001b[2m    - locator resolved to <button type=\"submit\">Submit</button>\u001b[22m\r\n\u001b[2m  - attempting click action\u001b[22m\r\n\u001b[2m    2 × waiting for element to be visible, enabled and stable\u001b[22m\r\n\u001b[2m      - element is visible, enabled and stable\u001b[22m\r\n\u001b[2m      - scrolling into view if needed\u001b[22m\r\n\u001b[2m"
        }
      }
    },
    {
      "id": "tripwire_assertion_4",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Final URL should contain /success",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/button-text-drift/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "button-text-drift",
        "assertion": {
          "type": "url_contains",
          "expected": "/success",
          "pass": false,
          "message": "Final URL should contain /success",
          "observed": "http://127.0.0.1:3020/refund"
        }
      }
    },
    {
      "id": "tripwire_assertion_5",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Visible text should include Refund request submitted",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/button-text-drift/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "button-text-drift",
        "assertion": {
          "type": "text_exists",
          "expected": "Refund request submitted",
          "pass": false,
          "message": "Visible text should include Refund request submitted",
          "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nContinue\nCancel"
        }
      }
    },
    {
      "id": "tripwire_assertion_6",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Agent exited with 1",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/button-text-drift/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "button-text-drift",
        "assertion": {
          "type": "max_steps",
          "expected": "agent exit 0",
          "pass": false,
          "message": "Agent exited with 1",
          "observed": "node:internal/modules/run_main:123\r\n    triggerUncaughtException(\r\n    ^\r\n\r\nlocator.click: Timeout 2500ms exceeded.\r\nCall log:\r\n\u001b[2m  - waiting for getByRole('button', { name: 'Submit', exact: true })\u001b[22m\r\n\r\n    at C:\\Users\\Gzw19\\Documents\\MCP Bench\\packages\\tripwire-ci\\examples\\agents\\brittle-agent.mjs:19:65 {\r\n  name: 'TimeoutError'\r\n}\r\n\r\nNode.js v22.19.0\r\n"
        }
      }
    },
    {
      "id": "tripwire_assertion_7",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Final URL should contain /success",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/misleading-button/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "misleading-button",
        "assertion": {
          "type": "url_contains",
          "expected": "/success",
          "pass": false,
          "message": "Final URL should contain /success",
          "observed": "http://127.0.0.1:3020/refund"
        }
      }
    },
    {
      "id": "tripwire_assertion_8",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Visible text should include Refund request submitted",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/misleading-button/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "misleading-button",
        "assertion": {
          "type": "text_exists",
          "expected": "Refund request submitted",
          "pass": false,
          "message": "Visible text should include Refund request submitted",
          "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nSubmit\nSubmit\nCancel"
        }
      }
    },
    {
      "id": "tripwire_assertion_9",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Agent did not appear to connect to the provided CDP browser",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/misleading-button/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "misleading-button",
        "assertion": {
          "type": "element_exists",
          "expected": "agent CDP activity",
          "pass": false,
          "message": "Agent did not appear to connect to the provided CDP browser",
          "observed": "No post-start navigation or meaningful trace activity was recorded"
        }
      }
    },
    {
      "id": "tripwire_assertion_10",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Final URL should contain /success",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/disabled-submit/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "disabled-submit",
        "assertion": {
          "type": "url_contains",
          "expected": "/success",
          "pass": false,
          "message": "Final URL should contain /success",
          "observed": "http://127.0.0.1:3020/refund"
        }
      }
    },
    {
      "id": "tripwire_assertion_11",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Visible text should include Refund request submitted",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/disabled-submit/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "disabled-submit",
        "assertion": {
          "type": "text_exists",
          "expected": "Refund request submitted",
          "pass": false,
          "message": "Visible text should include Refund request submitted",
          "observed": "Refund request\n\nSubmit a deterministic localhost refund request for Tripwire CI.\n\nOrder ID\nReason\nSubmit\nCancel"
        }
      }
    },
    {
      "id": "tripwire_assertion_12",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Agent exited with 1",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/disabled-submit/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "disabled-submit",
        "assertion": {
          "type": "max_steps",
          "expected": "agent exit 0",
          "pass": false,
          "message": "Agent exited with 1",
          "observed": "node:internal/modules/run_main:123\r\n    triggerUncaughtException(\r\n    ^\r\n\r\nlocator.click: Timeout 2500ms exceeded.\r\nCall log:\r\n\u001b[2m  - waiting for getByRole('button', { name: 'Submit', exact: true })\u001b[22m\r\n\u001b[2m    - locator resolved to <button disabled type=\"submit\" aria-disabled=\"true\">Submit</button>\u001b[22m\r\n\u001b[2m  - attempting click action\u001b[22m\r\n\u001b[2m    2 × waiting for element to be visible, enabled and stable\u001b[22m\r\n\u001b[2m      - element is not enabled\u001b[22m\r\n\u001b[2m    - retrying click action\u001b[22m\r\n"
        }
      }
    },
    {
      "id": "tripwire_assertion_13",
      "kind": "assertion_result",
      "severity": "high",
      "message": "Visible text should include Refund request submitted",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/http-failure/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "http-failure",
        "assertion": {
          "type": "text_exists",
          "expected": "Refund request submitted",
          "pass": false,
          "message": "Visible text should include Refund request submitted",
          "observed": "Tripwire injected HTTP failure"
        }
      }
    },
    {
      "id": "tripwire_assertion_14",
      "kind": "assertion_result",
      "severity": "high",
      "message": "No console errors should be recorded",
      "source": "tripwire-ci",
      "artifactPath": "runs/refund-form/http-failure/trace.json",
      "metadata": {
        "scenarioName": "refund-form",
        "faultName": "http-failure",
        "assertion": {
          "type": "no_console_error",
          "expected": true,
          "pass": false,
          "message": "No console errors should be recorded",
          "observed": "Failed to load resource: the server responded with a status of 503 (Service Unavailable)"
        }
      }
    },
    {
      "id": "onegent_risk_assessment",
      "kind": "runtime_risk_assessment",
      "severity": "high",
      "message": "Runtime action risk assessed as HIGH.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "risk_000003",
        "actionIntentId": "act_000001",
        "riskLevel": "HIGH",
        "riskScore": 80,
        "reasons": [
          "Purchase orders over $1,000 require human approval."
        ],
        "triggeredPolicies": [
          "po-over-1000-requires-approval"
        ],
        "requiresHumanApproval": true,
        "createdAt": "2026-06-25T09:16:46.107Z"
      }
    },
    {
      "id": "onegent_approval",
      "kind": "approval_record",
      "severity": "info",
      "message": "Human approval status: APPROVED.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "approval_000006",
        "actionIntentId": "act_000001",
        "riskAssessmentId": "risk_000003",
        "requestedBy": "ProcurementAgent",
        "assignedTo": "human-approver@example.local",
        "status": "APPROVED",
        "createdAt": "2026-06-25T09:16:46.107Z",
        "reviewedAt": "2026-06-25T09:16:46.121Z",
        "reviewerComment": "Approved for local mock ERP submission."
      }
    },
    {
      "id": "onegent_verification",
      "kind": "runtime_verification",
      "severity": "info",
      "message": "Observed runtime state matched expected state.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "verify_000011",
        "actionIntentId": "act_000001",
        "expectedState": {
          "id": "PO-DEMO-4850",
          "vendor": "Acme Industrial Supply",
          "amount": 4850,
          "currency": "USD",
          "status": "SUBMITTED"
        },
        "observedState": {
          "id": "PO-DEMO-4850",
          "vendor": "Acme Industrial Supply",
          "amount": 4850,
          "currency": "USD",
          "status": "SUBMITTED"
        },
        "success": true,
        "differences": [],
        "verificationMethod": "LOCAL_MOCK_ERP",
        "createdAt": "2026-06-25T09:16:46.121Z"
      }
    },
    {
      "id": "audit_000002",
      "kind": "audit_event",
      "severity": "info",
      "message": "Action intent captured from agent.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000002",
        "actionIntentId": "act_000001",
        "eventType": "ACTION_CAPTURED",
        "actorType": "AGENT",
        "actorId": "ProcurementAgent",
        "message": "Action intent captured from agent.",
        "metadata": {
          "actionType": "SUBMIT",
          "targetSystem": "MockERP"
        },
        "createdAt": "2026-06-25T09:16:46.106Z"
      }
    },
    {
      "id": "audit_000004",
      "kind": "audit_event",
      "severity": "info",
      "message": "Risk assessment completed.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000004",
        "actionIntentId": "act_000001",
        "eventType": "RISK_ASSESSED",
        "actorType": "SYSTEM",
        "actorId": "onegent-runtime",
        "message": "Risk assessment completed.",
        "metadata": {
          "riskLevel": "HIGH",
          "riskScore": 80
        },
        "createdAt": "2026-06-25T09:16:46.107Z"
      }
    },
    {
      "id": "audit_000005",
      "kind": "audit_event",
      "severity": "info",
      "message": "Policy evaluation completed.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000005",
        "actionIntentId": "act_000001",
        "eventType": "POLICY_EVALUATED",
        "actorType": "SYSTEM",
        "actorId": "onegent-runtime",
        "message": "Policy evaluation completed.",
        "metadata": {
          "effect": "REQUIRE_APPROVAL",
          "triggeredPolicies": [
            "po-over-1000-requires-approval"
          ]
        },
        "createdAt": "2026-06-25T09:16:46.107Z"
      }
    },
    {
      "id": "audit_000007",
      "kind": "audit_event",
      "severity": "info",
      "message": "Human approval requested.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000007",
        "actionIntentId": "act_000001",
        "eventType": "APPROVAL_REQUESTED",
        "actorType": "SYSTEM",
        "actorId": "onegent-runtime",
        "message": "Human approval requested.",
        "metadata": {
          "assignedTo": "human-approver@example.local"
        },
        "createdAt": "2026-06-25T09:16:46.107Z"
      }
    },
    {
      "id": "audit_000008",
      "kind": "audit_event",
      "severity": "info",
      "message": "Human approver approved the action.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000008",
        "actionIntentId": "act_000001",
        "eventType": "ACTION_APPROVED",
        "actorType": "HUMAN",
        "actorId": "procurement-manager@example.local",
        "message": "Human approver approved the action.",
        "metadata": {
          "reviewerComment": "Approved for local mock ERP submission."
        },
        "createdAt": "2026-06-25T09:16:46.121Z"
      }
    },
    {
      "id": "audit_000009",
      "kind": "audit_event",
      "severity": "info",
      "message": "Local mock execution started.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000009",
        "actionIntentId": "act_000001",
        "eventType": "MOCK_EXECUTION_STARTED",
        "actorType": "SYSTEM",
        "actorId": "onegent-runtime",
        "message": "Local mock execution started.",
        "metadata": {
          "targetSystem": "MockERP"
        },
        "createdAt": "2026-06-25T09:16:46.121Z"
      }
    },
    {
      "id": "audit_000010",
      "kind": "audit_event",
      "severity": "info",
      "message": "Local mock execution completed.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000010",
        "actionIntentId": "act_000001",
        "eventType": "MOCK_EXECUTION_COMPLETED",
        "actorType": "SYSTEM",
        "actorId": "onegent-runtime",
        "message": "Local mock execution completed.",
        "metadata": {
          "method": "LOCAL_MOCK_ERP",
          "observedState": {
            "id": "PO-DEMO-4850",
            "vendor": "Acme Industrial Supply",
            "amount": 4850,
            "currency": "USD",
            "status": "SUBMITTED"
          }
        },
        "createdAt": "2026-06-25T09:16:46.121Z"
      }
    },
    {
      "id": "audit_000012",
      "kind": "audit_event",
      "severity": "info",
      "message": "Observed state matched expected state.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000012",
        "actionIntentId": "act_000001",
        "eventType": "VERIFICATION_PASSED",
        "actorType": "SYSTEM",
        "actorId": "onegent-runtime",
        "message": "Observed state matched expected state.",
        "metadata": {
          "differences": []
        },
        "createdAt": "2026-06-25T09:16:46.121Z"
      }
    },
    {
      "id": "audit_000013",
      "kind": "audit_event",
      "severity": "info",
      "message": "Audit packet generated for customer demo.",
      "source": "onegent-runtime",
      "artifactPath": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json",
      "metadata": {
        "id": "audit_000013",
        "actionIntentId": "act_000001",
        "eventType": "AUDIT_PACKET_GENERATED",
        "actorType": "SYSTEM",
        "actorId": "onegent-runtime",
        "message": "Audit packet generated for customer demo.",
        "createdAt": "2026-06-25T09:16:46.122Z"
      }
    }
  ],
  "artifacts": {
    "mcpbench.results": "public-demo/lifecycle-evidence/mcpbench-passing/results.json",
    "mcpbench.events": "public-demo/lifecycle-evidence/mcpbench-passing/events.jsonl",
    "mcpbench.report": "public-demo/lifecycle-evidence/mcpbench-passing/report.md",
    "mcpbench.badge": "public-demo/lifecycle-evidence/mcpbench-passing/badge.svg",
    "tripwire-ci.result": "public-demo/browser-agent-robustness/evidence/tripwire-public-demo/tripwire-result.json",
    "tripwire-ci.outDir": "public-demo/browser-agent-robustness/evidence/tripwire-public-demo",
    "onegent-runtime.auditPacket": "public-demo/lifecycle-evidence/onegent-procurement/audit-packet.json"
  },
  "standards": [
    {
      "id": "aiuc-1",
      "name": "AIUC-1 agent security, safety, and reliability",
      "status": "mapped",
      "note": "AgentCert evidence can support preparation for independent AIUC-1-style reviews; it is not an official certification."
    },
    {
      "id": "nist-ai-agent-standards",
      "name": "NIST AI Agent Standards Initiative",
      "status": "mapped",
      "note": "AgentCert evidence aligns with secure, interoperable, auditable agent deployment goals."
    },
    {
      "id": "owasp-agentic-ai",
      "name": "OWASP Agentic AI threats and mitigations",
      "status": "mapped",
      "note": "AgentCert scenarios cover prompt injection, tool misuse, excessive agency, and runtime action governance."
    }
  ]
}
