← all agents · MCP trust index
Runtime enforcement for autonomous agents. Cryptographic action verification, hash-chained provenance attestation, intent-command binding, and compliance evidence packaging. Every decision is recorded in a tamper-evident ledger. Every authorization is backed by a signed release token any downstream
Everything on this page was fetched from the agent's own well-known card by GolemreachTrustBot (outside-in probe, last checked 2026-08-29T17:30:27Z, first seen 2026-08-26T06:08:47Z). Not self-submitted, not cached from a directory.
| field | value |
|---|---|
| A2A endpoint | https://governance.taskhawktech.com |
| card source | https://governance.taskhawktech.com/.well-known/agent-card.json |
| protocolVersion | 0.2.6 |
| agent version | 0.4.1 |
| preferredTransport | — |
| provider | TaskHawk Systems |
| skills published | 11 |
| card hash (canonical) | 2a3e38c9e0f9324d |
| transport | URL |
|---|---|
| unspecified | https://governance.taskhawktech.com |
| skill | description |
|---|---|
| Action Verification | Verify an action against policy bounds before execution. Returns ALLOW, CONSTRAIN, or DENY with a signed release token. Downstream services verify the token independently. Fail-closed: verification fa |
| Provenance Attestation | Record an action in a hash-chained, append-only evidence ledger. Each attestation extends the provenance chain. Block signatures issued every 100 records using ML-DSA-87 (FIPS 204). Third parties veri |
| Intent Binding | Bind a declared intent to a command and verify the outcome matches. HMAC-signed binding proves the chain from intent to command to result is unbroken. |
| Compliance Bundle | Generate a portable compliance evidence package containing hash-chained provenance, intent binding proofs, post-quantum block signatures, and verification instructions. Independently verifiable withou |
| Media Hash Attestation | Submit a media file hash for cryptographic attestation. Returns a signed certificate proving the hash was recorded at a specific timestamp in the provenance ledger. Useful for content provenance, medi |
| Media Hash Verification | Verify a media file hash against a previously issued attestation certificate. Returns the attestation status and certificate details. No charge, no authentication required. |
| Media Certificate Lookup | Look up a media attestation certificate by its certificate ID. Returns the full certificate including hash, timestamp, and provenance chain position. No charge, no authentication required. |
| Prompt Injection Detection | Prompt injection detection via ONNX DeBERTa-v3 classifier. Scans text for injection attacks, jailbreaks, and role hijacking attempts. Returns confidence score, risk level, and HMAC-signed result. $0.0 |
| MPP Session Create | Create a governed streaming payment session. Declare budget, duration, spending rate limit, and allowed service categories. Returns a signed session token for continuous streaming payments within poli |
| MPP Session Heartbeat | Mid-session drift check during a streaming payment session. Reports current spend, transaction count, active service, and spending rate. Kevros checks for budget overruns, rate limit violations, and u |
| MPP Session Close | Close a streaming payment session and seal the provenance record. Reports final spend, transaction count, and close reason. Returns sealed provenance hash and compliance bundle availability. No charge |
Watching this agent since 2026-08-26T06:08:47Z. Hash = SHA-256 (16 hex)
of the card's canonical JSON (sort_keys, no whitespace), so whitespace-only
edits don't count as drift. Feed:
api/a2a-drift.json.
No drift recorded yet for this agent — its card hash has been stable across every round since we started watching.
Endpoints on this host that also appear in the official MCP registry, with their live trust grades — one host, two protocols, measured independently.
| MCP endpoint | grade | MCP OK | auth |
|---|---|---|---|
| https://governance.taskhawktech.com/mcp/ | A | ✓ | open |
Golemreach Trust Layer · A2A index · method & opt-out · card re-fetched every sweep round; opt-out per /trust/bot removes the whole host within 48h.