sigelo — portable identity for AI agents

Draft: the wire may change; the keeper is experimental, stagenet only; unaudited. Wire sigelo/0, packages 0.1.0, nothing published to a registry yet. SPEC.md: "Nothing is stable until v1.0"; VERSIONING.md: sigelo/0 freezes at tag v0.2 after 30 days with no wire change. See versioning.

Evidence

What has been run, with the numbers it printed. Every review and every test harness so far was written by Claude models; the cross-check below is the one place where the expected answers come from code sigelo's authors did not write. Nothing has been reviewed by anyone outside the project.

Suites, measured for this site

Run at c2c9cdc on 2026-10-01 (the test host, go1.27.1, node v24.18.1).

CommandResult
cd go && go test ./... -v498 PASS lines, exit 0
sigelo-verify --conformance ../test-vectors.json (monero vectors beside it)242 passed, 0 failed, ALL PASS
sigelo-verify --conformance test-vectors.json (the file alone, as released)188 passed, one SKIP monero section, ALL PASS
sigelo-verify --conformance test-vectors.json --impl ./sigelo-verify139 passed: positive 14/14, monero 9/9, negative 29/29, parity 87/87; 6 invoice vectors not scored
cd integrations/mcp && npm testALL PASS (50 checks)
cd adapters/moadim && npm test84 checks, ALL PASS

Recorded, not re-run for this site (the figures the repository's READMEs record at cad0357): ts/ 620 PASS lines with monero-wallet-rpc on PATH (608 and one SKIP without it); spend/ 659 passed with the funded stagenet wallet reachable, 626 passed and 2 skipped without it; release/pack-test.sh 16 checks on a built directory, 17 when it runs the build itself.

Release build

release/build.sh builds every artefact from a clean clone of HEAD. At c2c9cdc with go1.27.1, node v24.18.1 and npm 11.11.0 it wrote:

11f71314ab6d093cae209e7bdefb38e9ebf3bf32960dbf3e0d73434517028b2e  sigelo-0.1.0.tgz
6574249b8b271bbb18d12b831ae422413a988ece0305afef563c794d81e39f26  sigelo-agent-0.1.0.tgz
c0006cafc946dd7040db55dc71198ac3479dfe83a77dcfe248e8e62d57e8529f  sigelo-mcp-0.1.0.tgz
c73d4de82bc141893d21caea88c08384694be62737669d0e51e2f28f7c81624f  sigelo-spend-0.1.0.tgz
2e024f6afcd15609c8dd2012d5ba467c8dee032a7f66b81ef3a04b0be197e0e6  sigelo-verify-darwin-amd64
40498f95a62121bf8b18ec6e7303b3efab5e43abb6324ce0b3b381f2f29727d9  sigelo-verify-darwin-arm64
554f259dcfb75061701145e182b0b344d6167056c9bb4140a5053bfffcd0b31e  sigelo-verify-linux-amd64
c8edcb1f8be99f2dc554203145a97496dd91030494691513ef7c82afd5d0267f  sigelo-verify-linux-arm64
7104943beeb569ee8eed6e2c15ec03136d42b59d9098af61ea997d5140e34a5e  sigelo-verify-src-0.1.0.tar.gz
603e1cc6a282f51800c73cdd6a3e9aa8140d6c7a16067585fca331b2ca8d6659  sigelo-verify-windows-amd64.exe
5fe0405db81a841fbab2fff8b9622857988ba321895f9e4fa79354589fb6e3d1  test-vectors.json

build.sh is made so that the same commit and the same Go toolchain give byte-identical binaries (ROADMAP §1 R2 records SHA256SUMS identical across two builds); the npm tarballs also depend on the node, npm and TypeScript versions. With these tarballs in an empty directory, every command on adopt's agent path ran and sigelo-verify accepted the bundle (exit 0). Nothing has been published.

Simulations

Seeded and deterministic, so a digest names a run (repository sim/README.md):

SimulationWhatDigest
swarm.mjs, seed sigelo-swarm-1300 agents, 6 worlds, 40 rounds: joins, migrations, rotations, Monero bindings, thefts, forks, recoveries, tampered and fuzzed bundles; a sample re-verified by the Go verifier byte for bytee7500c102bd9cbad (6 and 3 workers alike)
worlds.mjs, seed sigelo-worlds-1dishonest worlds and the 1f916 adapter as a world: 36 case kinds, each with the SPEC section that decides itc51d1462e916bac8
keeper-scenarios.mjs, seed sigelo-keeper-scenarios78 scripted keeper steps: nested delegation, policy.json edited under a running keepere9622c852b72a605

Checks on the checkers: 13 bugs planted one at a time in a copy of ts/dist, each reported by the swarm or the worlds run; 7 planted in the keeper's delegation tree, each caught by the scenarios (the repository's sim/REPORT.md).

Cross-check against third-party code

2026-09-29, sigelo 4e1a5aa, seed 20260929: 0 divergences. Oracles: the RFC 8785 author's reference canonicalizers and testdata, monero-python 1.1.1, libsodium through PyNaCl 1.6.2, the RFC 8032 text, Wycheproof (151 Ed25519 vectors), ed25519-speccheck (12 cases). Among the runs: 20 000 random JCS documents and 100 008 integers equal in ts and go; 1 800 forbidden inputs rejected by both; 10 000 Monero base58 encodes, 5 000 seed-derived wallets and 2 500 subaddresses equal; 500 libsodium signatures byte-identical and 800 malleated ones rejected. The three monero-python disagreements are its own departures from Monero's C++. Not covered: Monero message signatures (SigV2), for lack of a third-party oracle; the wallet-rpc oracle in spend/ checks those. Source: the repository's crosscheck/README.md.

Docs-only comprehension

A model gets only a task prompt and a frozen snapshot of the docs, and a program grades what it produces. One run per cell, Claude models only, so a datapoint, not a distribution. The table, copied from the repository's docs-test/RESULTS.md:

DateRoundTaskModelResultDocs atLed to
2026-09-171lifecycle from docs onlySonnet8/10before 38e9c7638e9c76
2026-09-171lifecycle from docs onlyHaiku6.5/10before 38e9c7638e9c76
2026-09-171bthe same, after QUICKSTART fixes and examples/world.mjsHaiku7/1038e9c76its two remaining asks folded into QUICKSTART in f1aba94
2026-09-172a verifier from SPEC aloneOpus34/34 vectors, first iteration; 12 spec findingsbefore f1aba94spec round 2, f1aba94
2026-09-23keeperthe MONERO.md §4.2 snippet only, sigelo-wallet on stagenetHaikuaccepted (below)fdaba3f..393b7b4recorded in MONERO.md §8
2026-09-293lifecycle from docs onlySonnet10/10 (artifacts b9278416cb18388d…, transcript 9c8c12e479fb9952…, no forbidden reads)9dadab0 (snapshot ff3639074728bd09…)—
2026-09-293lifecycle from docs onlyHaiku7/10 (artifacts e27afc796896aebd…, transcript 01ec4245607ad494…; FAIL binding discarded — cross-signed correctly but dated now + 3600, so §9 step 6 drops it; FAIL stolen iat earlier than recovery — it spaced every iat like a story and wrote "recovery must be AFTER the stolen one"; FAIL invariants: that binding discarded in both bundles)9dadab0R3 bar (≥ 9/10 Haiku) not met. Root cause for both: the docs stated "iat is the signing time" and "recovery beats iat" only as permissions in SPEC, with no bind() line and no worked case in QUICKSTART → a795275 (QUICKSTART: the exact ed25519-test bind({… addr_secret, iat: now}), a Timestamps paragraph, recovery-beats-iat worked at T and T+3600; ts/README API notes). Re-measure at the next round
2026-09-293a verifier from SPEC + vectors alone, Python (1 033 lines; PyNaCl, pycryptodome, Edwards arithmetic by hand)Opus139/139 on grade-verifier.mjs and 139/139 on sigelo-verify --conformance --impl, first iteration; 0 spec findings (it asked whether an object-form parity case with __proto__ grades as a reject — it does, by the grader's text interface, grade-verifier.mjs:152)9dadab0 (verifier snapshot 469da8a3c59fe898…)Perl (the second foreign language on the host) impossible: no Ed25519 library, no compiler. Non-Claude models: still no API keys
2026-10-01siteadopt sigelo from the website alone (site/test/TASK-site.md: the served site + the release files, nothing else)Haiku6/6 in 97 s (install from tarballs, SHA256SUMS checked, tier-2 recovery key, attested by the served mock world, bundle accepted by the release sigelo-verify-linux-arm64; transcript 48392b8c8c560116…, no forbidden reads; pages read: /, /adopt, /quickstart, /spec, /examples/world.mjs)site at 4bf622b (tree c2c9cdc release)the candidate ran the world from a subdirectory, so site/test/collect.sh now finds the world state anywhere under the workspace
2026-10-013blifecycle from docs only, after a795275 (QUICKSTART: the exact ed25519-test bind() call, a Timestamps paragraph, recovery-beats-iat worked)Haiku10/10 (artifacts b2d1dff2922602fb…, transcript ccd508f60726b629…, no forbidden reads; 24 min)9516622 (snapshot docs-test/snapshot/9516622)R3 bar met at Haiku tier (≥ 9/10) with Claude models; non-Claude families still unmeasured (API keys)

The bar for v0.2 is at least 9/10 at Haiku tier across model families; it is not met. Non-Claude families have not run.

Keeper soak (stagenet)

Scripted agents against a real keeper and wallet on stagenet, started 2026-09-23 (41076a6), planned for at least 14 days; ROADMAP §1 R4 records day 6 on 2026-09-29. Four incidents are written up in the repository's spend/soak/README.md (a stale lock after a reboot, a torn log tail pre-empted, a near-miss redeploy, 32 hours offline). The incident rehearsal (T14) has no recorded result at this commit.