I tried to build a personal AI system ("LifeOS") for my family and hit a wall.
I realized: If an external AI Agent tries to connect to my data, I have zero way to verify it.
*Who owns it?
*Is the code safe?
*Who pays if it deletes my data?
So I built a protocol to fix it. ๐งต๐
@AISafetyMemes@Vouch_Protocol Signed identity for every agent. Scope checks that live outside the prompt. Trust that expires unless it's renewed.
The agents basically wrote our spec for us. https://t.co/MdimQs4E2T
@AISafetyMemes@Vouch_Protocol They invented the need for agent identity on their own, mid-incident, because they couldn't function without it.
Here's the kicker: that infrastructure already exists.
Ref: @Vouch_Protocol
@tobi That is why I have started building @Vouch_Protocol that cryptographically signs Agents intent & ensures right Identity, Accountability & Reputation is carried. It is replay attack-safe.
It is open-source & bridges a critical security gap. Your views plz
https://t.co/P1qOqaTxrj
@tobi Eg. User tells a shopping agent to "Buy the red shoes".
What if a malicious actor tries to "replay token" to buy "Blue Shoes" (or change the shipping address), or if the agent hallucinates & tries to execute a different action?
We have security built for access not for intent..
@buildwithankur@tobi ...transmits securely, cryptographically so that even a single digit change in the agent action denies execution.
I am building @Vouch_Protocol to do exactly that. It's open source, lightweight, uses the best of security standards.
Any thoughts?
https://t.co/P1qOqaTxrj
@buildwithankur@tobi Spot on, Ankur!
What if the AI Agent buys red shoes instead of blue? Ships to a different address? Who is accountable?
UCP standardizes message format. But what is the message here morphed?
We need a protocol that'll bind the user's intent to the agent's action & transmits...
@JustenEcom@tobi@Vouch_Protocol ...makes AI Agents accountable & provides their reputation to users, to know if it is safe to use them.
Interested to get your views on it. Thank you
https://t.co/P1qOqaTxrj
@JustenEcom@tobi ...binds intent to the agent action cryptographically so that only that action gets executed. Even a single digit change in the intent will stop its action!
I am building @Vouch_Protocol to do exactly that. It's light weight, uses the best of the security standards & makes AI..
@AgenticReadyHQ@tobi The rails carry the message in standardized format. But doesn't safeguard is from that message not getting executed the way we want it to.
I am building @Vouch_Protocol to solve this. It's open source. Light weight. Uses best of the security standards.
https://t.co/P1qOqaTxrj
@AgenticReadyHQ@tobi True, this standardizes rails. But what if the AI Agent goes rogue (hallucinates) or a man-in-the-middle attack makes agent take a rogue action? Eg. Buys blue shoes instead of red. Ships to a different address?
We need a protocol that binds intent to action, cryptographically...
@ItsSun @tobi@lulumeservey ...binds intent to the agent action & sends it cryptographically signed. So that, any change in the intent doesn't let the action take place.
I am building this as an open source protocol & can be utilised for secure Agentic workflows...
https://t.co/P1qOqaTxrj
@ItsSun @tobi@lulumeservey It is indeed an https moment for shopping but it isn't sufficient. Https secured connection but we need to bind the agent intent too.
What if the AI agent buys blue shoes instead of red? Ships to a different address? Who is it to be blamed?
We need a protocol that binds...
We are building this in the open because security standards shouldn't be siloed.
Help us make 'verified builds' the industry default. Check out the architecture, workflow, test it, break it and tell us how we can make it better, together.
Shipping code is easy. Verifying exactly who wrote it at scale (without losing your mind over GPG keys) is hard.
Today we shipped the Vouch Git Workflow.
Itโs identity-backed commit signing that actually fits into modern development flows.
Verified commits just leveled up. โก๏ธ
Introducing the Vouch Git Workflow.
Itโs time to move beyond painful GPG key management. Vouch brings verifiable, identity-backed code attestation directly to your terminal. Secure your software supply chain at the source.
contd...
@sundarpichai@Vouch_Protocol@Vouch_Protocol solves this AI Identity, Accountability & Reputation problem. It binds agent intent through cryptographic key to ensure execution of only the authorised action.
It's open source & in decent shape: https://t.co/P1qOqaTxrj
Worth checking?
@sundarpichai@Vouch_Protocol User tells a shopping agent to "Buy the red shoes".
What if a malicious actor tries to "replay token" to buy "Blue Shoes" (or change the shipping address), or if the agent hallucinates and tries to execute a different action?
@Vouch_Protocol solves this AI Identity and ...contd