Repository navigation
Verifiable receipts for AstrBot agents? #10366
Replies: 3 comments 1 reply
|
Thanks for disclosing that you maintain INAM — that's appreciated. I spent some time looking at both INAM and how AstrBot actually works, so here's a concrete answer rather than a generic one. The real trust boundary in AstrBotMost AstrBot users don't have a runtime execution verification problem — they have a "is this plugin safe to install" problem:
That means a signed Execution Receipt emitted by the same plugin is self-attestation: it proves the plugin signed something, not that the work was independently done correctly. INAM's own spec acknowledges this — the value of a Verification comes from an independent verifier, and INAM explicitly does not run that verification itself. For a receipt to carry real weight here, you'd need a genuinely separate party, and today there isn't one. Semantic mismatch with AstrBot's task model
So mapping "a plugin calls an external service" onto INAM only becomes meaningful if that external service is itself an INAM agent that can serve as the other party. Without that counterparty, you get the shape of a receipt without the substance. Lowest-friction integration pathIf someone does want INAM in AstrBot, the honest path is MCP, not a custom plugin:
Treat INAM as an optional capability a user opts into per agent, never as something in AstrBot's core. Before investing in this integrationI think the more useful question is how many AstrBot users actually transact with external agents under INAM-like terms. Most deployments are self-hosted and single-user, where a portable public reputation score has little to anchor to. In that setting, a local, signed, exportable, replayable audit log of what an agent did — built from existing hooks like Two practical notes
Net: technically feasible as an optional plugin or MCP integration, semantically thin today because the counterparty and independent verifier are missing, and probably better framed as an audit mechanism than as a reputation layer for this community. |
|
Cảm ơn bạn đã chia sẻ chi tiết về INAM và cách nó có thể (hoặc không) hòa nhập với AstrBot. Mình đồng ý rằng ranh giới tin cậy chính trong AstrBot hiện tại là ở mức “cài đặt plugin”. Khi một plugin được tải và chạy, người dùng đã quyết định tin tưởng nó, vì vậy một receipt ký bởi cùng plugin thực chất chỉ là tự chứng thực chứ không mang lại xác thực độc lập. Nếu muốn một lớp xác thực thực sự, mình thấy cách tích hợp qua MCP là hợp lý hơn so với việc viết plugin riêng. MCP đã hỗ trợ giao tiếp với inam‑mcp và cung cấp các công cụ kiểm tra uy tín, ký receipt mà không cần tái triển khai toàn bộ quy trình ký hai bên. Điều này giúp người dùng bật/tắt tính năng này một cách linh hoạt và giữ cho core của AstrBot sạch sẽ. Trong thực tiễn, mình cũng gặp trường hợp cần audit log chi tiết cho các tác vụ tự động. Thay vì dựa vào public registry, mình đã dùng hook Cuối cùng, mình muốn hỏi thêm: cộng đồng có nhu cầu thực sự về việc giao dịch giữa các agent độc lập không? Nếu nhu cầu này tăng, việc xây dựng một verifier độc lập sẽ trở nên cần thiết, còn hiện tại có lẽ tập trung vào audit log nội bộ sẽ đáp ứng được phần lớn nhu cầu của người dùng. |
|
For the external-agent case, has an AstrBot user run into a dispute over whether another service completed a task, separate from plugin installation concerns? If so, what evidence of completion would have changed what they did next? |
Uh oh!
There was an error while loading. Please reload this page.
Hi AstrBot community, I maintain INAM Protocol, so disclosing that. AstrBot is described as an agentic assistant; I'm curious about plugins that call other agents or services. One idea: a plugin emitting a signed Execution Receipt for each completed task, so results can be verified independently. Do your users face trust or verification issues with plugins or external agents today?
All reactions