You're pledging to donate if the project hits its minimum goal and gets approved. If not, your funds will be returned.
AI agents are provided with credentials / tokens / api keys designed for user accounts or applications, even when they only need permission for one task. Moreover the same credentials are passed on to a subagent instance without any scoped or narrowed permissions for a subtask. This is a catastrophic problem, when an agent assumes permissions which are not consented but the credential has access to.
AGNAP is an open protocol extending GNAP for AI Agents, GNAP an IETF standard https://datatracker.ietf.org/group/gnap/documents/ , It enables providing agents limited authority or scoped permissions without handing them the credentials at all. A grant answers "which agent may perform which operation, under what constraints, and what it may delegate". In this architecture I propose a separate private vault used to store the credentials. The agent never gets access to the credentials in the vault, rather only the result of an operation it intended for after its authorization.
This project will test and validate the approach on how it prevents unauthorized actions, how it compares with simpler alternatives, and what it costs in complexity and performance. The specifications, implementation, benchmark, tests, and findings will all be published openly.
The main question I want to answer is simple: can we limit what an AI agent can actually cause to happen, even when the agent itself behaves badly?
Over ten weeks, I will turn the existing AGNAP openapi specifications into core packages, client adapters and create a pluggable harness plugin in frameworks e.g. deepseek, perform testing and evaluation, publish results and a whitepaper.
The project is seeking $50,000 for six months:
$30,000 for engineering and protocol development
$10,000 for protocol and security review from individuals via grants
$5,000 for client integration grants
$5,000 for compute purchase and infrastructure
$2,000 for documentation, standards engagement
This funding would be used to cover operational expenses for research and development through community support via grant's, bug bounty programs etc.
I am currently building AGNAP myself, you can find my socials Linkedin: https://www.linkedin.com/in/daev-mithran-30b314158/ and GitHub: https://github.com/DaevMithran . My background includes Decentralized Identity, Open payments and Applied Cryptography. Relevant work includes Golang Engineer at Interledger Foundation, where I worked with the GNAP spec to implement card payment authorization.
I expertise in protocols and standards development. With over 6 years in the decentralized identity ecosystem contributing to Openwallet foundation Eudi wallet protocols. I recently contributed to Openclaw and understood the security issues in agent runtimes escpecially in the authorization layer.
I've won global hackathons such as ETH Global Bangkok, Hackmos Dubai participating solo. I expect to remain the primary implementer during this phase while bringing in crucial reviews and client integration via grant programmes.
The biggest risk is that AGNAP becomes sucessful but too complicated for agent developers to adopt.
Security bugs could also make the system appear safer than it really is.
AGNAP will remain a specification or prototype without meaningful deployment.
AGNAP has not received any external funding during the last 12 months. This is at a very early stage and I've been working on it for the past two months. I have applied to MATS Research, ERA Fellowship, OpenAI cybersecurity grants, but no funding has been awarded yet.
There are no bids on this project.