Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
acp-framework-en — Agent Control Protocol (ACP) — Official English specification. Cryptographically verifiable authorization architecture for autonomous AI agents. | Kitploit
ツール/GitHubGitHub/chelof100/acp-framework-en
Authentication & AuthorizationCryptographyCloud SecurityIdentity & Access Management (IAM)Supply Chain SecurityPapers & ResearchLearning & EducationAI Security
GitHubchelof100/acp-framework-en

acp-framework-en

Agent Control Protocol (ACP) — Official English specification. Cryptographically verifiable authorization architecture for autonomous AI agents.

2501ヶ月前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
リポジトリを見る
要求された言語のコンテンツは利用できません。英語版を表示しています。

ACP — Agent Control Protocol

Admission control for agent actions.

Before any agent mutates system state, ACP answers four questions: Who is this agent? What are they authorized to do? Is this action policy-compliant? Can the outcome be traced to an accountable institution?

Cryptographic identity · Scoped capability tokens · Verifiable delegation chains · Execution proof

Official Website

https://agentcontrolprotocol.xyz

Paper

Agent Control Protocol: Admission Control for Agent Actions Marcelo Fernandez (TraslaIA), 2026

DOI: 10.5281/zenodo.19672575  ·  arXiv: 2603.18829


Research Series

ACP is the published foundation of a ten-paper series on formal agent governance. Each paper addresses a distinct layer of the governance stack.

PaperTitleRepoStatus
Paper 0Atomic Decision Boundariesdecision-boundary-modelZenodo · arXiv:2604.17511
Paper 1Agent Control Protocol (ACP) — this repoacp-framework-enZenodo · arXiv:2603.18829
Paper 2From Admission to Invariants (IML)iml-benchmarkZenodo · arXiv:2604.17517
Paper 3/4Irreducible Governance Structuregovernance-structureZenodo · arXiv: on appeal
Paper 5Reconstructive Authority Model (RAM)reconstructive-authority-modelZenodo · arXiv:2604.22898
Paper 6Operationalizing Reconstructive Authorityoperationalizing-ramZenodo · arXiv:2605.23935
Paper 7Closing the Execution Gap (Empirical)agent-governance-appliedZenodo · arXiv: on appeal
Paper 8Identity-Bound Governance (APB)identity-bound-governanceZenodo · arXiv: on appeal
Paper 9MCP-Native Governancemcp-governed-agentsZenodo · arXiv: pending
Paper 10Non-Blocking Governancenon-blocking-governanceZenodo · arXiv: pending

Series logic: Paper 0 proves when admissibility can be guaranteed → Paper 1 (ACP) builds the protocol → Paper 2 detects drift invisible to enforcement → Paper 3/4 proves correct enforcement ≠ fair allocation and establishes the irreducibility of the four-layer architecture → Paper 5 (RAM) provides operational closure: when to execute under partial observability → Paper 6 operationalizes RAM as a runtime Recovery Loop → Paper 7 provides the first empirical validation of the full stack on real LangGraph agents → Paper 8 establishes identity-bound accountability for halted agents (Phase II: governance of governance) → Paper 9 deploys that governance transparently at the MCP protocol layer → Paper 10 makes it non-blocking via escrow-based asynchronous human oversight.


Why ACP Exists

Autonomous agents are moving from experimentation into production. They already interact with APIs, enterprise systems, financial infrastructure, and other agents.

When one acts across organizations, several questions immediately arise:

  • Who authorized the agent to act?
  • What capabilities does the agent actually have?
  • What policy allowed the action?
  • What exactly was executed?
  • Can that execution be verified later?
  • Can the full interaction history be reconstructed?

Today, most systems cannot answer these questions reliably.

ACP introduces the infrastructure to answer all of them.


ACP vs Related Protocols

Several initiatives address how autonomous agents interact with systems. Most focus on tool access or communication. ACP focuses on authority, execution verification, and institutional accountability.

ProtocolFocusScope boundary
MCP (Model Context Protocol)Tool access for LLMsAuthority verification, policy enforcement, execution auditability
A2A (Agent-to-Agent)Agent communication patternsInstitutional trust, governance, accountability chain
OpenAI Agents SDKTool orchestrationCross-organization authority, provenance, liability
Agent Client Protocol ¹Runtime client/agent integrationGovernance, delegation chains, verifiable execution history
ACP (Agent Control Protocol)Governance & accountability infrastructure—

ACP addresses a different layer: who authorized the action, under what policy, and who is accountable for the outcome.

ACP vs Policy & Auth Systems

Engineers evaluating ACP often ask: "why not use OPA?" These systems are complementary, not competitive.

SystemWhat it doesWhat ACP adds
OPA (Open Policy Agent)Evaluates policies from data and rulesCryptographic agent identity + delegation chain + execution proof
AWS IAM / Azure RBACStatic permission model for cloud resourcesDynamic agent-to-agent delegation with verifiable chain + ledger
OAuth 2.0 + OIDCUser and service authorization via tokensMulti-hop agent delegation with non-escalation + institutional liability
SPIFFE / SPIRECryptographic workload identityACP builds on workload identity to add capability scoping + governance
ACPAdmission control for agent actions—

OPA can be used as the policy evaluation engine inside an ACP-compliant system. ACP does not replace OPA — it adds the agent identity layer, delegation chain, and execution proof that OPA does not provide.


¹ ACP (Agent Control Protocol) is unrelated to other initiatives sharing the same acronym.


ACP as Admission Control

Kubernetes uses an Admission Controller to intercept API requests before they reach the cluster — evaluating policies, enforcing quotas, rejecting non-compliant operations. ACP applies the same pattern to agent actions.

agent intent
    ↓
[1] Identity check       →  pkg/agent + pkg/hp       (ACP-AGENT-1.0, ACP-HP-1.0)
    ↓
[2] Capability check     →  pkg/ct + pkg/dcma         (ACP-CT-1.0, ACP-DCMA-1.0)
    ↓
[3] Policy check         →  pkg/risk + pkg/psn        (ACP-RISK-3.0, ACP-PSN-1.0)
    ↓
[4] ADMIT / DENY / ESCALATE
    ↓  (if ADMIT)
[5] Execution token      →  pkg/exec                  (ACP-EXEC-1.0)
    ↓
[6] Ledger record        →  pkg/ledger                (ACP-LEDGER-1.3)
    ↓
system state mutation

The difference from Kubernetes: ACP operates across institutional boundaries. An agent from Bank A can be admitted by Bank B without Bank B trusting Bank A's internal infrastructure — only the cryptographic proof matters.


How ACP Works

ACP treats agent interactions as governed operations, not simple requests.

Every interaction passes through six structured stages:

ツールをダウンロード