An open map for verifiable agent infrastructure: 1,300 LF project records, 30 source reviews, zero claimed integrations

Community Article
Published September 25, 2026

A directory is a starting point, not an integration. We published a dated, machine-readable map of public Linux Foundation project records so agent builders can move from “this component exists” to “this component’s effect was independently reproduced.”

As of 25 September 2026, the official LF projects directory yielded 1,300 visible active project records. We individually read and pinned public sources for 30. The remaining 1,270 are directory or preflight records, not audits. Three of the 30 supplied bounded anonymous public API or data readbacks. Open Policy Agent passed four synthetic policy tests in an isolated lab. No project has qualified as a CSOAI production integration, and this index does not imply a Linux Foundation partnership or endorsement.

What the map is for

The open dataset groups candidates across scoped authority, policy, bounded execution, provenance, measurement, and software supply-chain evidence. Its records preserve exact source revisions, source hashes, evidence level, and reuse caveats. The audited subset includes OPA, OpenFGA, SPIFFE, in-toto, sigstore, OpenTelemetry, MCP, SLSA, TUF, OpenSSF Scorecard and others. A project name in the map is a research pointer, not a quality verdict.

We want one repeatable admission path for any component:

source and rights review → positive and negative fixture → independent replay → measured effect → signed evidence → change watch.

That path matters because a successful API response proves less than people often think. A documentation readback does not show runtime behavior. A synthetic test does not show production containment. A timestamp does not prove the source is true. A payment challenge does not prove a buyer received an accepted result.

What can be independently checked today

The released graph is 1,150,012 bytes with SHA-256 52f49733862107f41e4a05fc0d6814c63a5b559ddeb4a6c9b5076345572a24ac. The dataset includes the graph, original and upgraded OpenTimestamps sidecars, and a Bitcoin-header-path readback to blocks 968537 and 968555. The public release was read back anonymously, file by file, against its hash manifest. That establishes an exact-byte publication and existence-time trail. It is not a production signature, an audit of all 1,300 records, or GSPC admission.

The Council MCP endpoint, GSPC board, and x402 catalog expose live entry points. Discovery and commercial offers remain separate from the component tests described here.

If you maintain one of these projects, or know a better public source, point to one immutable source revision, one public endpoint if available, and one concrete positive and negative behavior to test. Corrections and failed reproductions are useful results too. The index will only call something an integration after its effect survives the measured admission path.

A runnable policy example

The four-case OPA read-only lab is a public reproducibility packet, with a pinned OPA binary, Rego policy, frozen inputs, decision/effect receipts, a four-row JSONL case index, and an offline byte verifier. In its recorded synthetic run, a reviewer decision permitted one public GSPC GET; guest, changed-scope, and revoked cases blocked the effect. The separately replayed OPA decisions and matching response bytes narrow what can be checked. They do not establish a real identity or grant source, independent GSPC admission, a qualified production integration, or a buyer. The LF integration count remains zero.

Community

Sign up or log in to comment