The commitments, boundaries, and operational transparency data required to trust Mago's agent behavioral attestation.
We welcome responsible vulnerability disclosure. By submitting reports through our official channels, security researchers are protected by our Safe Harbor policy.
Mago establishes cryptographically verifiable identity and behavior attestation for agent skills. It does not guarantee a skill is free of bugs, nor does it override an agent's host OS sandboxing.
Access the raw cryptographic materials required to verify Mago's infrastructure state independently.
| Resource | Status / Link |
|---|---|
| Trust-root Metadata (v1) | trust-root.json |
| Transparency Log Checkpoints | rekor.magofoundation.dev |
| Verifier CLI Release Signatures | cosign.pub |
| Revocation Lookups (CRL) | crl.magofoundation.dev |
Mago operates under open-source governance. All components are licensed under the MIT License unless stated otherwise.
We welcome red-team submissions to test our Agent Behavioral Checksums. Please review our AUP prior to submitting adversarial payloads to the public registry.
Prior to collecting external submissions for evaluation, Mago adheres to strict evidence-handling guidelines to protect researcher data and avoid cross-contamination.
Evidence Collection: Telemetry is strictly opt-in. Submitted skill traces are scrubbed of PII locally before uploading.
Retention & Deletion: Evaluation traces are stored for 90 days. Raw execution dumps are deleted immediately post-validation.
Processing Location: All infrastructure runs in EU-central zones with restricted access controls.
Privacy Contact: privacy@magofoundation.dev