← Funded evaluations
Acme Gate
Evaluation pack · prepared by Agentic Thinking Ltd · sample
Acme Gate 2.4.0 · commit 3f9c2a1 · full evaluation · 2026.10
Plate I · Six links, and which ones hold SAMPLE · FICTIONAL PRODUCT
THE CLAIM what Acme Gate says its record proves POLICYDECISIONholds AUTHORIS-ATIONholds EXECUTIONfails OBSERV-ATIONpartial DURABLEEVIDENCEpartial INDEPENDENTVERIFICATIONfails THE RUN 40 actions by a live coding agent, counted at each link 40 decided 40 authorised 34 ran6 "completed"but never ran 31 observed3 networkeffects missed 40 writtenunkeyed digest forgery passed 1 of 1 forgedbundles accepted 1 2 3 4 BAR WIDTH full width = 40 actions · each link measured on the same scale established partial fails
Scroll the plate sideways →
Findings
1F1 · Phantom completion6 actions reported "completed" by the default sandbox, with no side effect
2F2 · Blind spotobserver watches files, not network; 3 outbound calls unrecorded
3F3 · Unkeyed digestplain SHA-256 over the bundle; anyone can recompute it
4F4 · Forgery acceptedverify-bundle passed a re-hashed, altered bundle

FIG. 1  Sample data for a fictional product. In a real pack, every count on this plate comes from the capture kit and links to its evidence file. Here the numbers are invented to show the format; they are internally consistent so the pack can be read as a worked example.

Acme Gate

Evaluation Pack

An independent full evaluation of a fictional agent governance gateway at a fixed commit: what its record proves, link by link, tested against a live coding agent and four negative controls. This is a sample of the pack we deliver for a funded evaluation.

Scope Verdicts Findings Controls Remediation Reproduce
Executive summary

Acme Gate's record can be trusted for what it decided: every action was decided and authorised correctly, and replayed or expired authorisations were refused. It cannot yet be trusted for what happened: 6 of 40 actions were recorded as completed but never ran, network activity is not observed, and a forged evidence bundle passed the product's own verification.

Until F1 and F4 are fixed, an auditor or insurer should not rely on Acme Gate's evidence bundles as proof of what an agent did.

  1. Fix first: sign evidence bundles (F3, F4) and stop reporting unexecuted actions as completed (F1).
  2. Then: observe network side effects (F2).
  3. Re-test: all four findings can be re-checked at a new commit with the same capture kit (section 5).
0

Scope and terms

One product, one commit, one isolated environment. What we tested is fixed before we start.

ItemValue
ProductAcme Gate 2.4.0 (fictional), an agent governance gateway
Commit · tree3f9c2a1 · tree b71e0d4, fresh checkout
PackageFull evaluation: re-test scope plus live-agent run, evidence integrity review, protocol coverage
Environmentcontainers with no network access; build dependencies pre-fetched and pinned
Runs2 full runs; the second reproduced every verdict
Termsfixed scope and fee agreed up front; the fee does not depend on the result; findings published unedited; not an endorsement
Declared interest

We maintain the open-source HookBus project and the AgentHook standard. We sell no agent-governance product. AgenticBench is separate and takes no funding from the agents it tests.

1

Verdicts

Two links hold, two are partial, two fail. The record is reliable about decisions and unreliable about outcomes.

2 / 6
links established
2 / 6
links partial
2 / 6
links fail
LinkVerdictBasisFinding
Policy decisionestablished40 of 40 actions decided; deny and allow both observednone
Authorisationestablishedexpired and replayed authorisations rejected (controls C2, C3)none
Executionfails6 of 40 reported "completed" with no side effectF1
Observationpartial31 of 34 real side effects observed; network calls missedF2
Durable evidencepartialevery action written; digest is unkeyedF3
Independent verificationfailsa forged bundle passed verify-bundleF4
2

Findings

Each finding names the claim, the test, what happened, and the file that proves it.

F1"Completed" for actions that never ranopen · high
Claim
An allowed action is executed and its completion is recorded.
Test
A live coding agent ran 40 tool calls through the gateway using the default CLI configuration. We compared the gateway's completion records with the filesystem and process table after each call.
Result
6 calls (4 file writes, 2 shell commands) were recorded as completed. The target files were unchanged and no process ran. The default sandbox returns success without executing.
Evidence
evidence/F1/completions.jsonl, evidence/F1/fs-diff.txt, run 1 and run 2
Fix to re-test
Fail closed when no executor is configured, or record not_executed instead of completed.
F2Network side effects are not observedopen · medium
Claim
The observer records every side effect of an executed action.
Test
Of the 34 actions that really ran, 3 made outbound HTTP requests to a local sink. We compared the sink's log with the observer's records.
Result
File and process effects were observed (31 of 31). None of the 3 network effects appeared in the record.
Evidence
evidence/F2/sink.log, evidence/F2/observations.jsonl
Fig. 2.1  F4, the forgery that passedsequence · sample
GENUINE BUNDLE EVALUATOR VERIFY-BUNDLE EXIT CODE copy; set action 17 to "allow" recompute sha256 over body verify-bundle forged.json "verified: true" 0 no key, no signature: the digest proves the bundle is self-consistent, not who wrote it
Sample sequence. In a real pack this figure is drawn from the captured commands, with the forged and genuine bundles attached as evidence files.
F3The evidence digest is unkeyedopen · medium
Claim
Evidence bundles are tamper-evident.
Test
Read the digest construction in the source and in a bundle.
Result
evidence_digest is a plain SHA-256 over the bundle body, with no key or signature. It detects accidental change, not deliberate change.
Evidence
evidence/F3/digest-source.txt
F4A forged bundle passes verificationopen · high
Claim
An independent party can verify a bundle with verify-bundle.
Test
Fig. 2.1: alter one decision, recompute the digest, verify.
Result
verified: true, exit code 0. Follows directly from F3.
Evidence
evidence/F4/forged.json, evidence/F4/verify.out
Fix to re-test
Sign bundles with a key the verifier is given separately; fail verification without it.
3

Negative controls

Four deliberate faults. A control that is not caught is reported as a finding, not hidden.

ControlFault injectedExpectedResult
C1tampered bundle, digest left staleverification failscaught
C2stale authorisation replayed after a policy changedenycaught
C3direct call to the executor, bypassing the gatewayflagged as unauthorisedcaught
C4tampered bundle, digest recomputedverification failsmissed · F4
4

What this evaluation is not

Not an endorsement. A link marked established held under these tests, at this commit. It says nothing about other versions or configurations.

Not a security audit. We test whether the record matches reality. We did not test the gateway's own attack surface beyond the four controls.

Not exhaustive. One live agent, 40 actions, two runs. A pattern that needs more actions or other agents to appear may be missed.

5

Remediation and re-test

What to fix, in what order, and exactly what the re-test will check.

PriorityFindingFixRe-test passes when
1F3, F4sign bundles with a key supplied to the verifier separatelycontrol C4 is caught; a re-hashed bundle fails verify-bundle with a non-zero exit
2F1fail closed with no executor, or record not_executed0 of 40 actions recorded as completed without a side effect
3F2observe outbound network calls3 of 3 sink requests appear in the record

A re-test uses the same capture kit and controls at the new commit, and reports each finding as closed, partially closed or open.

R.1

Reproduce

Every verdict can be re-run from the pack. Sample commands shown.

# fixed commit, no network
git clone https://example.invalid/acme-gate && git -C acme-gate checkout 3f9c2a1
./capture/run.sh --network none --runs 2          # writes evidence/
./capture/verify.sh evidence/                     # re-derives every verdict above
# F4
./capture/forge.sh evidence/bundle-0.json > forged.json && acme-gate verify-bundle forged.json; echo "exit $?"
# → verified: true · exit 0
R.2

Evidence index

Every file a verdict rests on, with its digest, so nothing can be swapped after delivery.

FileSupportssha256 (first 16)
evidence/F1/completions.jsonlF19c1e04a7b2d35f80
evidence/F1/fs-diff.txtF141f7d0c3e98a6b12
evidence/F2/sink.logF2b83a5e2f0c147d96
evidence/F2/observations.jsonlF22de90b6a71c4f835
evidence/F3/digest-source.txtF3e6047c9d3a1b58f2
evidence/F4/forged.json, verify.outF4, C47fa2c81e05d96b3c
evidence/controls/C1-C4.jsonlC1 to C4c58b3f9e24a0d671
Prepared byAgentic Thinking Ltd, Company No. 17152930
PackageFull evaluation, fixed fee, result-independent
Pack digestsha256:3b9e…71c2
Signeded25519:AT-EVAL-2026 · 8f4c…d1a0

Sample values. In a delivered pack, the digests and signature are real and can be checked with the Agentic Thinking evaluation key supplied with the pack.