{"_id":"@clawbureau/clawsig-conformance","_rev":"2-df4eaaab145d4bb75e1e1bb80246eb99","name":"@clawbureau/clawsig-conformance","dist-tags":{"latest":"0.2.1"},"versions":{"0.2.0":{"name":"@clawbureau/clawsig-conformance","version":"0.2.0","keywords":["clawsig","conformance","proof-bundle","agent-verification","github-action","clawsig-inside"],"license":"MIT","_id":"@clawbureau/clawsig-conformance@0.2.0","maintainers":[{"name":"gwelinder","email":"npm@clawbureau.com"}],"homepage":"https://clawsig.com/directory","bugs":{"url":"https://github.com/clawbureau/clawbureau/issues"},"dist":{"shasum":"4f68e6568986714791b89dc32fd8aba8d53dfee3","tarball":"https://registry.npmjs.org/@clawbureau/clawsig-conformance/-/clawsig-conformance-0.2.0.tgz","fileCount":23,"integrity":"sha512-oVZqbvLPqZgwK+J4KbJwM4lyqcwckZ1xFwFrL55vEGhivPJhrmLw7DRJs8Kwj6xMD27sWIfxxKRUbP0Uj7Brvg==","signatures":[{"sig":"MEYCIQCfEddWpt+gIKY5SDoCU9+JH0v6LMxnsDmaQvIC9j3NnQIhALDZzuo+keELcVcvJCQ7K600WHjAteDvsiaQXJ3KHS2P","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":48071},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"3bea3e78f285053527ea21cc071399afbc0f7bd9","scripts":{"build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"_npmUser":{"name":"gwelinder","email":"npm@clawbureau.com"},"repository":{"url":"git+https://github.com/clawbureau/clawbureau.git","type":"git","directory":"packages/clawsig-conformance"},"_npmVersion":"11.8.0","description":"Conformance test runner and GitHub Action for the Clawsig Inside program.","directories":{},"_nodeVersion":"24.13.0","dependencies":{"@clawbureau/clawverify-core":"^0.1.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^25.2.1","@actions/core":"^1.11.1"},"_npmOperationalInternal":{"tmp":"tmp/clawsig-conformance_0.2.0_1771003039781_0.5042048353038477","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@clawbureau/clawsig-conformance","version":"0.2.1","description":"Conformance test runner and GitHub Action for the Clawsig Inside program.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","typecheck":"tsc --noEmit","prepublishOnly":"npm run build"},"keywords":["clawsig","conformance","proof-bundle","agent-verification","github-action","clawsig-inside"],"repository":{"type":"git","url":"git+https://github.com/clawbureau/clawbureau.git","directory":"packages/clawsig-conformance"},"homepage":"https://clawsig.com/directory","bugs":{"url":"https://github.com/clawbureau/clawbureau/issues"},"dependencies":{"@clawbureau/clawverify-core":"^0.2.0"},"devDependencies":{"@actions/core":"^1.11.1","@types/node":"^25.2.1","typescript":"^5.7.0"},"engines":{"node":">=20"},"license":"MIT","gitHead":"707b934c991bee2279d39080dd83c4d7315fa328","_id":"@clawbureau/clawsig-conformance@0.2.1","_nodeVersion":"24.13.0","_npmVersion":"11.8.0","dist":{"integrity":"sha512-h/M8iRHOQksQrvHWIb6/FqpCsEA+Nmc+XphVtjU1+6z0RLQsTqFJfLf67+ip9e0AJio3XRzhVrNLW5V0MoFvKA==","shasum":"294725fcee9f3fc6e0b81376c9cfba8a13a7f6a3","tarball":"https://registry.npmjs.org/@clawbureau/clawsig-conformance/-/clawsig-conformance-0.2.1.tgz","fileCount":23,"unpackedSize":48071,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEr5Wuylyp5qUM/lxe5MX+A+hZLswg08qQY/T2HcRaVTAiBdkGafIk8/NaBhvGu60vIuSziyp7Xl/wf+0AxiQOi3oA=="}]},"_npmUser":{"name":"gwelinder","email":"npm@clawbureau.com"},"directories":{},"maintainers":[{"name":"gwelinder","email":"npm@clawbureau.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/clawsig-conformance_0.2.1_1771003222768_0.23219141216445593"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-13T17:17:19.697Z","modified":"2026-02-13T17:20:23.059Z","0.2.0":"2026-02-13T17:17:19.915Z","0.2.1":"2026-02-13T17:20:22.909Z"},"bugs":{"url":"https://github.com/clawbureau/clawbureau/issues"},"license":"MIT","homepage":"https://clawsig.com/directory","keywords":["clawsig","conformance","proof-bundle","agent-verification","github-action","clawsig-inside"],"repository":{"type":"git","url":"git+https://github.com/clawbureau/clawbureau.git","directory":"packages/clawsig-conformance"},"description":"Conformance test runner and GitHub Action for the Clawsig Inside program.","maintainers":[{"name":"gwelinder","email":"npm@clawbureau.com"}],"readme":"# @clawbureau/clawsig-conformance\n\nConformance test runner and GitHub Action for the **Clawsig Inside** program.\n\nValidates that AI agent frameworks emit correct [Clawsig Protocol](https://clawsig.com) proof bundles. Frameworks that pass earn the \"Clawsig Inside\" badge and are listed in the [Clawsig Directory](https://clawsig.com/directory).\n\n## What the Conformance Test Checks\n\n1. **Mock proxy** -- starts a local HTTP server mimicking OpenAI/Anthropic APIs\n2. **Agent spawn** -- runs your agent command with env vars pointing at the mock proxy\n3. **Bundle discovery** -- looks for `.clawsig/proof_bundle.json` in the working directory\n4. **Cryptographic verification** -- verifies the bundle using `@clawbureau/clawverify-core` (Ed25519 signatures, hash chain integrity, receipt validation)\n5. **Tier check** -- confirms the proof tier meets your expected minimum\n\n### Result fields\n\n| Field | Description |\n|---|---|\n| `passed` | Overall pass/fail |\n| `bundle_found` | Was a proof bundle found at the expected path? |\n| `bundle_valid` | Did the bundle pass cryptographic verification? |\n| `tier` | Detected proof tier (`self`, `gateway`, `sandbox`, `tee`) |\n| `tier_meets_expected` | Does the detected tier meet your minimum? |\n| `event_chain_length` | Number of events in the proof bundle event chain |\n| `receipt_count` | Total receipts (gateway + tool + side-effect + human approval) |\n| `errors` | List of human-readable error messages |\n\n## Quick Start (GitHub Action)\n\nAdd to your CI workflow:\n\n```yaml\nname: Clawsig Conformance\non: [push, pull_request]\n\njobs:\n  conformance:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: actions/setup-node@v4\n        with:\n          node-version: '20'\n      - run: npm ci\n\n      - name: Clawsig Conformance Test\n        uses: clawbureau/clawsig-conformance-action@v1\n        with:\n          agent_command: 'npm run test:agent'\n          expected_tier: 'self'\n          timeout: '60'\n```\n\n### Action Inputs\n\n| Input | Required | Default | Description |\n|---|---|---|---|\n| `agent_command` | Yes | -- | Command to run your agent |\n| `expected_tier` | No | `self` | Minimum proof tier (`self`, `gateway`, `sandbox`, `tee`) |\n| `timeout` | No | `60` | Timeout in seconds |\n| `output_path` | No | `.clawsig/proof_bundle.json` | Where the agent writes its proof bundle |\n\n### Action Outputs\n\n| Output | Description |\n|---|---|\n| `passed` | `true` or `false` |\n| `tier` | Detected tier or `none` |\n| `bundle_found` | `true` or `false` |\n| `bundle_valid` | `true` or `false` |\n| `event_chain_length` | Number of events |\n| `receipt_count` | Number of receipts |\n\n## Quick Start (Programmatic)\n\n```typescript\nimport { runConformanceTest } from '@clawbureau/clawsig-conformance';\n\nconst result = await runConformanceTest({\n  agentCommand: 'node my-agent.js',\n  expectedTier: 'self',\n  timeout: 60,\n});\n\nconsole.log(result.passed);    // true/false\nconsole.log(result.tier);      // 'self', 'gateway', etc.\nconsole.log(result.errors);    // [] if passed\n```\n\n## How It Works\n\n1. Starts a **mock LLM proxy** on a random local port\n2. Sets `OPENAI_BASE_URL` and `ANTHROPIC_BASE_URL` to point at the mock\n3. Spawns your agent command as a child process\n4. The mock returns canned responses and emits mock gateway receipts via `X-Clawsig-Receipt`\n5. On agent exit, reads `.clawsig/proof_bundle.json`\n6. Verifies the bundle cryptographically with `@clawbureau/clawverify-core`\n7. Checks the proof tier against your expected minimum\n\nThe mock proxy is fully self-contained -- **no external network calls**.\n\n### Environment Variables Set by the Runner\n\n| Variable | Value |\n|---|---|\n| `OPENAI_BASE_URL` | `http://127.0.0.1:{port}/v1/proxy/openai` |\n| `OPENAI_API_BASE` | Same as above (legacy) |\n| `ANTHROPIC_BASE_URL` | `http://127.0.0.1:{port}/v1/proxy/anthropic` |\n| `CLAWSIG_CONFORMANCE_TEST` | `1` |\n| `CLAWSIG_MOCK_PROXY_URL` | `http://127.0.0.1:{port}` |\n| `CLAWSIG_MOCK_PROXY_PORT` | `{port}` |\n\n## Earning the \"Clawsig Inside\" Badge\n\n1. **Integrate** `@clawbureau/clawsig-sdk` (or `npx clawsig wrap`) so your framework emits proof bundles\n2. **Add the conformance test** to your CI using the GitHub Action\n3. **Pass the test** -- the Action submits a certification claim\n4. **Get listed** on [clawsig.com/directory](https://clawsig.com/directory):\n\n```markdown\n[![Clawsig Inside](https://api.clawverify.com/v1/badges/conformance/gateway.svg)](https://clawsig.com/directory)\n```\n\n### Tier Levels\n\n| Tier | What it proves |\n|---|---|\n| `self` | Agent signs its own proof bundle (DID + Ed25519) |\n| `gateway` | LLM calls routed through a trusted gateway with independent receipts |\n| `sandbox` | Agent ran in an isolated sandbox with attestations |\n| `tee` | Agent ran in a Trusted Execution Environment (hardware attestation) |\n\n### Certification Lifecycle\n\n- **Verified** -- passes conformance, listed in directory\n- **Expired** -- no passing run in 90 days\n- **Revoked** -- manual revocation (policy violation)\n\n## Schemas\n\n- Conformance Claim: [`packages/schema/certification/conformance_claim.v1.json`](../schema/certification/conformance_claim.v1.json)\n- Directory Entry: [`packages/schema/certification/directory_entry.v1.json`](../schema/certification/directory_entry.v1.json)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}