ASPL Blog

What it does, and why it's different.

A field guide to the agent trust layer — discovery, signed delivery, earned reputation, transparency, and supply-chain defense. Honest about the hard parts.

Overview2026-06-165 min read

What ASPL Actually Is (and What It Isn't)

ASPL is a thin trust layer that sits above MCP and A2A — not a replacement for them.

Trust2026-06-135 min read

Discovery Needs Trust, Not Just a Registry

A flat list of tools tells you what exists. It doesn't tell you what's worth running.

Integrity2026-06-114 min read

Signed Delivery: Getting Exactly What Was Advertised

Content hashes plus an Ed25519 delivery signature let you prove the bytes you got are the bytes you were promised.

Trust2026-06-095 min read

You Can't Pump Your Own Reputation

Trust is built from distinct, non-self confirmations — so a publisher confirming its own capability earns nothing.

MCP2026-06-064 min read

Bringing MCP Tools Into a Trust Fabric

Point ASPL at an MCP server and its tools become trust-scored, signed, revocable capabilities.

A2A2026-06-034 min read

A2A Agent Cards as First-Class Capabilities

An A2A Agent Card's skills become discoverable, trust-scored ASPL capabilities — without leaving A2A behind.

Discovery2026-05-304 min read

Ask for What You Mean: Semantic Intent Matching

Discovery uses sentence embeddings, so 'convert documents to plain text' finds a 'PDF text extraction' tool even with no shared keywords.

Audit2026-05-276 min read

Certificate Transparency, Applied to Agents

An RFC 6962 Merkle log lets anyone prove the audit history only ever appended — and that a specific event is in it.

Safety2026-05-234 min read

Revocation That Actually Reaches Agents

A live push stream for instant notice, plus a signed status list to catch up after downtime — and revocation can't be bypassed by pre-accepting.

Scale2026-05-195 min read

Federation Without Becoming a Bottleneck

A node can mirror a peer's catalogue with verified provenance — discovery spans nodes, but the peer stays out of the acquisition path.

Security2026-05-156 min read

Defending the Agent Supply Chain

A layered content scanner plus a standalone adversarial crash-test agent — the defensive and the offensive halves of the same problem.

Compatibility2026-05-124 min read

Will This Capability Even Run Here?

Before acquiring a capability, an agent can declare its environment and ask whether the capability's requirements are satisfied.