A field guide to the agent trust layer — discovery, signed delivery, earned reputation, transparency, and supply-chain defense. Honest about the hard parts.
ASPL is a thin trust layer that sits above MCP and A2A — not a replacement for them.
A flat list of tools tells you what exists. It doesn't tell you what's worth running.
Content hashes plus an Ed25519 delivery signature let you prove the bytes you got are the bytes you were promised.
Trust is built from distinct, non-self confirmations — so a publisher confirming its own capability earns nothing.
Point ASPL at an MCP server and its tools become trust-scored, signed, revocable capabilities.
An A2A Agent Card's skills become discoverable, trust-scored ASPL capabilities — without leaving A2A behind.
Discovery uses sentence embeddings, so 'convert documents to plain text' finds a 'PDF text extraction' tool even with no shared keywords.
An RFC 6962 Merkle log lets anyone prove the audit history only ever appended — and that a specific event is in it.
A live push stream for instant notice, plus a signed status list to catch up after downtime — and revocation can't be bypassed by pre-accepting.
A node can mirror a peer's catalogue with verified provenance — discovery spans nodes, but the peer stays out of the acquisition path.
A layered content scanner plus a standalone adversarial crash-test agent — the defensive and the offensive halves of the same problem.
Before acquiring a capability, an agent can declare its environment and ask whether the capability's requirements are satisfied.