⬡ SNAPKITTY SOVEREIGN OS · SECURITY LANE

Investigators get tools.
The AI gets a proof trail.

AgentScope SIFT wraps every forensic finding in a WORM-sealed evidence chain. No agent claims a result unless it can prove which tool produced it, signed with Ed25519, and timestamped on-chain.

View on GitHub App Directory →
agentscope-sift · demo run
[INIT]  AgentScope SIFT v1.0.0
[SCAN]  Loading 3 forensic pipelines...
[TOOL]  volatility3 → memory.dump
[TOOL]  plaso      → timeline.csv
[TOOL]  yara       → rules/malware.yar
[AGENT] Hypothesis: lateral movement via RDP session hijack
[CHAIN] Evidence sealed → 0x7fa3...c291
[LEAN4] EvidenceChain.lean ✓ verified
[WORM]  Block #441 · SHA-256 · Ed25519 signed
[DONE]  Finding provable · chain intact

WHAT IT DOES

⛓
WORM Evidence Chain
Every tool invocation appends to an append-only SHA-256 chain. The agent cannot modify history, only extend it.
∴
Lean 4 Verification
Critical deductions are machine-verified in Lean 4 before the agent is allowed to claim a finding as proven.
🔍
Tool Scope Enforcement
Each forensic tool is scoped to its declared domain. Volatility, Plaso, YARA — every invocation is logged and bounded.
⚡
MCP Native
Runs as a Model Context Protocol server. Drop into any MCP-compatible AI shell — Claude, Cursor, OpenAI Assistants.
🔐
Ed25519 Signing
Each sealed block is signed with Ed25519. The trust deed is published, the key is auditable.
◈
Prolog Trust Rules
Trust.pl contains the inference engine. Add your own rules — who can see which evidence, under what conditions.

TECH STACK

01 Node.js 18+ Runtime, MCP transport, tool orchestration runtime
02 Lean 4 Formal proof verification of evidence chains proof
03 Prolog Trust rule inference engine (trust.pl) logic
04 WORM Chain SHA-256 append-only sealed ledger (JSONL) sovereign
05 Ed25519 Block signing via libsodium / Node:crypto crypto
06 MCP Model Context Protocol transport layer protocol