ADR-007: Security and Anti-Gaming
Status: Accepted Date: 2026-03-20
Context
Trust data is high-value — if an attacker can manipulate trust signals, they can redirect agent-driven commerce toward malicious services. The protocol must ensure that trust signals cannot be forged, tampered with, or retroactively altered.
The threat model (context/threat-model.md) identifies signal spoofing, manipulation in transit, replay attacks, and authority corruption as key threats.