ended5월 8일· 1 sources
The Trust Illusion: How Agent Registries Verify the Past, Not the Present
Agent 신뢰의 착각, 등록 시점이 행동을 보장하지 않는다
Why it matters
Agent registries today verify who signed up, not who is running—a fundamental Time of Check, Time of Use vulnerability where legitimately registered agents can pivot to malicious behavior while remaining marked as trusted. Static registration directories have no mechanism to detect runtime behavior changes, creating a dangerous gap between verification at signup and execution in production. Per-session identity tokens like AgentLair's 1-hour EdDSA JWT solve this by shifting trust from permanent registration to continuous runtime validation.
1
Sources
+0
24h
—
Growth
136d
Active
TOCTOUAgent registryAgentLairEdDSA JWTSession authentication