{
  "tool_id": "art-385-agent-token-scope-checker",
  "kernel_id": "art-385-agent-token-scope-checker",
  "display_name": "Agent Token Scope Checker",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_mandate",
  "purpose": "Compares a requested agent action (amount, currency, merchant category, timestamp) against an agent token or mandate's declared scope: spend cap, currency, MCC allow-list, and expiry. If an attenuation chain of ancestor tokens is supplied, also checks that each delegation link narrows -- never widens -- the parent's bounds. Returns an in-scope or out-of-scope verdict and receipt. Pure evaluation only -- never authorizes, blocks, or executes a payment. Consumes the same mandate-chain vocabulary as art-01; distinct job -- one requested action against one token's bounds, not full mandate-chain structural validation.",
  "control_description": "Compares a requested agent action (amount, currency, merchant category, timestamp) against an agent token or mandate's declared scope: spend cap, currency, MCC allow-list, and expiry. If an attenuation chain of ancestor tokens is supplied, also checks that each delegation link narrows -- never widens -- the parent's bounds. Returns an in-scope or out-of-scope verdict and receipt. Pure evaluation only -- never authorizes, blocks, or executes a payment. Consumes the same mandate-chain vocabulary as art-01; distinct job -- one requested action against one token's bounds, not full mandate-chain structural validation.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:ceb4b481b11aabd4718fed5d5c1d67fb69a5b58a07e48c5d1be12bbe8113af1a",
  "trust_label": "independently verified -- zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-10",
  "last_validated": "2026-07-10",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 47,
  "source_url": "https://ainumbers.co/chaingraph/art-385-agent-token-scope-checker.html",
  "generated_at": "2026-07-25T20:02:55.601Z"
}
