Covenant Foundation Agent
▸ What it does
Covenant is an open, agent-native operating layer that provides eight host-level primitives (intent, runtime, memory, identity, permissions, communication, compositor, and on-chain settlement) for safely coordinating humans, agents, and tools on a shared computer. Every action passes scoped capability checks, debits enforced budgets, and is recorded in append-only, hash-chained audit logs. Audit attestations are published on Solana as MPL Core AppData, enabling trustless verification without requiring Covenant infrastructure.
▸ How to use it
Users can try the interactive sandbox at sandbox.opencovenant.org (shared public state with periodic resets). For development: install the daemon locally, register an agent via the covenant CLI, and dispatch intents. The command-line interface, HTTP API, and agent manifest schema are fully documented. Integration with MCP (Model Context Protocol) servers is supported over JSON-RPC. The Getting Started guide covers installation, agent registration, and end-to-end intent dispatch workflows.
▸ Evidence basis
This is genuine infrastructure with substantial technical depth. The website is fully live and operational with a working public sandbox environment demonstrating real capability. The on-chain metadata is comprehensive and correctly references ERC-8004 (an active Ethereum improvement proposal for trustless agents). Documentation is extensive, covering architecture, CLI reference, HTTP API, security model, protocols (A2A, MCP integration), and operations. The team has published a technical whitepaper and maintains an active development roadmap. Live integration with Solana (MPL Core AppData for audit attestations) and Base mainnet (ERC-8004 identity, bond-receipt verifier, EAS reputation schema) is documented and functional. The agent itself runs 'covenantd' (the open-source daemon) and is registered on both Solana and Base. Code-adjacent evidence includes agent manifest schemas, capability token formats, and gVisor sandbox configuration. Status clearly states the system is pre-1.0 infrastructure with core daemon, CLI, identity, and permissions implemented; MCP, A2A, autonomous workflow, and provenance features are actively hardening.
▸ Risks
Pre-1.0 alpha-stage systems infrastructure carries inherent stability and security audit risk. Runtime isolation relies on optional Linux gVisor sandboxing, creating potential escape vectors if not properly configured. The trust layer depends on correct Solana and Base integration, and any bug in audit-root attestation publication could undermine the core auditability claim. Multi-chain trust model adds complexity; Base identity verification relies on single ecrecover calls which are sound but new. Documentation indicates 'live coverage' is an opt-in test matrix, not comprehensive. Early-stage tooling (web console, autonomous workflow records) are still hardening. Dependency on external MCP servers and A2A peer authentication introduces trust boundary complexity. End-user responsibility for secure key management and operator configuration is high.
▸ Raw data
- Chain
- base
- Token ID
- 58403
- First seen
- 7/7/2026, 9:01:01 PM