{
  "report_id": "DDCAL-PA-001",
  "revision": "1.0",
  "status": "RELEASED",
  "classification": "PUBLIC",
  "assessment_date": "2026-08-29",
  "assessment_type": "claim-bounded source-code review with controlled runtime probes",
  "target": {
    "name": "Microsoft Agent Framework — FIDES",
    "repository": "https://github.com/microsoft/agent-framework.git",
    "commit": "edfe115ea06bca57ae5a123d0fac5b3fdda13603",
    "control": "External public target controlled by Microsoft; DDCAL used public read-only source evidence and made no target changes."
  },
  "claim": "Whether FIDES supports its public characterization as a deterministic prompt-injection defense in which tool calls are policy-checked and security guarantees are verifiable.",
  "source_sha256": {
    "security": "ec9daee8e812e61a4a7ddff2bebcfe668b16c72fd6388a7e5796234fc0848da9",
    "tests": "8d09b0883889dc43ea13a999949b79ea0feb1b03cb6f2857fc452cf9d73f5003",
    "adr": "302e918053a8a3947821151e056eca5923574c6eecdb390be4e9aaff6a640b1a",
    "summary": "d7d34026e10bc2c8fa7438991aa2db89a1073398d00236dce474d9e177ca1bd7",
    "pyproject": "44bb22325b553643109c3ac5167fc1313b6c33281dbf8c8cdf7396d1bad97a75"
  },
  "controlled_probes": {
    "policy_blocks_untrusted_when_context_label_present": true,
    "policy_executes_when_context_label_missing": true,
    "private_to_public_confidentiality_is_blocked": true,
    "trusted_source_integrity_overrides_untrusted_input_label": true
  },
  "findings": [
    {
      "id": "F1",
      "type": "positive",
      "result": "PASS — untrusted-context tool call blocked when context label is present"
    },
    {
      "id": "F2",
      "type": "positive",
      "result": "PASS — PRIVATE to PUBLIC confidentiality flow rejected"
    },
    {
      "id": "F3",
      "type": "adverse",
      "severity": "high",
      "result": "REPRODUCED — policy middleware continues execution when context_label is absent"
    },
    {
      "id": "F4",
      "type": "adverse",
      "severity": "medium",
      "result": "REPRODUCED — source_integrity=trusted can yield TRUSTED output from UNTRUSTED input"
    },
    {
      "id": "F5",
      "type": "limitation",
      "severity": "material",
      "result": "ADR is proposed, FIDES classes are experimental, and no formal proof artifact was established in scope"
    }
  ],
  "unresolved": [
    "middleware ordering across every integration path",
    "trust assumptions for external MCP-provided IFC labels",
    "full end-to-end prompt-injection attack space"
  ],
  "limitations": [
    "one immutable revision only",
    "not certification",
    "does not establish absence of vulnerabilities",
    "does not generalize to future revisions"
  ],
  "uncertainty": "Moderate — principal adverse behaviors reproduced; not every integration/provider/deployment exercised.",
  "disposition": "CLAIM PARTIALLY SUPPORTED — MATERIAL ADVERSE FINDINGS",
  "relationship_declaration": "Assessment-specific external public target; no blanket organizational-independence claim.",
  "publication_authority": "Only public target material and DDCAL synthetic probes are published; no private evidence, credentials, exploit payloads or protected DDC internals."
}
