2026-10-11 16:38 UTC

Kenwea claims its released Notary tooling executes a package's own install surface under constrained sandbox conditions and signs hash-bound results, enabling verifiable pre-install and CI checks without certifying package safety or transitive dependencies.

state: seedheat: lowuncertainty: mediumknownscott: lowsupply-chain-security sandboxing developer-toolsKenwea Protocol

What is this?

The case describes Notary, attributed to Kenwea Protocol, as released tooling that runs a package’s own install scripts in a constrained sandbox and issues artifact-hash-bound, Ed25519-signed execution verdicts through a CLI, GitHub Action, and browser verifier. Its claimed scope is evidence of observed execution, not certification of package safety or coverage of transitive dependencies. None of the supplied web results mentions Kenwea or Notary, so the release, implementation, and attribution remain uncorroborated here; the snippets establish only the surrounding problem of install-time malware compromising developer machines and CI systems.

Why it matters to Scott

The radar already tracks this development in radar:kenwea-npm-install-sandbox; the supplied material adds no corroborated implementation or testing result. Its claimed hash-bound execution receipts alongside containment intersect Scott’s Execution Attestation and Agent Provenance Stack, but establish neither their broader authorisation guarantees nor a reason to change his builds or arguments.
ip:concept.execution-attestationip:framework.agent-provenance-stackradar:kenwea-npm-install-sandboxradar:concept.supply-chain-security
queries asked of Scott's wikis
  • coding agent dependency installation sandbox trust boundaries
  • artifact hash signed execution receipts verifiable evidence
  • pre-install package quarantine CI security gates
  • sandbox observations versus safety guarantees
  • transitive dependency risk lifecycle script controls

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 633h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-15 07:28 (minted)⭐ origin echo-reconstructedProvides a CLI check, GitHub Action, and browser verification for Ed25519-signed execution verdicts bound to artifact hashes; explicitly exc
Kenwea Protocol on blog (echo) · attributed from hn.story.49708563 · published time unknown
—
09-15 06:35first on hacker news · published · lag ?Kenwea Notary run a package's install scripts in a sandbox, get a signed verdict
genshro
—
09-15 06:35amplified on hacker news 👑hn.story.49708563
genshro
peak 2 · 0 comments · 98% of case engagement
09-15 07:21our radar first saw it · lag ?discovery anchor: hn.story.49708563—
pace: p23 vs 1032 stories at the 336h mark (now 633h old) — ahead of aafp-commons-signed-agent-notebook (2.0x), behind agentgate-signed-agent-receipts (0.7x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnKenwea Notary run a package's install scripts in a sandbox, get a signed verdict
Retrieved article excerpt

Open article · Retrieved 2026-09-15T07:22:35.558479+00:00

# Verify a notarization

A Kenwea record is a signed statement of what an artifact did — the exact bytes, run under stated constraints, at a moment in time. Paste one here and check it against our published key. This runs entirely in your browser — the payload and signature are never sent anywhere, including to us.

That is deliberate. A page where Kenwea tells you Kenwea's signature is fine would prove nothing; the whole point of signing a verdict is that you do not have to take our word for it. Better still, don't use this page at all — verify it in your own code. This exists so you can see it work before you write any.

## Try it first

One command, no account, no key. Name any npm package, or give an https URL to a file, an npm tarball or a Python wheel:

```
npx -y @kenwea/mcp check lodash
```

It fetches the exact bytes npm would install, runs the package's own declared install scripts in a container with no network, all capabilities dropped and a read-only filesystem, and prints a verdict signed under our published Ed25519 key and bound to the sha256 of what it read. A Python wheel or source zip is unpacked with the standard library only, each top-level package is imported, and a declared console script is invoked with `--help`. The signedAttestation block in the result is what the box below checks.

What it does not do, so nobody is surprised: dependencies are not installed, so it measures a package's own install surface and not the transitive tree. Code that only runs when the consuming app calls it is out of reach. Anonymous keys get 20 checks an hour. When the limit is ours, a runtime we do not have for instance, the result says `manual_review` and names our limit rather than blaming your code.

As a CI gate, the same check is a GitHub Action:

```
- uses: kenwea-protocol/kenwea-notary-action@v1
  with:
    package: your-package-name
    fail-on: rejected
```

payload — paste it exactly as returned, byte for bytesignature — base64

Verify in this browser

## What a record does and does not say

- The claim is about the hash, not the URL. A valid signature says those exact bytes produced that verdict. The address can serve something else tomorrow — hash what you hold and compare it to contentSha256.
- An unreadable artifact is never signed. If we could not fetch the bytes there is no signature at all, rather than a signed “we could not read it” that an attestation scanner would count as a finding.
- A signature is not an endorsement. It says what happened under stated constraints. `approved` means it ran and exited zero — not that the code is good, safe for your use, or does what it claims.

Public key: [/.well-known/kenwea-attestation-key](https://www.kenwea.com/.well-known/kenwea-attestation-key)
genshro20
🟧 echo.blog ⭐Provides a CLI check, GitHub Action, and browser verification for Ed25519-signed execution verdicts bound to artifact hashes; explicitly excKenwea Protocol——

Interpretation history

Decision trace