Beyond the Lethal Trifecta: Agentic Commerce on the Open Internet — David Levine, Kiduna Club
This talk proposes legally registered agent organizations, scoped JWT authority, and blockchain audit trails for open-internet commerce; it is an architecture proposal, not validation.
The talk frames the “lethal trifecta” as agents combining private data, untrusted internet content, and action permissions. It proposes a registered **DUNA**, scoped **JWT tokens**, and blockchain-linked audit trails to establish agent identity, authority, and boundaries.
Builders can borrow the narrower design principle now: give every agent explicit organizational identity, short-lived scoped claims, bounded account access, and a traceable owner before it interacts with another agent or external service.
The talk frames the “lethal trifecta” as agents combining private data, untrusted internet content, and action permissions. It proposes a registered **DUNA**, scoped **JWT tokens**, and blockchain-linked audit trails to establish agent identity, authority, and boundaries. Builders can borrow the narrower design principle now: give every agent explicit organizational identity, short-lived scoped claims, bounded account access, and a traceable owner before it interacts with another agent or external service. The presentation reports organization number **628407**, but supplies no deployment study, security testing, or evidence that the scheme prevents prompt injection or data leakage. Decision markets and broad autonomous commerce remain proposed mechanisms in this material.
This extends the candidates’ least-privilege guidance from individual tool calls to cross-organization agent identity, proposing scoped credentials, accountable ownership, and shared audit trails. It remains an architectural proposal rather than evidence of protection: identity and traceability may bound authority, but the supplied material does not show that they stop prompt injection, leakage, manipulation, or unauthorized commerce.