Wrench

Argument · Wrench 0.16.1

A claimed agent name is not an attested web operation.

The Agentic Web Index counts inbound impersonation when a request claims a recognized agent identity and then fails that identity's supported authentication. That measurement is useful and bounded. It still leaves the outbound problem that Wrench answers: name the job, bind the account and transport, and refuse to treat a familiar bot string, live browser, or missing contract as proof.

This argument uses the live Known Agents insights page fetched for this draft, the dated Hraness Reading digest of that index, and the public v0.16.1 pages for the Wrench home, provider capability attestation, security guide, and personal-agents comparison. Operation counts are the current release attestation, substituted at site build time. The live spoofing chart does not publish an operator name beside every rate, so this page does not invent those names.

A spoofed visit fails a check, not an attribution

Known Agents defines the unit on The Agentic Web Index: “A visit is considered spoofed when it claims a recognized agent identity but fails that agent's supported authentication method, such as verified IP or Web Bot Auth.” The index is therefore a comparison between a claimed name and a supported proof. A user-agent string that merely looks like a listed crawler or assistant is not enough to enter the measurement as authentic traffic.

The same methodology page keeps detection separate from blame: “A failed check indicates that the visit was likely impersonating the named agent; it does not identify the software or operator that actually made the request.” A site that logs a spoofed Googlebot hit still does not know which crawler, scanner, or person sent it. The named identity is the costume. The operator stays unknown.

The measurement also has a hard edge: “Agents without a supported authentication method are not included in these measurements.” Unauthenticated traffic can still arrive. The index simply refuses to score impersonation for identities that cannot be checked. That is the same refusal Wrench makes on the outbound side when a contract is missing: absence of proof is not treated as a passing grade.

The live insights page updates daily. In the snapshot fetched for this draft, the highest listed spoofed-traffic rate was 0.5% for a Search Engine Crawler identity. An AI Assistant identity sat at 0.2%. Several AI Search Crawler and AI Data Scraper identities sat at 0.1%. An AI Agent identity appeared in the same list at 0.0%. Those figures are displayed rates on participating sites, not a ranked operator table, and they are not copied from the dated digest below.

The 12 August 2026 Hraness Reading digest recorded a different completed-day snapshot: Googlebot at 0.5% of impersonated traffic, and several AI-related identities at 0.1% or less. That digest is a dated reading of the same public index, published from hraness.com. It is not this page, and this page does not reprint its idea list. Both snapshots stay directional. Known Agents writes: “Results characterize the observed network and broader directional trends; they should not be interpreted as a precise census of global web traffic.” The index draws completed days from more than 5,000 participating websites whose composition can change.

Credential paths are now ordinary web targets

The live index also publishes an active-threat note beside the spoofing charts: “We are observing a widespread campaign impersonating AI bots to scan websites for vulnerabilities.” The next sentence names the object of those scans: “The attacker appears to be targeting credential and configuration paths used by AI coding tools.” Impersonation is the cover. The payload is a request for files that an agent, cloud account, or deployment environment might leave on a reachable origin.

The same section lists recent top targeted paths. The fetched examples include /.config/anthropic/credentials/default.json, /.claude/settings.json, /.hermes/.env, /.openclaw/.env, /.codex/config.toml, /.aws/credentials, /.npmrc, and several .env variants. Those paths are public in the index. They are not Wrench operations, and they are not evidence that any listed coding tool authorized the request.

This is inbound reconnaissance wearing a bot name. It does not grant the sender those secrets, and it does not tell a receiving site who sent the probe. It does tell an operator something narrower: agent tooling has a public filesystem vocabulary, and scanners are already asking the web for it. A local capability layer that keeps credentials opaque still matters after you have read that list.

Attested operations bind the request before it leaves

The Wrench home states the product boundary in one sentence: each authenticated operation is typed, bounded, and tied to one account and transport. The caller brings the model and interface. Wrench supplies the local capability and custody layer. It is not an AI agent, planner, or approval shell. The home page also states the fail-closed rule in public: Wrench never switches to a browser fallback silently.

The security guide makes the bind exact. An authenticated Wrench operation binds one named outcome to an exact provider, transport, account realm, contract version, implementation, input, and risk. Credentials stay opaque to the caller. When those facts drift, the operation stops instead of changing transports or falling back to general browser control. The same guide keeps writes behind an exact preview and confirmation, and it refuses to retry an indeterminate dispatch.

The current release attests 322 operations across 22 bundled public adapters. 135 are observed. 187 remain capture-required. Those figures are the same release-bound counts published on the provider capability attestation. This page does not add a provider, invent an extra operation, or treat a reservation as ready. Telegram is absent from those manifests. Wrench does not install a Telegram Bot API substitute or claim Telegram contact access.

observed means the current contract can plan and execute after local doctor and auth checks pass. capture-required is an inert reservation. The attestation page says a missing or capture-required operation stays unavailable rather than falling back to general browser control. That is the outbound counterpart of the index rule that excludes identities with no supported authentication method.

Inbound authentication and outbound attestation answer different questions

The personal-agents comparison asks whether a persistent browser loop can stand in for a named contract. This page asks a different question: whether a claimed inbound identity, or a low displayed spoofing rate, can stand in for that same contract. Both pages refuse a substitution. They refuse different substitutes.

Decision Agentic Web Index spoofing check Wrench attested operation
What is named A recognized inbound agent identity A named outbound outcome such as messaging.list
What proves it That identity's supported authentication method, such as verified IP or Web Bot Auth Exact provider, transport, account realm, contract version, implementation, input, and risk
Failed check The visit is counted as spoofed. The real operator stays unknown The operation stops. A capture-required reservation stays inert
No supported method The identity is excluded from the spoofing measurement The reservation cannot plan or execute, and Wrench does not invent a browser fallback
Secrets Recent probes request agent, cloud, package, and environment credential paths Credentials stay opaque to the caller and terminate only at sinks declared by the capability

A displayed 0.5% or 0.1% spoofed-traffic rate does not make an unreviewed Wrench operation safe to invent. The index is an inbound sample with a changing participant set. The attestation is a finite outbound catalog. Neighboring surfaces still do not inherit authority: LinkedIn's official contact adapter does not grant its consumer-web inbox adapter, and an Instagram inbox summary does not authorize an individual thread read. Those examples are published on the security page so a gap stays visible.

The comparison of browser-using personal agents with attested Wrench operations covers Instinct, Grok Bots, ChatGPT Work, and the password-reset recovery that finished a broken browser job. A separate argument covers why a VM is not an attested web operation. Read the comparison for the product-loop argument. Read the VM page for the containment argument. Read this page for the inbound-identity argument. The pages do not reprint one another.