agent-loss-map 0.21.0

  section                      findings  blocker  major  minor
  ---------------------------  --------  -------  -----  -----
  uacp-spec                           4        0      2      2
  autogen-agentchat                   6        0      4      2
  openai-function-calling             3        0      1      2
  uacp-native                         1        1      0      0
  anthropic-tool-use                  2        0      1      1
  gemini-function-declaration         2        0      1      1
  bedrock-converse                    2        0      1      1
  bedrock-agent-function              2        0      1      1
  a2a-agentcard                       1        0      0      1
  agent-skills                        2        0      1      1
  stripe                              6        0      1      5
  deepwiki                            3        0      0      3
  context7                            4        0      2      2
  adoraads-beauty-gateway             6        0      0      6
  ---------------------------  --------  -------  -----  -----
  TOTAL                              44        1     15     28

  UACP spec: worst finding is major.
  Cross-format blockers are loss measured in foreign formats,
  which is what the harness is for, not a defect in UACP.
Provenance of corpus entries:
  autogen-agentchat        confidence=documented-api
  openai-function-calling  confidence=documented-api
  uacp-native              confidence=observed-serialization
  anthropic-tool-use       confidence=documented-api
  gemini-function-declaration confidence=documented-api
  bedrock-converse         confidence=documented-api
  bedrock-agent-function   confidence=documented-api
  a2a-agentcard            confidence=documented-api
  agent-skills             confidence=documented-api
  stripe                   confidence=observed-serialization
  deepwiki                 confidence=observed-serialization
  context7                 confidence=observed-serialization
  adoraads-beauty-gateway  confidence=observed-serialization

==============================================================================
PART 1  UACP schema vs normative text, and schema vs the two reference implementations
==============================================================================
  [major]   SCHEMA_CONFLICT    schemas.$id/$ref
      The schema set cannot be resolved by a standards-compliant validator without network access. Relative $refs resolve against the schema's own $id, and every $id sits on a host that does not resolve, so even a plain sibling ref like 'capability.schema.json' becomes an unreachable URL. A registry holding only the referring document raises on the lookup, and one that falls back to remote retrieval (jsonschema's default) instead attempts a network fetch of that URL, which returns nothing. Either way air-gapped builds and any offline CI cannot validate a descriptor. Resolved here with: agent-descriptor ($id host wippa.dev) refs capability.schema.json -> https://wippa.dev/uacp/schemas/capability.schema.json [Unresolvable: capability.schema.json]. The one thing this did not check is whether the host serves the schemas -- that needs the network this harness avoids, so it is stated here rather than computed
      evidence: computed against the vendored bytes, not asserted: referencing Registry().resolver(base_uri='https://wippa.dev/uacp/schemas/agent-descriptor.schema.json').lookup('capability.schema.json') raises Unresolvable: capability.schema.json, so the ref resolves to https://wippa.dev/uacp/schemas/capability.schema.json and nothing can be fetched from there

  [major]   UNVERIFIABLE_CLAIM unspecified safety property: cross_pipeline_cost_ceiling
      The spec is silent where it should not be. SPEC.md 15.6: agents and buses MAY enforce per-agent rate limits. No cross-pipeline ceiling is specified, and neither Bus implements one. Reported as a gap rather than an unimplemented claim: the spec makes rate limiting a MAY and says nothing about a pipeline-wide ceiling, so there is no claim to have failed. Two agents calling each other were measured at ~20k round trips/second, bounded only by the host recursion limit, and the caller received a success response with no indication the loop had been cut short.
      evidence: no cross-pipeline ceiling is defined in SPEC.md and neither Bus enforces one; measured behaviour rather than a source probe, so this is recorded as a gap in the specification

  [minor]   UNVERIFIABLE_CLAIM unverified security claim: acl_pattern_globbing
      This check needs the UACP source tree to confirm the claim is implemented. Set UACP_SOURCE_ROOT to a checkout to verify it; without it the claim is unverified, not passing.
      evidence: probe would read python/wippa_uacp/core/authz.py

  [minor]   UNVERIFIABLE_CLAIM unverified security claim: per_caller_acl_enforcement
      This check needs the UACP source tree to confirm the claim is implemented. Set UACP_SOURCE_ROOT to a checkout to verify it; without it the claim is unverified, not passing.
      evidence: probe would read python/wippa_uacp/core/bus.py


==============================================================================
PART 2  autogen-agentchat  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[web_search_func].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; autogen-agentchat exposes no output schema for this tool

  [major]   SEMANTIC_MISMATCH  lifecycle.autogen-agentchat
      The source agent is stateful: run() mutates internal history and is documented as being called with new messages rather than complete history. A UACP descriptor has no lifecycle or state field, and the UACP envelope is stateless message passing, so two calls that look identical on the wire mean different things on either side.
      evidence: source declares is_stateful=true; its own provenance: Official AutoGen AgentChat agents tutorial, read 2026-09-27. UACP SPEC.md section 1 agent descriptor has no state field

  [major]   SEMANTIC_MISMATCH  streaming.autogen-agentchat
      The source streams per-token chunks (ModelClientStreamingChunkEvent) that are part of the agent's own message trace. UACP stream messages are partial *results* correlated to a request via replyTo and sequence numbers. Mapping one onto the other conflates 'the agent's reasoning trace' with 'the result stream', so a UACP consumer would receive internal reasoning it never asked for and could not tell the two apart.
      evidence: autogen-agentchat declares streams_tokens=true; its own provenance: Official AutoGen AgentChat agents tutorial, read 2026-09-27. UACP SPEC.md section 13 defines stream/stream.end as correlated partial results. The specific chunk type observed in the AutoGen entry (ModelClientStreamingChunkEvent) is that framework's, not a universal one, so it is not cited as this source's evidence

  [major]   UNREPRESENTABLE    payload
      The source accepts heterogeneous content parts (for example MultiModalMessage(content=[str, Image])). The UACP envelope's payload is untyped, so a list would validate, but the spec defines no modality, media type or part ordering, and an in-memory Image object has no wire form. Nothing in UACP distinguishes this from an ordinary array payload.
      evidence: autogen-agentchat MultiModalMessage; UACP SPEC.md section 3 envelope fields define no content-part or modality construct

  [minor]   LOSSY              capabilities[web_search_func].name
      Capability 'web_search_func' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'web_search_func' is unnamespaced

  [minor]   LOSSY              capabilities[web_search_func].strict
      The source sets strict=False. JSON Schema has no equivalent of the OpenAI 'strict' flag, so the guarantee is dropped in either direction and cannot be re-expressed as a UACP consumer check.
      evidence: OpenAI function-calling tool shape vs JSON Schema (draft 2020-12); no 'strict' keyword exists in JSON Schema


==============================================================================
PART 2  openai-function-calling  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[get_weather].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; openai-function-calling exposes no output schema for this tool

  [minor]   LOSSY              capabilities[get_weather].name
      Capability 'get_weather' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'get_weather' is unnamespaced

  [minor]   LOSSY              capabilities[get_weather].strict
      The source sets strict=True. JSON Schema has no equivalent of the OpenAI 'strict' flag, so the guarantee is dropped in either direction and cannot be re-expressed as a UACP consumer check.
      evidence: OpenAI function-calling tool shape vs JSON Schema (draft 2020-12); no 'strict' keyword exists in JSON Schema


==============================================================================
PART 2  uacp-native  (confidence: observed-serialization)
==============================================================================
  [BLOCKER] UNREPRESENTABLE    csv.analyze.inputSchema.oneOf
      UACP capability uses JSON Schema keyword 'oneOf' at $.oneOf, which has no representation in an OpenAI function-calling `parameters` block. The capability cannot be exposed to an OpenAI-style tool consumer without either dropping the constraint or flattening it into prose.
      evidence: $.oneOf vs the OpenAI function-calling parameter subset


==============================================================================
PART 2  anthropic-tool-use  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[search_tool].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; anthropic-tool-use exposes no output schema for this tool

  [minor]   LOSSY              capabilities[search_tool].name
      Capability 'search_tool' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'search_tool' is unnamespaced


==============================================================================
PART 2  gemini-function-declaration  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[searchTool].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; gemini-function-declaration exposes no output schema for this tool

  [minor]   LOSSY              capabilities[searchTool].name
      Capability 'searchTool' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'searchTool' is unnamespaced


==============================================================================
PART 2  bedrock-converse  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[top_song].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; bedrock-converse exposes no output schema for this tool

  [minor]   LOSSY              capabilities[top_song].name
      Capability 'top_song' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'top_song' is unnamespaced


==============================================================================
PART 2  bedrock-agent-function  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[BookHotel].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; bedrock-agent-function exposes no output schema for this tool

  [minor]   LOSSY              capabilities[BookHotel].name
      Capability 'BookHotel' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'BookHotel' is unnamespaced


==============================================================================
PART 2  a2a-agentcard  (confidence: documented-api)
==============================================================================
  [minor]   LOSSY              capabilities[academic-research].name
      Capability 'academic-research' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'academic-research' is unnamespaced


==============================================================================
PART 2  agent-skills  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[pdf-form-filler].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; agent-skills exposes no output schema for this tool

  [minor]   LOSSY              capabilities[pdf-form-filler].name
      Capability 'pdf-form-filler' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'pdf-form-filler' is unnamespaced


==============================================================================
PART 2  stripe  (confidence: observed-serialization)
==============================================================================
  [major]   SEMANTIC_MISMATCH  lifecycle.stripe
      The source agent is stateful: run() mutates internal history and is documented as being called with new messages rather than complete history. A UACP descriptor has no lifecycle or state field, and the UACP envelope is stateless message passing, so two calls that look identical on the wire mean different things on either side.
      evidence: source declares is_stateful=true; its own provenance: openapi.spec3.json fetched from https://raw.githubusercontent.com/stripe/openapi/master/latest/openapi.spec3.json; the spec itself reports openapi 3.0.0 and info.version 2026-09-30.endive. Local refs resolved to depth 3 by scripts/extract_stripe.py, which is a code path rather than a transcription.. UACP SPEC.md section 1 agent descriptor has no state field

  [minor]   LOSSY              capabilities[GetCharges].name
      Capability 'GetCharges' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'GetCharges' is unnamespaced

  [minor]   LOSSY              capabilities[GetCustomers].name
      Capability 'GetCustomers' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'GetCustomers' is unnamespaced

  [minor]   LOSSY              capabilities[PostCharges].name
      Capability 'PostCharges' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'PostCharges' is unnamespaced

  [minor]   LOSSY              capabilities[PostCustomers].name
      Capability 'PostCustomers' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'PostCustomers' is unnamespaced

  [minor]   LOSSY              capabilities[PostRefunds].name
      Capability 'PostRefunds' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'PostRefunds' is unnamespaced


==============================================================================
PART 2  deepwiki  (confidence: observed-serialization)
==============================================================================
  [minor]   LOSSY              capabilities[ask_wiki_question].name
      Capability 'ask_wiki_question' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'ask_wiki_question' is unnamespaced

  [minor]   LOSSY              capabilities[read_wiki_contents].name
      Capability 'read_wiki_contents' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'read_wiki_contents' is unnamespaced

  [minor]   LOSSY              capabilities[read_wiki_structure].name
      Capability 'read_wiki_structure' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'read_wiki_structure' is unnamespaced


==============================================================================
PART 2  context7  (confidence: observed-serialization)
==============================================================================
  [major]   LOSSY              capabilities[query-docs].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; context7 exposes no output schema for this tool

  [major]   LOSSY              capabilities[resolve-library-id].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; context7 exposes no output schema for this tool

  [minor]   LOSSY              capabilities[query-docs].name
      Capability 'query-docs' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'query-docs' is unnamespaced

  [minor]   LOSSY              capabilities[resolve-library-id].name
      Capability 'resolve-library-id' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'resolve-library-id' is unnamespaced


==============================================================================
PART 2  adoraads-beauty-gateway  (confidence: observed-serialization)
==============================================================================
  [minor]   LOSSY              capabilities[brand_spotlight].name
      Capability 'brand_spotlight' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'brand_spotlight' is unnamespaced

  [minor]   LOSSY              capabilities[fire_billing_event].name
      Capability 'fire_billing_event' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'fire_billing_event' is unnamespaced

  [minor]   LOSSY              capabilities[get_shopper_prefs].name
      Capability 'get_shopper_prefs' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'get_shopper_prefs' is unnamespaced

  [minor]   LOSSY              capabilities[routine_builder].name
      Capability 'routine_builder' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'routine_builder' is unnamespaced

  [minor]   LOSSY              capabilities[skin_match].name
      Capability 'skin_match' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'skin_match' is unnamespaced

  [minor]   LOSSY              capabilities[sponsored_search].name
      Capability 'sponsored_search' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'sponsored_search' is unnamespaced


==============================================================================
TOTALS
==============================================================================
  spec/schema conflicts : 4
  cross-format findings : 40
  ----------------------------------------------------------------------------
  all findings          : 44
    blocker  1
    major    15
    minor    28

Caveat: the AutoGen entry models a documented constructor surface, not an
observed serialization. Findings derived from it are weaker evidence than
findings derived from the UACP-native entry, which is quoted from SPEC.md.
