uacp-interop 0.16.0

  section                  findings  blocker  major  minor
  -----------------------  --------  -------  -----  -----
  uacp-spec                       4        0      2      2
  autogen-agentchat               6        0      4      2
  openai-function-calling         3        0      1      2
  uacp-native                     2        2      0      0
  -----------------------  --------  -------  -----  -----
  TOTAL                          15        2      7      6

  UACP spec: worst finding is major.
  Cross-format blockers are loss measured in foreign formats,
  which is what the harness is for, not a defect in UACP.
Provenance of corpus entries:
  autogen-agentchat        confidence=documented-api
  openai-function-calling  confidence=documented-api
  uacp-native              confidence=observed-serialization

==============================================================================
PART 1  UACP schema vs normative text, and schema vs the two reference implementations
==============================================================================
  [major]   SCHEMA_CONFLICT    schemas.$id/$ref
      The schema set cannot be resolved by a standards-compliant validator without network access. Relative $refs resolve against the schema's own $id, and every $id sits on a host that does not resolve, so even a plain sibling ref like 'capability.schema.json' becomes an unreachable URL. A validator then attempts a network fetch and fails with Unretrievable, which breaks air-gapped builds and any offline CI. Observed while building this harness: agent-descriptor ($id host wippa.dev) refs capability.schema.json -> https://wippa.dev/uacp/schemas/capability.schema.json
      evidence: uacp_interop had to construct a local referencing.Registry purely to validate the schemas at all

  [major]   UNVERIFIABLE_CLAIM unspecified safety property: cross_pipeline_cost_ceiling
      The spec is silent where it should not be. SPEC.md 15.6: agents and buses MAY enforce per-agent rate limits. No cross-pipeline ceiling is specified, and neither Bus implements one. Reported as a gap rather than an unimplemented claim: the spec makes rate limiting a MAY and says nothing about a pipeline-wide ceiling, so there is no claim to have failed. Two agents calling each other were measured at ~20k round trips/second, bounded only by the host recursion limit, and the caller received a success response with no indication the loop had been cut short.
      evidence: no cross-pipeline ceiling is defined in SPEC.md and neither Bus enforces one; measured behaviour rather than a source probe, so this is recorded as a gap in the specification

  [minor]   UNVERIFIABLE_CLAIM unverified security claim: acl_pattern_globbing
      This check needs the UACP source tree to confirm the claim is implemented. Set UACP_SOURCE_ROOT to a checkout to verify it; without it the claim is unverified, not passing.
      evidence: probe would read python/wippa_uacp/core/authz.py

  [minor]   UNVERIFIABLE_CLAIM unverified security claim: per_caller_acl_enforcement
      This check needs the UACP source tree to confirm the claim is implemented. Set UACP_SOURCE_ROOT to a checkout to verify it; without it the claim is unverified, not passing.
      evidence: probe would read python/wippa_uacp/core/bus.py


==============================================================================
PART 2  autogen-agentchat  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[web_search_func].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; autogen-agentchat exposes no output schema for this tool

  [major]   SEMANTIC_MISMATCH  lifecycle
      The source agent is stateful: run() mutates internal history and is documented as being called with new messages rather than complete history. A UACP descriptor has no lifecycle or state field, and the UACP envelope is stateless message passing, so two calls that look identical on the wire mean different things on either side.
      evidence: autogen-agentchat documents run() as stateful (microsoft.github.io/autogen AgentChat agents tutorial); UACP SPEC.md section 1 agent descriptor has no state field

  [major]   SEMANTIC_MISMATCH  streaming
      The source streams per-token chunks (ModelClientStreamingChunkEvent) that are part of the agent's own message trace. UACP stream messages are partial *results* correlated to a request via replyTo and sequence numbers. Mapping one onto the other conflates 'the agent's reasoning trace' with 'the result stream', so a UACP consumer would receive internal reasoning it never asked for and could not tell the two apart.
      evidence: autogen-agentchat emits per-token chunks in its output stream; UACP SPEC.md section 13 defines stream/stream.end as correlated partial results

  [major]   UNREPRESENTABLE    payload
      The source accepts heterogeneous content parts (for example MultiModalMessage(content=[str, Image])). The UACP envelope's payload is untyped, so a list would validate, but the spec defines no modality, media type or part ordering, and an in-memory Image object has no wire form. Nothing in UACP distinguishes this from an ordinary array payload.
      evidence: autogen-agentchat MultiModalMessage; UACP SPEC.md section 3 envelope fields define no content-part or modality construct

  [minor]   LOSSY              capabilities[web_search_func].name
      Capability 'web_search_func' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'web_search_func' is unnamespaced

  [minor]   LOSSY              capabilities[web_search_func].strict
      The source sets strict=False. JSON Schema has no equivalent of the OpenAI 'strict' flag, so the guarantee is dropped in either direction and cannot be re-expressed as a UACP consumer check.
      evidence: OpenAI function-calling tool shape vs JSON Schema (draft 2020-12); no 'strict' keyword exists in JSON Schema


==============================================================================
PART 2  openai-function-calling  (confidence: documented-api)
==============================================================================
  [major]   LOSSY              capabilities[get_weather].outputSchema
      UACP requires outputSchema on every capability. The source declares no output contract, so the adapter must fabricate a permissive one. Consumers will believe a guarantee the source never made.
      evidence: UACP capability.schema.json requires ['name','description','inputSchema','outputSchema']; openai-function-calling exposes no output schema for this tool

  [minor]   LOSSY              capabilities[get_weather].name
      Capability 'get_weather' carries no namespace prefix, so the adapter must rename it. Registry queries scoped to a namespace (for example 'data.*') will not match the original name.
      evidence: UACP SPEC.md section 2 requires dot-notation namespaces (csv, llm, web, deploy, data.*, custom allowed); source name 'get_weather' is unnamespaced

  [minor]   LOSSY              capabilities[get_weather].strict
      The source sets strict=True. JSON Schema has no equivalent of the OpenAI 'strict' flag, so the guarantee is dropped in either direction and cannot be re-expressed as a UACP consumer check.
      evidence: OpenAI function-calling tool shape vs JSON Schema (draft 2020-12); no 'strict' keyword exists in JSON Schema


==============================================================================
PART 2  uacp-native  (confidence: observed-serialization)
==============================================================================
  [BLOCKER] UNREPRESENTABLE    csv.analyze.inputSchema.const
      UACP capability uses JSON Schema keyword 'const' at $.oneOf[0].properties.mode.const, which has no representation in an OpenAI function-calling `parameters` block. The capability cannot be exposed to an OpenAI-style tool consumer without either dropping the constraint or flattening it into prose.
      evidence: $.oneOf[0].properties.mode.const in the UACP capability schema vs the OpenAI function-calling parameter subset

  [BLOCKER] UNREPRESENTABLE    csv.analyze.inputSchema.oneOf
      UACP capability uses JSON Schema keyword 'oneOf' at $.oneOf, which has no representation in an OpenAI function-calling `parameters` block. The capability cannot be exposed to an OpenAI-style tool consumer without either dropping the constraint or flattening it into prose.
      evidence: $.oneOf in the UACP capability schema vs the OpenAI function-calling parameter subset


==============================================================================
TOTALS
==============================================================================
  spec/schema conflicts : 4
  cross-format findings : 11
  ----------------------------------------------------------------------------
  all findings          : 15
    blocker  2
    major    7
    minor    6

Caveat: the AutoGen entry models a documented constructor surface, not an
observed serialization. Findings derived from it are weaker evidence than
findings derived from the UACP-native entry, which is quoted from SPEC.md.
