Summary
- The proposed
/.well-known/knowledge-linksetdocument lets an origin enumerate knowledge artefacts, attach relation types and optionally bind resources by digest, but it does not authenticate an author or grant an agent permission to follow instructions found in those resources. - Operators should split discovery, retrieval, byte verification, content classification and action authorisation into separate controls; a successful step must never silently satisfy the next one.
The agent had done everything its retrieval team asked. It resolved an approved domain, fetched /.well-known/knowledge-linkset, selected an artefact advertised as current guidance, downloaded the target and reproduced the published digest. The bytes matched exactly. The final paragraph then told the reader to run a command against a production control plane.
That is the moment at which a useful discovery protocol can become a dangerous authority shortcut. A matching digest answers a narrow question: did the client receive the byte sequence named by this discovery document? It does not answer who wrote the sequence, whether the writer speaks for the organisation, whether the proposition is true, whether the material remains licensed for the intended use, or whether the requesting agent is allowed to perform the described action. The correct result of the retrieval was not execution. It was a verified, origin-associated input waiting for a separate policy decision.
The distinction matters because the Internet-Draft submitted by Paul Besleaga on 30 September 2026 is deliberately ambitious about machine discovery. It proposes the registered well-known name knowledge-linkset and a JSON discovery representation in which an origin can publish typed links to knowledge artefacts. Links can describe formats, profiles, licences, update feeds, ledgers, graphs, skills, surfaces, boards and peer maps. The document can be compact enough for a machine to traverse and expressive enough to become the front door to a substantial knowledge estate.
The proposal is also deliberately modest about what that front door proves. Revision 00 is an active individual submission, not an IETF consensus document. It declares an intended Informational status. The requested well-known URI remains provisional, and the profile URI described by the draft follows a separate registration path. Those facts do not invalidate the design. They locate it correctly: a proposal for interoperable discovery, not a standards imprimatur for every resource it helps a client find.
One origin, two layers of control
RFC 8615 gives well-known URIs a predictable place under an origin. That predictability is operationally valuable. A client no longer needs a proprietary bootstrap endpoint or a search-engine guess. HTTPS and DNS can tell the client which origin answered, subject to the normal certificate, resolver and routing assumptions. HTTP semantics provide status codes, redirects, validators and cache controls. The linkset model in RFC 9264 and Web Linking in RFC 8288 provide a vocabulary for relations among resources.
None of those layers turns origin control into editorial identity. If an attacker or departed administrator controls both the discovery document and a target resource on the same origin, the attacker can replace the artefact and publish its new digest. Verification still succeeds because the two values agree. The digest has protected consistency inside the attacker’s newly controlled statement; it has not recovered the previous owner’s intent.
This is why the implementation boundary must be explicit. Transport authentication establishes the serving origin. A digest binds a representation to a value. An application profile can constrain syntax. An organisational trust store can recognise approved publishers. A workload policy can decide which operations are permitted. Those are five different assertions, maintained by different owners and failing in different ways.
The proposed document usefully supports digest-addressed links. RFC 9530 and RFC 9651 provide the contemporary HTTP vocabulary for content digests. Canonicalisation such as RFC 8785 can help when a profile specifies a canonical JSON representation. Yet canonicalisation is not a universal solvent. A verifier must know whether the digest covers transferred bytes, decoded content, a canonical form or some other representation. Compression, content negotiation and transformations can otherwise make honest systems disagree.
A missing digest should mean “not byte-verified by this mechanism,” not “malicious”; a mismatched digest should stop acceptance of that representation, not automatically establish who caused the mismatch.
Foreign prose remains foreign input
The most important implementation rule is simple: discovered content is data. A crawler may index it. A retrieval service may parse it. A language model may summarise it. None of those operations turns imperatives embedded in the material into instructions for the surrounding agent.
That boundary must survive relation labels such as skills, now or contribute. Relation names help classify why a link is present; they do not elevate the target into a privileged prompt channel. An artefact that says “ignore previous constraints,” “send credentials here,” or “execute this remediation” is still an untrusted object unless an independent authority system has approved both its publisher and the requested capability.
Good agent architecture therefore carries provenance alongside content and keeps control tokens out of the retrieved text. The execution service should receive a structured request: origin, final URL, redirect chain, media type, selected relation, digest result, fetch time, trust decision, requested capability and applicable policy version. It should not receive a flattened transcript in which system policy, operator instructions and discovered prose become indistinguishable paragraphs.
HTTP Message Signatures, described by RFC 9421, can add a cryptographic statement over selected message components. That may support stronger publisher identification when keys and covered fields are governed well. It still does not create permission by itself. A valid signature from a recognised party can establish who signed what; the local relying party must decide whether that signer is authorised for this artefact, this date, this tenant and this action.
The crawler is also a network client
A discovery graph is not merely a document format. It is a programme for issuing requests. Every peer relation, redirect and linked target can steer the client toward another network location. That creates the familiar server-side request forgery problem, complicated by DNS rebinding and address changes between resolution and connection.
An implementation should parse and normalise URLs before policy evaluation; allow only intended schemes; reject user-info tricks and ambiguous host forms; resolve names through a controlled resolver; block loopback, link-local, private, multicast and infrastructure metadata ranges unless explicitly authorised; and re-check the actual connected address after redirects and fresh resolution. Redirect hops need their own limit and policy evaluation. A public name that resolves to a public address during inspection and an internal address during connection must not cross the boundary unnoticed.
Traversal also needs a budget. The draft’s peer concept can support federation, but an agent should never interpret a peer walk as an exhaustive census. Depth, node count, byte count, wall-clock time, concurrency and per-origin request limits should all be finite. Cycles must be detected with normalised identifiers. When the budget is exhausted, the result is partial. “Not found within this bounded walk” is not evidence that an artefact does not exist.
Caching preserves another boundary. RFC 9111 lets a server describe freshness and revalidation, while validators such as ETag can reduce transfer. A 304 Not Modified says the selected representation is current relative to the server’s validator. It does not re-attest authorship or permission. Security-sensitive clients may need shorter freshness windows, explicit revalidation and retained copies of the discovery document that led to each decision. A new document version can remove a target while a cached target remains retrievable; operators should decide which event invalidates which decision.
Absence, succession and exposure
The proposal includes useful machinery for lifecycle. A tombstone can indicate that a knowledge node is gone and can point to a successor. The pointer should not be treated as identity continuity. The successor may have different operators, policies, licences, signing keys or semantics. Clients should preserve the old identifier and status, record the asserted successor relation, and perform fresh discovery and trust evaluation for the new node.
The same restraint applies to ledgers and update feeds. A ledger head can help detect replacement or rollback when a client remembers an earlier state. It cannot tell the client which competing history deserves trust without an external governance rule. A current pointer is evidence about what the origin publishes now, not proof that the published past is complete.
Publishing the map can itself disclose sensitive information. Even when the linked artefacts require authentication, a public discovery document may reveal their existence, names, media types, update cadence, relation counts or digests. Stable digests can allow an observer to test whether a guessed document is present. Operators should therefore be able to gate the discovery document, publish a deliberately reduced public view, omit sensitive digests and return different authorised views without pretending that all clients see a complete estate.
This produces a disciplined reading of knowledge-linkset. It is an origin-controlled statement about discoverable resources. It can make heterogeneous estates more legible. It can support deterministic retrieval and byte comparison. It can expose useful lifecycle relations. But it is not a claim that the origin authored every target, that every peer is safe, that a link is complete, or that a machine may obey the text it finds.
The design becomes more valuable, not less, when those limits are made visible. Discovery is composable precisely because it does not try to absorb identity, provenance, policy and execution into one magic document. The agent in the opening scenario should store the matching digest, label the prose as external evidence, identify the requested production capability and ask the authority service for a decision. A refusal at that final gate is not a failure of discovery. It is proof that the system understood what discovery was for.
Sources
- https://datatracker.ietf.org/doc/draft-besleaga-agentic-knowledge-wellknown/
- https://datatracker.ietf.org/doc/draft-besleaga-agentic-knowledge-wellknown/history/
- https://datatracker.ietf.org/api/v1/doc/document/draft-besleaga-agentic-knowledge-wellknown/
- https://datatracker.ietf.org/doc/draft-besleaga-agentic-knowledge-wellknown/references/
- https://datatracker.ietf.org/doc/draft-besleaga-agentic-knowledge-wellknown/referencedby/
- https://www.ietf.org/archive/id/draft-besleaga-agentic-knowledge-wellknown-00.txt
- https://www.ietf.org/archive/id/draft-besleaga-agentic-knowledge-wellknown-00.html
- https://www.ietf.org/archive/id/draft-besleaga-agentic-knowledge-wellknown-00.xml
- https://www.rfc-editor.org/rfc/rfc8615.html
- https://www.rfc-editor.org/rfc/rfc9264.html
- https://www.rfc-editor.org/rfc/rfc9530.html
- https://www.rfc-editor.org/rfc/rfc9651.html
- https://www.rfc-editor.org/rfc/rfc8785.html
- https://www.rfc-editor.org/rfc/rfc9110.html
- https://www.rfc-editor.org/rfc/rfc9111.html
- https://www.rfc-editor.org/rfc/rfc9421.html
- https://www.rfc-editor.org/rfc/rfc9727.html
- https://www.rfc-editor.org/rfc/rfc6906.html
- https://www.rfc-editor.org/rfc/rfc8288.html
- https://www.rfc-editor.org/rfc/rfc9309.html
- https://datatracker.ietf.org/doc/draft-arsentev-llm-context-discovery/
- https://datatracker.ietf.org/doc/draft-jimenez-dawn-discovery-landscape/
- https://www.iana.org/assignments/well-known-uris/well-known-uris.xhtml
- https://www.iana.org/assignments/link-relations/link-relations.xhtml
- https://agenticsystemcore.com/.well-known/knowledge-linkset
- https://agenticsystemcore.com/specs/
- https://heng.lu/on-reality-layers-symbolic-power-and-why-clarity-feels-so-hostile/
- https://heng.lu/minimum-initial-specification-localized-future-decision-voluntary-adoption-internet-coordination-system/
- https://heng.lu/running-code-primary-the-patch-needed-to-preserve-the-internet-original-design/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
