Agentic blueprints run with real permissions: reading files, calling APIs, executing shell commands. metafactory is built so that what you install is something a named human has already put their reputation behind. Six mechanics carry that weight.
Every publisher on metafactory is a verified identity. No anonymous uploads, no ghost accounts, no disposable aliases. Five tiers (○ ◐ ● ◆ ★) make trust visible at a glance, and you can always trace a blueprint to a human you can read about.
A first blueprint from an unknown operator never ships alone. A named sponsor, someone already trusted on the shelf, has read the code, checked the capability declarations, and put their own reputation behind the submission.
Filesystem, shell, network, secrets, subagents: every capability a blueprint needs is listed in its manifest, justified by the steward in plain language, and surfaced in a full-width audit panel on the blueprint's page. No hidden access.
Every release is content-addressed — like a wax seal on a letter. The fingerprint is computed at publish time, stored in the registry, and displayed on the blueprint page. If the seal is broken, arc refuses to install.
Every release index is signed by metafactory — like a letterhead on the envelope that holds the sealed letters. When arc fetches the index, it verifies the signature against a key it already knows. A compromised mirror or man-in-the-middle can't slip a fingerprint into the list.
Each published release carries a cryptographic attestation tied to the author's identity, recorded in a public transparency log. You can verify not just that metafactory approved a release, but that a specific person built it — and even we can't rewrite the record.
Every publisher starts at New. Each tier unlocks new capabilities and responsibilities. Progression requires sustained, verifiable contributions and human review at every step.
Can browse and install. Submissions require full sponsor review. An explicit "not verified" warning is shown.
Identity confirmed. MFA enabled, GitHub account linked, verified by an existing trusted member.
Track record established through sustained contributions. Can review other publishers' work.
Security-aware operator who can sponsor new contributors into the ecosystem.
Governance authority. Promotes operators, coordinates security response, shapes ecosystem policy.
No MFA, no badge. Multi-factor authentication is required before any tier beyond New. Hardware keys are recommended for Trusted and above.
No one publishes alone. Every new contributor needs a sponsor who has read the code and put their reputation behind it.
metafactory is not a sandbox, not a code audit service, and not a guarantee of correctness. It is an identity-anchored trust network: blueprints come from named people, are vouched for by other named people, declare what they do, and are addressed by their contents. The six mechanics above are the whole trust model. Everything else on this site is a consequence.
Every blueprint passes through ten stages — from the author's first arc bundle to the consumer's arc install. Each stage has an owner, a gate, and a design decision that anchors it.