Some Traverse capabilities carry third-party model weights inside their WASM artifact, and the registry redistributes those artifacts publicly. So a fair question from anyone wiring one into a product is: am I allowed to use this model commercially? The usual answer in open source is “read the README and the upstream license.” That doesn't hold up once an agent is the one picking the capability.
+ +This post walks the chain Traverse uses instead, from authoring to the host, and is plain about which links are shipped and which are still open.
+ +1. Authoring: the contract carries an ai record
+ +You still author capabilities skill-first with traverse-capability-author; you don't need to write Rust. For a model-backed capability, the contract's ai object names each model with an immutable upstream pin (a full commit id, not a branch or tag), an SPDX license expression, and the rights fields the registry requires.
2. Publish: rejected offline, before any registry write
+ +As of traverse#1597, traverse-cli capability publish rejects an ai object offline when registry CI would reject it on rules the contract alone can decide: object-shaped models when model_backed is true, commit pins, SPDX syntax, and the rights-record shape. Each failure uses the same error code registry CI uses. It also keeps the ai object verbatim in the generated registry contract, where it used to be dropped. Proving evidence bytes and rights drift stays in registry CI, because the CLI doesn't fetch from the network.
Honest status: this is on Traverse main, merged after v0.14.0, and isn't in a tagged release yet. Details: Does capability publish validate model attribution?
3. Registry: a signed rights record
+ +Registry spec 026 makes every newly added model-backed contract declare commercial_use, redistribution and derivatives for each model, as allowed, forbidden or conditional. unknown fails, because the registry won't redistribute weights on unknown rights. LICENSE and NOTICE files are pinned by sha256, any conversion of the weights (like quantization) is recorded with its digest, and the contract bytes themselves are signed with the registry key, so the rights fields are authenticated and not just the WASM.
The index then projects a usage_class per model: unrestricted, evaluation-only or conditional, and the consumer guidance is deny-by-default on conditional. That's a field an agent can filter on at discover time instead of a paragraph it has to interpret. More: Does the registry record model rights?
What it is not: a legal certification. The signature proves the maintainer's declaration wasn't altered. It doesn't prove the declaration is right, and it isn't legal advice.
+ +4. Host: trust roots belong to the host
+ +Traverse v0.14.0 shipped signed model packages (schema 2.0.0 manifests plus a detached Ed25519 model.sig.json). The app pins the manifest digest and the expected rights; the host owns the trusted keys, and apps can't inject their own. A naked URL is never identity. Exact-ref execute runs on native Rust, the web embedder and Swift today; Kotlin and .NET don't execute exact-ref yet. See How do hosts trust signed models?
What's still open (as of October 6, 2026)
+ +-
+
- Runtime enforcement. Showing the full rights record in
traverse-cli, honoringrevokedat runtime, and verifying the contract signature are tracked in traverse#1598. Not in a release yet.
+ - Existing model-backed agents. Published versions are never judged retroactively; compliant new MINOR versions are tracked in registry#623. +
- Production model signing. The first trained package,
digits-mlp-1.0.0, uses a test-only key. Key custody, rotation and revocation are traverse#1567. See Is production model signing ready?
+
Why bother
+ +When a person picks a library, a README is fine. When an agent proposes a capability, the rights question has to be answerable from data the runtime can check, at the same moment it checks the contract. That's the whole idea: the rule lives in one governed place, and every host reads the same answer.
+ +If you're building a model-backed capability and want to help close one of the open items above, the tickets are linked and the door for first-time contributors is open: How do I contribute?
+ +