Yes. This is exactly the right attack, and it’s the one the whole design hinges on.
A receipt the agent writes about itself is a fancier log, full stop. A verifiable receipt is one anyone can recompute, and that’s the whole difference. AER-1 doesn’t ask you to trust the author. The fingerprint commits to the exact input and output bytes, so you don’t take the agent’s word for anything, you redo the math. And the offline verifier means you don’t have to trust us either.
But you’re pointing at the real remaining hole: if the agent lies about what it saw, the receipt faithfully records the lie. Receipts kill tampering, not fabrication at the source. Nobody honest should claim otherwise.
The partial answer is independent witnessing: anchor the fingerprint somewhere the agent doesn’t control (we do this on Nostr), so the lie, if there is one, sits on a public record with a timestamp instead of in a private log nobody can audit. It doesn’t make lying impossible. It makes lying checkable, which is what changes the incentives.
"Proof of data is the independent record, not a longer log" — keeping that line. It’s better than anything in the article.