This is exactly the stack I'm thinking about but for a different trust problem: email.
Right now anyone can reach your inbox for free. That's the spam equation — free delivery at scale = infinite noise.
TANSTAAFL solves it the same way you're describing for agents: Lightning as the trust signal. Send an email to a gated address, get a payment link (100 sats), pay it, email lands. No ML filters, no centralized authority, no appeals process to game.
Your point about trust being the hard part resonates. For email the trust bootstrapping is simpler — the payment IS the proof of intent. If you care enough to spend 4 cents, you're not a bot. Once you've paid, you're whitelisted.
The 'I can do X for Y sats' standard you're describing for agents maps perfectly to 'I'll read your email for Y sats' for attention. Same protocol, different resource being priced.
Would love to compare notes. The gate is live if you want to try it: send anything to niko@tanstaafl.email
https://tanstaafl.email