Activity

Where your energy went, across every repo.

scanned 3w ago
435 commits in the last 13 weeks

Most active repos

7 shown

By type

events
435events
  • Commits435

Commits per week

Daily heatmap · last 13 weeks

4w ago
fix(telemetry): report lab usage from the server path (#70)damn-vulnerable-ai-agent
docs: correct a false claim about the collector's live stategithub-analytics-tracker
fix(telemetry): fail loudly when collection stops, and detect a drained feed (#24)github-analytics-tracker
chore: mark 0.19.1 released (hotfix off v0.19.0); baseline bumpsecretless
secretless-ai 0.19.1homebrew-tap
broker profile: two active suites per AAP-SPEC 0.4 (ML-DSA-65 Active, RFC 9964) (#10)agent-authorization-protocol
Do not store a declaration whose consent was revoked mid-lookupai-browserguard
Measure the delete obligation in bytes on disk, not live entriesai-browserguard
Scope the in-memory clear to the opted-out branchai-browserguard
Settle an outstanding declaration delete on every worker startai-browserguard
Classify AI_SAFETY_CLEAR; make an unroutable message type fail CIai-browserguard
Test the opt-out by outcome; keep the warning and give it an actionai-browserguard
Close the truncation-spoof class; make opt-out failure reach the userai-browserguard
fix(telemetry): suppress telemetry in CI and under DO_NOT_TRACK (#240)opena2a
Fix negative-cache eviction, prove the gate fails closedai-browserguard
fix(hook): full-command parse (no quote-truncation) + vault exec -- env guard (#99) (#102)secretless
Bind a declaration to the origin it was read fromai-browserguard
Read site ai-safety.txt declarations on agent detection (ADR-009)ai-browserguard
feat(broker): ML-DSA-65 and hybrid Ed25519+ML-DSA-65 assertion minting (RFC 9964) (#101)secretless
conformance: pin AAP_SPEC_REF to the 0.4.0-draft merge SHAaap-conformance
+16 more
4w ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
auth: gate agent credential + SDK download routes to member (JWT) accessagent-identity-management
feat(auth): allow machine API keys to register agents via a narrow gate (#341)agent-identity-management
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
docs: move Updates detail into CHANGELOG.md; one-line README table (#23)oasb
release: @opena2a/oasb 0.4.0oasb
fix: author the package entry point; document the library surface (#22)oasb
Release hardening: idempotent publish, smoke harness, honest hackmyagent pin (#21)oasb
docs: add CONTRIBUTING.md and Contributing section to README (#20)oasb
docs: tighten README enforcement-scope section (#56)ai-browserguard
Release 0.5.0: ADR-008 enforcement scope (#55)ai-browserguard
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
Scope enforcement to in-page automation; add report observation scope; real tab-close kill switch (ADR-008) (#54)ai-browserguard
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
Fix attack-log response attribution race under concurrent same-agent requests (#58) (#69)damn-vulnerable-ai-agent
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: add .hmaignore for the signature/fixture corpusaiis-signatures
v0.3.0: DAN + ROLE-INJECT precision, self-contained validation CI (#5)aiis-signatures
chore(cli): bump hackmyagent pin 0.24.0 -> 0.25.0 + re-bake corpus goldens (#239)opena2a
chore: bump hackmyagent pin 0.24.0 -> 0.25.0 + rebaseline repo corpus goldens (#67)ai-trust
hackmyagent 0.25.0: update formula url + sha256homebrew-tap
fix(scanner): handle async EPIPE on git check-ignore/ls-files stdin (#264)hackmyagent
release: 0.25.0 — bump @opena2a/aim-sdk to 1.0.2 (atx-verify 0.3.0), stamp changelog (#263)hackmyagent
release: @opena2a/atx-verify 0.4.0 (#238)opena2a
fix(unicode-tag-block): exclude regional flag emoji from Tag-block detection (#4)aiis-signatures
fix(release-smoke): resolve corpus parity reference from the pinned hackmyagent (#237)opena2a
fix(deps): bump jackson-databind and x/crypto/x/net for HIGH CVEs (#340)agent-identity-management
chore: update analytics data [skip ci]github-analytics-tracker
fix(cli): init detects credential-shaped values in template env files (#227)opena2a
chore: point published contact email to info@opena2a.org (#235)opena2a
chore: point published contact email to info@opena2a.org (#339)agent-identity-management
chore: point published contact email to info@opena2a.org (#94)secretless
chore: point published contact email to info@opena2a.org (#258)hackmyagent
chore: point published contact email to info@opena2a.org (#66)ai-trust
chore: point published contact email to info@opena2a.orgnanomind
chore: point published contact email to info@opena2a.orgmcp-security-checklist
+1 more
1mo ago
Align DID Document shape and syntax notes with DID Core (#5)did-method-opena2a
spec: status -> registered (did-extensions #717 merged)did-method-opena2a
Stop treating security-taxonomy documents as credential access (AST-CRED-002/003) (#256)hackmyagent
Move ai-safety.txt draft to its own repo (opena2a-standards/ai-safety-txt)agent-authorization-protocol
Move ai-safety.txt draft to its own repo (opena2a-standards/ai-safety-txt)agent-authorization-protocol
Add pre-push opt-out marker (matches sibling spec repos)ai-safety-txt
Add the IETF Internet-Draft (rendered text)ai-safety-txt
Add the IETF Internet-Draft (RFCXML source)ai-safety-txt
Describe the ai-safety.txt specai-safety-txt
Initial commitai-safety-txt
Change security contact email to info@opena2a.orgopena2a
Add author postal country (US) to match the datatracker submissionagent-authorization-protocol
Add author postal country (US) to match the datatracker submissionagent-authorization-protocol
Add author postal country (US) to match the datatracker submissionagent-authorization-protocol
Add author postal country (US) to match the datatracker submissionagent-authorization-protocol
fix(atx-verify): release-test P3 batch — anchor-fault diagnostics, exports map, type/doc precision (#234)opena2a
Add `opena2a admin sensors` enrollment-inbox operator command (#224)opena2a
sdk-ts: bump @opena2a/atx-verify to 0.3.0 (1.0.1 -> 1.0.2) (#338)agent-identity-management
feat(broker): strict-parse grant request bodies; bump @opena2a/atx-verify to 0.3.0 (#93)secretless
fix(atx-verify): release-test findings — verify() null guard, mldsaPresent on reject, reason wording (#233)opena2a
+21 more
1mo ago
Merge pull request #336 from opena2a-org/fix/aim-sdk-101-batch-arp-livefireagent-identity-management
sdk-ts: fix localhost hint for empty AIM_BASE_URL; align harness port labelsagent-identity-management
sdk-ts: v1.0.1 — bump version + README snippet clarityagent-identity-management
sdk-ts: batch 1.0.x deferred fixes + enable ARP live-fire harnessesagent-identity-management
Strict-parse the credential: duplicate members reject as PARSE_ERROR at any depth (#15)atx-conformance
aap-conformance: fixture suite and Node+Python reference verifiers for the AAP token canonical formaap-conformance
docs(analyst): add MLX Apple-Silicon GPU path; correct GGUF Metal guidance (#40)nanomind
Pin the token canonical form: JWS ratified from the reference broker (#5)agent-authorization-protocol
fix(broker): mint trust_class from the matched policy clause, not the scope (#92)secretless
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
fix(sdk-ts): make the Fastify plugin work through fastify.register + close packaging gaps (#331)agent-identity-management
Bump pinned atx-conformance ref to 18-fixture suite; vendor degenerate declaredPurpose fixtures (#333)agent-identity-management
Align reference verifiers on degenerate declaredPurpose; pin with fixtures (#14)atx-conformance
Persist execution_isolation and excluded_factors on trust scores (#332)agent-identity-management
docs(analyst): sync MODEL-CARD.md to the published HF card restructure (#39)nanomind
Add keyless cosign of MANIFEST.sha256 on every main push (#10)a2a-idf-conformance
Add keyless cosign of MANIFEST.sha256 on every main push (#7)aip-conformance
Add keyless cosign of MANIFEST.sha256 on every main push (#8)atp-conformance
Add keyless cosign of MANIFEST.sha256 on every main push (#13)atx-conformance
Upgrade section 3.2 to the family-wide shared resource-type registry (#4)did-method-opena2a
Wire fixture schema validation against the vendored AIP-SPEC schemas (#6)aip-conformance
Wire fixture schema validation against the vendored ATP-SPEC schemas (#7)atp-conformance
Wire fixture schema validation against the vendored atx-spec credential schema (#12)atx-conformance
docs(analyst): correct fp-suppression to ~77% and gate to threshold 0.90 (#38)nanomind
Add grant-reference schema; document what blocks the remaining AAP schemas (#4)agent-authorization-protocol
fix(telemetry): point SDK default endpoint at the canonical ingest path (#225)opena2a
Merge pull request #9 from opena2a-standards/feat/integrate-hippo-fixturesa2a-idf-conformance
Pin hippo-rfc9421 snapshot fixtures: MANIFEST + profile regen, READMEa2a-idf-conformance
Merge hippo-rfc9421 composition fixtures (#2)a2a-idf-conformance
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
docs: normalize authorship to family convention; backfill changelog (#3)agent-authorization-protocol
Suite hardening: byte-pin, level fixtures, negatives, CI, parity, profile (#8)a2a-idf-conformance
AIP §6.1 composition rule with anti-gaming ceiling + atx-conformance CI gate (#330)agent-identity-management
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
ci: add fan-in CI Gate so the full test suite can be a required check (#328)agent-identity-management
chore: update analytics data [skip ci]github-analytics-tracker
Name Secretless as the AAP broker reference implementation (#2)agent-authorization-protocol
Add ARP runtime-protection module at @opena2a/aim-sdk/arp (#329)agent-identity-management
Conformance CI, cross-impl parity gate, and machine-readable profile (#5)aip-conformance
Conformance CI, cross-impl parity gate, and machine-readable profile (#10)atx-conformance
v0.2: negative fixtures, conformance CI, cross-impl parity gate, machine-readable profile (#6)atp-conformance
docs: correct reference-verifier coverage claim and ATX expansion (#3)did-method-opena2a
profile: add did:opena2a, AAP, and the ATP/AIP conformance suites; fix technique countstandards-dotgithub
README: align Scoring section with scoring.md and conformance.mdagent-governance-spec
Fix Matrix Overview counts (57->61) and populate empty tactic technique tablesagent-threat-matrix
feat(telemetry): headline sybil-dampened engaged users on the dashboard (#23)github-analytics-tracker
fix(telemetry): correct REGISTRY_URL example to the real prod API domain (#22)github-analytics-tracker
feat(telemetry): ingest first-party CLI active-user telemetry (#21)github-analytics-tracker
Merge pull request #20 from opena2a-org/feat/chrome-web-store-trackinggithub-analytics-tracker
Merge remote-tracking branch 'origin/main' into feat/chrome-web-store-trackinggithub-analytics-tracker
Add Chrome Web Store tracking for BrowserGuardgithub-analytics-tracker
Add Weaver-validated decision operation: model+framework patch, runnable scenario, coverage reportotel-semconv-agent-identity
Add runnable invariant validation for the decision operation scenariootel-semconv-agent-identity
Add agent authorization decision operation proposal scaffoldotel-semconv-agent-identity
+5 more
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
ci: make Go Lint (security) always report so it can be a required check (#327)agent-identity-management
ci: make Go security linters blocking; fix authenticated config-path file read (#326)agent-identity-management
ci: make Go linting actually run (golangci-lint v2 + action v8) (#325)agent-identity-management
feat(fga): emit gen_ai.agent.* authorization attributes on the fga.authorize span (#324)agent-identity-management
feat(telemetry): add `arp telemetry register` sensor enrollment (#248)hackmyagent
docs(gap-analysis): add IETF prior-art and naming section (#8)agent-identity-protocol
chore: update analytics data [skip ci]github-analytics-tracker
feat(arp): G6 — wire opt-out to registry right-to-delete purge (#247)hackmyagent
1mo ago
feat(arp): structural signature telemetry producer (default-on, opt-out) (#246)hackmyagent
Fix comply() bare-string overload, AWS secret-key detection, scan help, bare decorators (#18)aicomply
Add agent-grid screenshot + fix Multi-Step table identifier wrapping (#68)damn-vulnerable-ai-agent
Refresh the Docker Hub overview (DOCKER_README) (#67)damn-vulnerable-ai-agent
Make the all-ports docker run the hero command (#66)damn-vulnerable-ai-agent
Clean CLI output for 0.9.2: remove em dashes, fix stale --help agent list (#65)damn-vulnerable-ai-agent
Release v0.9.2: one-port quickstart (#64)damn-vulnerable-ai-agent
Proxy Attack Lab chat through the dashboard so one port is enough (#63)damn-vulnerable-ai-agent
Mark semantic Guard as preview (measured benign FP); fix Python daemon hint + version drift (#17)aicomply
Simplify docker run: collapse agent ports into one 7001-7021 range (#62)damn-vulnerable-ai-agent
Remove remaining em dashes across the dashboard (#61)damn-vulnerable-ai-agent
Document dashboard storytelling with screenshots; remove em dashes (#60)damn-vulnerable-ai-agent
Expose FlightBot ports (7017/7018) in Docker config (#59)damn-vulnerable-ai-agent
Attack storytelling UX: show what leaked and how to defend (#57)damn-vulnerable-ai-agent
Merge pull request #19 from opena2a-org/fix/pypi-tool-attributiongithub-analytics-tracker
Attribute discovered PyPI packages to their toolgithub-analytics-tracker
Merge pull request #18 from opena2a-org/feat/pypi-auto-discoverygithub-analytics-tracker
Auto-discover PyPI packages from GitHub org reposgithub-analytics-tracker
Merge pull request #17 from opena2a-org/fix/track-aicomply-pypi-2github-analytics-tracker
Track aicomply on PyPIgithub-analytics-tracker
+1 more
1mo ago
Merge pull request #15 from opena2a-org/fix/canonical-dedupgithub-analytics-tracker
Regenerate analytics with canonical dedup on merged datagithub-analytics-tracker
Merge remote-tracking branch 'origin/main' into fix/canonical-repo-dedupgithub-analytics-tracker
Collapse transferred/renamed repo twins by canonical full_namegithub-analytics-tracker
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
feat(daemon): add explicit classify/abstain signal to /v1/infer (#131) (#36) (#37)nanomind
feat(fga): add Step 5 intent-check observability metrics (#131) (#322)agent-identity-management
fix(trust): MCP drift alerts now affect the connected agent's trust score (#314) (#321)agent-identity-management
fix(mcp-drift): atomic well-known recompute + operator alert on drift (#313)agent-identity-management
feat(sdk): async-refreshed revocation cache + Java verify benchmark (#317) (#318)agent-identity-management
feat(fga): consume daemon classify/abstain signal in Step 5 intent check (#131) (#323)agent-identity-management
feat(daemon): add explicit classify/abstain signal to /v1/infer (#131) (#36)nanomind
Fix AIM Cloud sync: move HasCapabilityNoAlert to a synced file (#320)agent-identity-management
Fix AIM Cloud sync: move raiseHoneytokenAlert to a synced file (#319)agent-identity-management
Add SDK isolation attestation ingest and surface the isolation factor (#311)agent-identity-management
Format isolation attestation test fixtures with gofmtaim-score-followups
Merge remote-tracking branch 'origin/main' into feat/aim-isolation-ingestaim-score-followups
chore: update analytics data [skip ci]github-analytics-tracker
feat(capabilities): honeytoken capabilities — alert + audit on verification (#293) (#316)aim-score-followups
feat(capabilities): honeytoken capabilities — alert + audit on verification (#293) (#316)agent-identity-management
1mo ago
Merge remote-tracking branch 'origin/main' into feat/aim-isolation-ingestaim-score-followups
Rename ATC client to ATCClient to avoid cloud-build collision (#315)aim-score-followups
Rename ATC client to ATCClient to avoid cloud-build collision (#315)agent-identity-management
Rename ATC client to ATCClient to avoid cloud-build collisionaim-atx
Add Agent Trust Credential issuance delegating to the Registry (#312)aim-score-followups
Add Agent Trust Credential issuance delegating to the Registry (#312)aim-atx
Add Agent Trust Credential issuance delegating to the Registry (#312)agent-identity-management
chore: update analytics data [skip ci]github-analytics-tracker
1mo ago
Add SDK isolation attestation ingest and surface the isolation factoraim-score-followups
Wire the 9-factor agent trust score to real data sourcesaim-score-followups
Harden otel-demo smoke script: reach Postgres over published portaim-score-followups
Wire the 9-factor agent trust score to real data sourcesaim-atx
Harden otel-demo smoke script: reach Postgres over published portaim-atx
Wire the 9-factor agent trust score to real data sourcesagent-identity-management
Harden otel-demo smoke script: reach Postgres over published portagent-identity-management
Revise README with latest version detailsai-browserguard
chore: update analytics data [skip ci]github-analytics-tracker
Rename dashboard heading to 'Security Overview' (#304)aim-score-followups
Rename dashboard heading to 'Security Overview' (#304)aim-atx
Rename dashboard heading to 'Security Overview' (#304)agent-identity-management
Server-side token revocation on logout + opt-in CORS preview origins (#307)aim-score-followups
Server-side token revocation on logout + opt-in CORS preview origins (#307)aim-atx
Server-side token revocation on logout + opt-in CORS preview origins (#307)agent-identity-management
1mo ago
Retire empty-typ grace on the access path (keep it for refresh) (#309)aim-score-followups
Retire empty-typ grace on the access path (keep it for refresh) (#309)aim-atx
Retire empty-typ grace on the access path (keep it for refresh) (#309)agent-identity-management
Run vitest once in sdk/typescript test script (#303)aim-score-followups
Run vitest once in sdk/typescript test script (#303)aim-atx
Run vitest once in sdk/typescript test script (#303)agent-identity-management
Separate access vs refresh tokens with a typ claim (grace rollout) (#308)aim-score-followups
Separate access vs refresh tokens with a typ claim (grace rollout) (#308)aim-atx
Separate access vs refresh tokens with a typ claim (grace rollout) (#308)agent-identity-management
Harden auth: block SDK tokens as bearer, idle/absolute session timeout, org name in /auth/me (#305)aim-score-followups
Harden auth: block SDK tokens as bearer, idle/absolute session timeout, org name in /auth/me (#305)aim-atx
Harden auth: block SDK tokens as bearer, idle/absolute session timeout, org name in /auth/me (#305)agent-identity-management
ai-trust 0.7.6: update formula url + sha256homebrew-tap
0.7.6ai-trust
chore: update analytics data [skip ci]github-analytics-tracker
chore: bump hackmyagent 0.17.1 -> 0.23.11 (exact pin) + rebaseline corpus goldens (#64)ai-trust
1mo ago
docs(detect): clarify that machine-wide discovery always runs (#245)hackmyagent
chore(deps): bump hackmyagent 0.23.6 -> 0.23.11 (#223)opena2a
hackmyagent 0.23.11homebrew-tap
chore(release): hackmyagent 0.23.11hackmyagent
docs(changelog): cut 0.23.11 release sectionhackmyagent
fix(scanner): MEM-006 no longer FPs on local render-array push (#244)hackmyagent
fix(scanner): make GIT-003 .env severity content-aware (#242) (#243)hackmyagent
fix(review): reconcile verdict line with composite band (#221) (#222)opena2a
py: re-export guard_io/guard_output at top level + document raw original_content (#16)aicomply
opena2a 0.10.11: comply detects bare provider keys (aicomply 2.2.0)homebrew-tap
opena2a-cli 0.10.11: bump @opena2a/aicomply 2.1.0 -> 2.2.0 (comply detects sk-ant) (#220)opena2a
docs([private]): cross-link aicomply as content-compliance companion (#302)aim-score-followups
docs([private]): cross-link aicomply as content-compliance companion (#302)aim-atx
docs([private]): cross-link aicomply as content-compliance companion (#302)agent-identity-management
docs: cross-link aicomply in Links section (#63)ai-trust
docs: cross-link aicomply in Links section (#91)secretless
docs: cross-link aicomply in Links section (#241)hackmyagent
fix(review): adoption is a recovery opportunity, not a composite penalty (#219)opena2a
feat(regex): detect bare provider API keys (sk-ant, sk-proj, sk-or-v1, sk-) (#15)aicomply
fix(review): dominant-analyzer floor — direction-agreement verdict for #175 (#218)opena2a
+12 more
1mo ago
chore: update analytics data [skip ci]github-analytics-tracker