Radar / AI security / VERA
VERA: zero-trust reference implementation for AI agents
Open-source reference implementation of the CSA Agentic Trust Framework spec: 12 microservices for agent identity, behavior monitoring, and data governance, plus a maturity-model runtime where agents earn autonomy through promotion gates.
Why it matters
The ATF spec has no reference implementation - this is the first. Policy-as-code segmentation, auto-containment circuit breaker, and 25 contract validation tests, all MIT licensed.
What you could build with it
A regulated company can adopt VERA's promotion gates so new agents start read-only and earn write access only after passing validation checks.
Does it hold up?
Too early to judge - announced on HN today with 1 star; the 25 contract tests are verifiable, but no independent production usage exists yet.
Built with VERA
- Show HN launch discussionhn · HN thread on the launch; author answering architecture questions on the 12-service design and ATF spec mapping.
Learn more
First spotted on hn: source.
More AI security
Cloudflare security-audit-skill: multi-phase security audits for coding agentsA coding-agent skill that runs multi-phase security audits with independently verified, machine-checkable findings.security · JEV 0.63Sandlock 0.8.8: deferred commit for agent sandboxesThe process-based Linux AI sandbox (no container, no VM) ships deferred commit: every run returns a changeset of what…security · JEV 0.56ClawSecure: free security scanner for OpenClaw AI agent skillsFree scanner that audits OpenClaw agent skills for vulnerabilities; the maker's audit of 2,890+ OpenClaw skills found…security · JEV 0.5Google DeepMind SynthID BioWatermarking technology that embeds an imperceptible, verifiable signature into AI-designed protein sequences and…security · JEV 0.49GitHub Security Lab Taskflow Agent: autonomous LLM fuzzing for C/C++Open-source agent that automates the full fuzzing lifecycle - entry-point discovery, harness generation, AFL++ runs…security · JEV 0.47LLM Agents Can Easily Tamper With Their Own TracesAn empirical study (arXiv 2026-09-24) showing that all tested local coding-agent harnesses except Muse Code allowed…security · JEV 0.4
Get the week's best AI launches, plus 3 ideas worth building
One email every Saturday. Ranked by traction, not hype. Free.