AI-agent security incidents
When an AI-agent security incident occurs, this page carries dated, verifiable observations from the register about the named entities — what we saw, when. Silence means no evidence, never no coverage.
What this page is
An incident-evidence surface, not a news feed and not an advisory. For an incident touching AI-agent coordination, MCP/tool infrastructure, schema/supply-chain mutation, or the takeover of an identifier whose owner no longer publishes, we extract the named entities (npm / MCP / GitHub Action / org), probe the register's dated archive, and publish an evidence set in which every claim maps to a concrete dated row with an ?as_of= link anyone can re-derive. Where the archive holds no dated row for a named entity, we publish no evidence rather than a guess. It ranks nothing, recommends nothing, and predicts nothing — it dates what the register saw.
Why an external record. Internal logs and transcripts are produced by the system under scrutiny and can be altered by it — transcript manipulation and tool-call spoofing are documented. This record is maintained outside the observed system, hash-chained and externally anchored — the observer cannot be rewritten by the observed.
Method & relevance
Candidate items are scored 0–100 against four dimensions — agent coordination, MCP/tool infrastructure, schema/supply-chain mutation, temporal reconstruction — from a documented, auditable keyword model (threshold 70); the score is never a black box. Evidence is the register's own dated observations; a claim with no mappable dated row becomes NO_EVIDENCE, split into pre-coverage (before we began observing that population) vs tracked-but-absent. Fabrication is a critical error, never a fallback. Verify any dated observation at /verify; corrections at /dispute.
Coverage declaration
Continuous dated observation began, per population, on:
| population | observed since |
|---|---|
| MCP servers — repository liveness/mortality | 2026-07-22 |
| MCP tool schemas — declared-contract changes | 2026-08-13 |
| npm packages | 2026-07-31 |
| GitHub Actions | 2026-08-01 |
| HuggingFace models | 2026-08-19 |
| Dependency graph (who-depends-on-whom) | 2026-04-14 |
Coverage is never backfilled: an observation is asserted only for a date on or after the start above. “No evidence before the start date” is a statement about our coverage window, not about the entity.
Incident records (LSI series)
5 published record(s). Machine-readable: feed.json. Methodology.
| id | class | subject | observation window |
|---|---|---|---|
| LSI-2026-0011 | 1 | app.dailystudio/teleprompter | 2026-08-20 → 2026-08-21 |
| LSI-2026-0010 | 1 | app.cannonstudio/cannon-studio | 2026-09-13 → 2026-09-14 |
| LSI-2026-0009 | 1 | com.ksaworks/goldseam | 2026-09-11 → 2026-09-13 |
| LSI-2026-0008 | 1 | ai.aislabs/gateway | 2026-08-31 → 2026-09-01 |
| LSI-2026-0006 | 1 | com.immersivecommons/floor10 | 2026-09-01 → 2026-09-02 |
Published incident evidence
No incident evidence has been published yet. Silence means no evidence, never no coverage — the populations below are under continuous dated observation; this page fills only when the register holds verifiable dated rows about the named entities in an incident.
These are factual observation records derived from dated snapshots of publicly declared, machine-readable material. They contain no assessment of fault, intent, or fitness for purpose. Corrections and context: /dispute.
Dataset (CC-BY-4.0, chain-anchored): Zenodo. See also the State of the Agent Economy report.