Agent Security Gate v0.7.1 is ready for independent reproduction by an AI-security reviewer who did not author the code or evaluation.
Start with the security reviewer guide. The minimum clean-checkout path is:
git clone https://github.com/giselleevita/agent-security-gate
cd agent-security-gate
git checkout v0.7.1
python -m venv .venv
source .venv/bin/activate
python -m pip install --constraint requirements-dev.lock -e ".[dev,security]"
make verify
An author-assisted internal pre-review found and fixed a stored-XSS path in the approval console before this request was updated. That work is transparent but is not counted as independent validation. The report also records the known residual request-size/concurrency and strict-mode deployment risks.
Please report the source commit (00182b9cebb32cc967cf07674fe2bf8ed4c1d19f), platform, commands, deviations, verification result, protected-function allow/deny/tampering/OPA-down behavior, and any bypass or unsupported claim found. The slower local AgentDojo reproduction is optional and documented in the guide.
This issue is an invitation, not a validation claim. The repository remains candidate-authored until an independent reviewer reports a reproduction.
Agent Security Gate v0.7.1 is ready for independent reproduction by an AI-security reviewer who did not author the code or evaluation.
Start with the security reviewer guide. The minimum clean-checkout path is:
An author-assisted internal pre-review found and fixed a stored-XSS path in the approval console before this request was updated. That work is transparent but is not counted as independent validation. The report also records the known residual request-size/concurrency and strict-mode deployment risks.
Please report the source commit (
00182b9cebb32cc967cf07674fe2bf8ed4c1d19f), platform, commands, deviations, verification result, protected-function allow/deny/tampering/OPA-down behavior, and any bypass or unsupported claim found. The slower local AgentDojo reproduction is optional and documented in the guide.This issue is an invitation, not a validation claim. The repository remains candidate-authored until an independent reviewer reports a reproduction.