{
  "markdown": "# 🕸️ Weave_Protocol\n\n**Infrastructure security for AI agents. We attack what we defend.**\n\n[![npm](https://img.shields.io/npm/v/@weave_protocol/cli.svg?label=cli)](https://www.npmjs.com/package/@weave_protocol/cli)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/cli.svg)](https://www.npmjs.com/package/@weave_protocol/cli)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/full.svg?label=full)](https://www.npmjs.com/package/@weave_protocol/full)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/full.svg)](https://www.npmjs.com/package/@weave_protocol/full)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/ward.svg?label=ward)](https://www.npmjs.com/package/@weave_protocol/ward)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/ward.svg)](https://www.npmjs.com/package/@weave_protocol/ward)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/adversary.svg?label=adversary&color=red)](https://www.npmjs.com/package/@weave_protocol/adversary)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/adversary.svg)](https://www.npmjs.com/package/@weave_protocol/adversary)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/agentsecbench.svg?label=agentsecbench&color=red)](https://www.npmjs.com/package/@weave_protocol/agentsecbench)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/agentsecbench.svg)](https://www.npmjs.com/package/@weave_protocol/agentsecbench)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/browser.svg?label=browser)](https://www.npmjs.com/package/@weave_protocol/browser)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/browser.svg)](https://www.npmjs.com/package/@weave_protocol/browser)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/adapter-claudecode.svg?label=adapter-claudecode)](https://www.npmjs.com/package/@weave_protocol/adapter-claudecode)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/adapter-claudecode.svg)](https://www.npmjs.com/package/@weave_protocol/adapter-claudecode)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/adapter-antigravity.svg?label=adapter-antigravity)](https://www.npmjs.com/package/@weave_protocol/adapter-antigravity)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/adapter-antigravity.svg)](https://www.npmjs.com/package/@weave_protocol/adapter-antigravity)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/adapter-msaf.svg?label=adapter-msaf)](https://www.npmjs.com/package/@weave_protocol/adapter-msaf)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/adapter-msaf.svg)](https://www.npmjs.com/package/@weave_protocol/adapter-msaf)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/hundredmen.svg?label=hundredmen)](https://www.npmjs.com/package/@weave_protocol/hundredmen)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/hundredmen.svg)](https://www.npmjs.com/package/@weave_protocol/hundredmen)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/mund.svg?label=mund)](https://www.npmjs.com/package/@weave_protocol/mund)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/mund.svg)](https://www.npmjs.com/package/@weave_protocol/mund)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/hord.svg?label=hord)](https://www.npmjs.com/package/@weave_protocol/hord)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/hord.svg)](https://www.npmjs.com/package/@weave_protocol/hord)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/domere.svg?label=domere)](https://www.npmjs.com/package/@weave_protocol/domere)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/domere.svg)](https://www.npmjs.com/package/@weave_protocol/domere)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/witan.svg?label=witan)](https://www.npmjs.com/package/@weave_protocol/witan)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/witan.svg)](https://www.npmjs.com/package/@weave_protocol/witan)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/tollere.svg?label=tollere)](https://www.npmjs.com/package/@weave_protocol/tollere)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/tollere.svg)](https://www.npmjs.com/package/@weave_protocol/tollere)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/yoxallismus.svg?label=yoxallismus&color=red)](https://www.npmjs.com/package/@weave_protocol/yoxallismus)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/yoxallismus.svg)](https://www.npmjs.com/package/@weave_protocol/yoxallismus)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/langchain.svg?label=langchain)](https://www.npmjs.com/package/@weave_protocol/langchain)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/langchain.svg)](https://www.npmjs.com/package/@weave_protocol/langchain)\n[![npm](https://img.shields.io/npm/v/@weave_protocol/api.svg?label=api)](https://www.npmjs.com/package/@weave_protocol/api)\n[![npm](https://img.shields.io/npm/dm/@weave_protocol/api.svg)](https://www.npmjs.com/package/@weave_protocol/api)\n[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)\n\nMake agent behavior verifiable, auditable, and cryptographically provable across any harness, any platform. Built as a TypeScript monorepo with MCP integration, blockchain anchoring, and — as of Q4 — a **published red-team engine that tests our own defenses**.\n\n> **The thesis:** every security platform claims its defenses work. We're the first to publish the attacks that prove it. Same suite. Same scorecard. Same locked benchmark — applied to our own packages, every release.\n\n---\n\n## 🚀 Get started in one command\n\n```bash\nnpx @weave_protocol/cli init\n```\n\nThe CLI detects your framework (LangChain, LlamaIndex, MCP, OpenAI, Anthropic, Microsoft, Google) and scaffolds the right security middleware for your stack. Or install everything at once:\n\n```bash\nnpm install @weave_protocol/full\n```\n\n---\n\n## 🆕 What's New\n\n### ⚔️ Q4 Moat Quarter — *we attack what we defend*\n\nThe first agent security platform to publish its own offensive engine. Two new packages flipped the suite from purely defensive to **defense + offense in the same monorepo**, validated against each other:\n\n| Package | Role | Version |\n|---|---|---|\n| [`@weave_protocol/adversary`](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary) | Offensive engine — 68 documented + novel attacks across 5 categories (IPI, tool-coercion, jailbreak, extraction, goal-corruption). Real Playwright browser target with 4 breach signal channels. Real-LLM demo mode via Anthropic API. | ✅ **v0.2.1** |\n| [`@weave_protocol/agentsecbench`](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench) | Standardized benchmark — locked attack suites, tier grades A–F, paste-ready reports, side-by-side comparison | ✅ v0.1.0 |\n\n**Trophy attacks** — documented in-the-wild incidents reproduced in the corpus:\n\n- 🏦 **Atlan autonomous-fraud** (Dec 2025) — first documented agent-driven financial fraud\n- 🔒 **EchoLeak** (CVE-2025-32711) — Microsoft Copilot zero-click exfil\n- 👻 **Brave/Comet OTP exfil** (2025) — browser agent secret leak via hidden CSS\n- 🚫 **Forcepoint false copyright** (Apr 2026) — DoS via fake copyright claim\n\n```bash\n# Run the canonical benchmark against the demo target — proves the suite lands\nnpx @weave_protocol/agentsecbench run\n\n# Or run the full 68-attack corpus directly\nnpx @weave_protocol/adversary demo\n```\n\n**Why this matters:** every model release, every WARD policy change, every adapter update can be re-benchmarked against the same locked suite. Did your score regress? `agentsecbench compare` will show you. Does your WARD policy actually defend anything? `--measure-ward-delta` will tell you. This is how a category gets defined.\n\n**[See Adversary README →](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary)** · **[See AgentSecBench README →](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench)** · **[See METHODOLOGY.md →](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench/METHODOLOGY.md)**\n\n---\n\n### 💰 Q4 Governance — autonomous spending caps\n\nEvery enterprise agent question today is *\"what's my ceiling on this thing?\"* — measured in dollars, not just tool calls. [`@weave_protocol/witan@1.1.0`](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan) answers it. Per-window budgets (run / hour / day / week / month) that gate LLM calls and tool calls, with three actions: **block**, **require approval/consensus**, or **notify**.\n\nMulti-provider LLM pricing built in — Anthropic, OpenAI, Google, and local (free). Per-tool amount caps (`send_payment` max $500/day). Interactive TTY approval prompt for human-in-loop terminals. Async callback for Slack/PagerDuty/custom UIs. Safe defaults — never silent approval in non-interactive contexts.\n\n```bash\nnpx @weave_protocol/witan@1.1.0 spending caps         # inspect WARD.md caps\nnpx @weave_protocol/witan@1.1.0 spending simulate     # dry-run scenarios\n```\n\n```yaml\n# Extend your WARD.md:\nspending_limits:\n  - window: day\n    budget: { usd: 5.00 }\n    on_exceeded: require_approval\n  - window: run\n    budget: { tool_calls: 100 }\n    on_exceeded: block\n  - window: day\n    budget:\n      tools:\n        send_payment: { max_amount_usd: 500 }\n    on_exceeded: require_approval\n```\n\nBackward compatible with the existing `behavioral_limits.maxCostUSD`. In-memory storage in v1.1 with a pluggable interface for the v1.2 Redis/SQLite backends. Programmatic API via `import { SpendingTracker } from '@weave_protocol/witan/spending'`.\n\n**[See Witan spending caps README →](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan#-autonomous-spending-caps-v110)**\n\n---\n\n### 🔐 Yoxallismus v2 — post-quantum cipher (open beta)\n\n[`@weave_protocol/yoxallismus@0.1.0-beta.0`](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus) — post-quantum cryptographic composition layer built on **NIST FIPS 203 (ML-KEM-768)** hybridized with X25519. AES-256-GCM AEAD, HKDF-SHA-256 KDF, symmetric ratchet for session forward secrecy. Composition, not invention — the primitives are NIST-standardized, the composition (PQ-hybrid KEM + agent-scoped context binding + ratcheting) is what's new.\n\n```bash\n# Explicit opt-in required — the beta tag is NOT installed by default\nnpm install @weave_protocol/yoxallismus@beta\n```\n\n```typescript\nimport { PQCipher } from '@weave_protocol/yoxallismus';\n\nconst alice = PQCipher.generateKeypair();\nconst bundle = PQCipher.encryptTo(PQCipher.publicKeyOf(alice), plaintext);\nconst message = PQCipher.decryptFrom(alice, bundle.ciphertext, bundle.payload);\n```\n\n**⚠️ EXPERIMENTAL — NOT AUDITED.** Do not use for regulated, medical, financial, or legal data. Validation is via public use, forks, community verification, and responsible disclosure — not paid audit. See [THREAT_MODEL.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/THREAT_MODEL.md) and [SECURITY.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/SECURITY.md) before adopting.\n\n**Verify every claim yourself:**\n\n```bash\nnpx @weave_protocol/yoxallismus@beta --package weave-yoxall test         # 13 reproducible-claims tests\nnpx @weave_protocol/yoxallismus@beta --package weave-yoxall audit-self   # 5 known-attack vectors\nnpx @weave_protocol/yoxallismus@beta --package weave-yoxall benchmark    # perf micro-benchmarks\n```\n\nMeasured on Node 22, single-threaded: **3.1 ms hybrid keypair generation · 2.4 ms encap+decap · 0.024 ms AEAD (1 KB)** — comfortably under the <5 ms target.\n\n**[See Yoxallismus README →](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus)**\n\n---\n\n### 🛡️ Four runtimes. Three vendors. One policy file.\n\nThe thesis was that [WARD.md](https://www.npmjs.com/package/@weave_protocol/ward) could be a **portable agent security standard** — write it once, enforce it everywhere. As of today, that's **shipped and live across the entire agent harness landscape**:\n\n| Runtime | Vendor | Enforcer | Status |\n|---|---|---|---|\n| **MCP servers** | Open standard | [Hundredmen v1.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/hundredmen) | ✅ Live on npm |\n| **Claude Code** | Anthropic | [adapter-claudecode v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-claudecode) | ✅ Live on npm |\n| **Google Antigravity** (desktop + `agy` CLI + SDK) | Google | [adapter-antigravity v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-antigravity) | ✅ Live on npm |\n| **Microsoft Agent Framework** | Microsoft | [adapter-msaf v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-msaf) | ✅ Live on npm |\n| **Browser agents** | Open standard | [browser v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser) | ✅ Live on npm |\n\nThe same `WARD.md` file in your project root is now read and enforced by **Anthropic's, Google's, Microsoft's, MCP's, and the browser harness's runtimes** — without any platform-specific edits.\n\n```\nmy-agent-project/\n├── AGENTS.md          # what the agent does\n├── SKILL.md           # how the agent does it\n└── WARD.md            # what the agent can't do  ← all five surfaces respect this\n```\n\n---\n\n### 🌐 Browser agent security (Q3) — fifth enforcement surface\n\n[`@weave_protocol/browser`](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser) adds runtime IPI (indirect prompt injection) scanning to browser-driving agents. 33 detection patterns cover the documented threat surface: hidden CSS payloads, role-hijack directives, tool-call mimicry, action-injection directives, payment-recipient proximity patterns (Atlan), copyright-DoS markers (Forcepoint), and more.\n\nPair with the [Browser Guard extension](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser-extension) for client-side visibility into what your agent sees vs. what you see.\n\n**[See browser README →](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser)**\n\n---\n\n### 📊 State of AI Agent Security: Q3 2026 Report\n\nIndustry analysis of agent security trends, platform maturity, supply chain risks, and market gaps. Live at: **[tyox-all.github.io/Weave_Protocol/q3-2026.html](https://tyox-all.github.io/Weave_Protocol/q3-2026.html)**\n\n---\n\n### Previously shipped (Q3)\n\n- **adapter-msaf v0.1.0** — Microsoft Agent Framework enforcement via middleware. `WardMiddleware` class, one-line integration, Azure credential heuristic.\n- **adapter-antigravity v0.1.0** — Google Antigravity enforcement. One install protects desktop + `agy` CLI + SDK.\n- **adapter-claudecode v0.1.0** — Claude Code enforcement via PreToolUse hooks.\n- **Hundredmen v1.1.0** — WARD.md is now the first gate in the MCP decision flow, ahead of reputation/drift/approval.\n- **WARD.md v0.1.0** — Agent security policy standard. Ten domains: filesystem, network, capabilities, data boundaries, behavioral limits, multi-agent, compliance, verification, threat model, incident response. [Spec →](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward/SPEC.md)\n- **Tollere v0.2.2** — Multi-channel supply chain security. npm, PyPI, Cargo, Go, Maven, Docker Hub, VS Code Marketplace, Open VSX, JetBrains. Sandwich pattern detection.\n- **Weave CLI v0.1.0 + Full Bundle v0.1.0** — `weave init` / `audit` / `dashboard` / `doctor`. One-command security setup.\n\n---\n\n## 📦 Packages\n\nThe suite is now organized into three layers — **defense**, **offensive**, and **operations**. All 17 packages live on npm under the `@weave_protocol` scope, plus one Python package on PyPI.\n\n### 🛡️ Defense Layer (12 packages)\n\nThe packages that keep your agent within policy: declare it, enforce it across every harness, scan everything that enters, encrypt everything that exits.\n\n| Package | Version | Description |\n|---|---|---|\n| [🛡️ @weave_protocol/ward](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward) | 0.1.0 | **WARD.md** — agent security policy standard (parser, validator, runtime checks) |\n| [🛡️ @weave_protocol/adapter-claudecode](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-claudecode) | 0.1.0 | **Claude Code adapter** — enforces WARD.md via PreToolUse hooks |\n| [🛡️ @weave_protocol/adapter-antigravity](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-antigravity) | 0.1.0 | **Google Antigravity adapter** — enforces WARD.md across desktop, `agy` CLI, and SDK |\n| [🛡️ @weave_protocol/adapter-msaf](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-msaf) | 0.1.0 | **Microsoft Agent Framework adapter** — middleware-based WARD enforcement |\n| [🌐 @weave_protocol/browser](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser) | 0.1.0 | **Browser agent security** — runtime IPI scanner (33 patterns) for headless agents |\n| [🔍 @weave_protocol/hundredmen](https://github.com/Tyox-all/Weave_Protocol/blob/main/hundredmen) | 1.1.0 | **MCP proxy** — intercept, scan, gate tool calls; enforces WARD.md as first gate |\n| [🛡️ @weave_protocol/mund](https://github.com/Tyox-all/Weave_Protocol/blob/main/mund) | 0.2.2 | **Scanner** — secrets, PII, injection, MCP vetting, threat intel |\n| [🏛️ @weave_protocol/hord](https://github.com/Tyox-all/Weave_Protocol/blob/main/hord) | 0.1.6 | **Vault** — encrypted storage with Yoxallismus dual-tumbler cipher |\n| [🔐 @weave_protocol/yoxallismus](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus) | **0.1.0-beta.0** | **Post-quantum cipher** — X25519 + ML-KEM-768 hybrid KEM · AES-256-GCM · HKDF · ratcheting · ⚠️ NOT AUDITED |\n| [⚖️ @weave_protocol/domere](https://github.com/Tyox-all/Weave_Protocol/blob/main/domere) | 1.3.4 | **Judge** — compliance (PCI-DSS, ISO27001, SOC2, HIPAA, GDPR, CCPA), blockchain anchoring |\n| [👥 @weave_protocol/witan](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan) | **1.1.0** | **Council** — multi-agent consensus & governance, autonomous spending caps (Q4 v1.1) |\n| [🛂 @weave_protocol/tollere](https://github.com/Tyox-all/Weave_Protocol/blob/main/tollere) | 0.2.2 | **Customs** — supply chain security (npm, PyPI, Docker, IDE extensions, sandwich detection) |\n\n### ⚔️ Offensive Layer (2 packages) — **NEW Q4**\n\nThe red team. We attack what we defend.\n\n| Package | Version | Description |\n|---|---|---|\n| [⚔️ @weave_protocol/adversary](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary) | **0.2.1** | **Offensive engine** — 68 attacks · real Playwright browser target · real-LLM demo mode · WARD-aware attack selection |\n| [🎯 @weave_protocol/agentsecbench](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench) | **0.1.0** | **Standardized benchmark** — locked suites (ASB-Browser-v1), tier grading A–F, trophy attacks, WARD delta, paste-ready reports |\n\n### 🔧 Operations & Integrations (5 packages, plus 1 PyPI)\n\nThe front door, the dashboard, the bridges to other frameworks.\n\n| Package | Version | Description |\n|---|---|---|\n| [🕸️ @weave_protocol/cli](https://github.com/Tyox-all/Weave_Protocol/blob/main/cli) | 0.1.0 | **The `weave` CLI** — `init`, `audit`, `dashboard`, `doctor` |\n| [📦 @weave_protocol/full](https://github.com/Tyox-all/Weave_Protocol/blob/main/full) | 0.1.0 | **Bundle** — installs all packages in one command |\n| [🔌 @weave_protocol/api](https://github.com/Tyox-all/Weave_Protocol/blob/main/api) | 1.1.1 | **REST API + Operator Dashboard** — `npx @weave_protocol/api` → http://localhost:3000/dashboard |\n| [🔗 @weave_protocol/langchain](https://github.com/Tyox-all/Weave_Protocol/blob/main/langchain) | **1.0.2** | **LangChain.js** security callbacks & tool wrappers (0 audit vulnerabilities via npm overrides) |\n| [🐍 weave-protocol-llamaindex](https://github.com/Tyox-all/Weave_Protocol/blob/main/llamaindex-py) | 0.1.0 | **Python/LlamaIndex** security callbacks & tools (on PyPI) |\n\n---\n\n## 🤖 AI Agent Skills\n\nEach package includes a `SKILL.md` file following the [Claude Agent Skills specification](https://docs.anthropic.com/en/docs/claude-code/skills). These teach AI agents how to use Weave Protocol tools effectively.\n\n| Package | Skill Name | Triggers |\n|---|---|---|\n| 🕸️ CLI | `weave-cli` | set up Weave, init project, scaffold security, audit, dashboard, doctor |\n| 🛡️ Ward | `ward` | WARD.md, agent security policy, guardrails, lock down agent |\n| 🛡️ adapter-claudecode | `adapter-claudecode` | secure Claude Code, install WARD hooks, block Claude Code actions |\n| 🛡️ adapter-antigravity | `adapter-antigravity` | secure Antigravity, agy hooks, block GCP credential reads |\n| 🛡️ adapter-msaf | `adapter-msaf` | secure MSAF agent, WardMiddleware, lock down Copilot SDK, Azure enforcement |\n| 🌐 browser | `browser-security` | secure browser agent, IPI scanning, hidden CSS detection, page-context safety |\n| 🛡️ Mund | `security-scanning` | scan, detect secrets, check injection, vet MCP server, threat intel |\n| 🏛️ Hord | `encrypting-data` | encrypt, decrypt, vault, Yoxallismus, protect |\n| 🔐 Yoxallismus | `pq-crypto` | post-quantum, ML-KEM, Kyber, hybrid KEM, PQ-hybrid, quantum-safe |\n| ⚖️ Domere | `compliance-auditing` | audit, checkpoint, SOC2, HIPAA, PCI-DSS, GDPR, CCPA, blockchain |\n| 👥 Witan | `consensus-governance` | consensus, vote, approve, policy, escalate |\n| 🔍 Hundredmen | `security-inspection` | intercept, drift, reputation, approve, block, live feed, enforce WARD |\n| 🛂 Tollere | `supply-chain-security` | npm install, docker pull, install extension, typosquat, CVE, sandwich pattern |\n| ⚔️ Adversary | `adversarial-testing` | red-team agent, attack, penetration test, find vulnerabilities, IPI test, run attack corpus |\n| 🎯 AgentSecBench | `security-benchmarking` | benchmark agent, security score, tier grade, ASB-Browser, citable security report, compare runs |\n| 🔗 Langchain | `langchain-security` | LangChain, callback, secure tool, RAG security, PII redaction |\n| 🔌 API | `weave-api-calling` | REST API, HTTP endpoint, curl, fetch |\n\n**Installation:**\n\nThe SKILL.md format is shared across Claude Code and Antigravity, so the same files work for both — only the install path differs.\n\n```bash\ngit clone https://github.com/Tyox-all/Weave_Protocol.git\ncd Weave_Protocol\n\n# For Claude Code:\nmkdir -p ~/.claude/skills/weave-protocol\ncp */SKILL.md ~/.claude/skills/weave-protocol/\n\n# For Google Antigravity (global, all sessions):\nmkdir -p ~/.gemini/antigravity-cli/skills/weave-protocol\ncp */SKILL.md ~/.gemini/antigravity-cli/skills/weave-protocol/\n\n# Or per-project under .agents/:\nmkdir -p .agents/skills/weave-protocol\ncp /path/to/Weave_Protocol/*/SKILL.md .agents/skills/weave-protocol/\n```\n\nFor **Microsoft Agent Framework**, skills aren't used — MSAF is code-level. Use the `WardMiddleware` class from `@weave_protocol/adapter-msaf` instead.\n\n---\n\n## 🚀 Quick Start\n\n### Option 1: Guided setup (recommended)\n\n```bash\nnpx @weave_protocol/cli init\n```\n\n### Option 2: Install everything\n\n```bash\nnpm install @weave_protocol/full\n```\n\n### Option 3: Install individual packages\n\n```bash\nnpm install @weave_protocol/mund @weave_protocol/tollere @weave_protocol/ward\n```\n\n### Option 4: Benchmark first, defend second\n\n```bash\n# See what attacks land on your agent before you start hardening\nnpx @weave_protocol/agentsecbench run --measure-ward-delta\n```\n\n### Claude Desktop Integration (MCP)\n\nAdd to `claude_desktop_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"mund\":       { \"command\": \"npx\", \"args\": [\"-y\", \"@weave_protocol/mund\"] },\n    \"hord\":       { \"command\": \"npx\", \"args\": [\"-y\", \"@weave_protocol/hord\"] },\n    \"domere\":     { \"command\": \"npx\", \"args\": [\"-y\", \"@weave_protocol/domere\"] },\n    \"hundredmen\": { \"command\": \"npx\", \"args\": [\"-y\", \"@weave_protocol/hundredmen\"] },\n    \"tollere\":    { \"command\": \"npx\", \"args\": [\"-y\", \"@weave_protocol/tollere\"] }\n  }\n}\n```\n\n### Claude Code / Antigravity / MSAF Integration\n\n```bash\n# Anthropic\nnpm install -g @weave_protocol/adapter-claudecode && weave-claude-code init\n\n# Google\nnpm install -g @weave_protocol/adapter-antigravity && weave-antigravity init\n\n# Microsoft (code-level)\nnpm install @weave_protocol/adapter-msaf\n```\n\n```typescript\nimport { WardMiddleware } from '@weave_protocol/adapter-msaf';\nconst ward = new WardMiddleware();\nagent.useFunctionMiddleware(ward.functionMiddleware());\n```\n\nDrop a `WARD.md` in your project root. Any (or all) of the adapters will gate every tool call.\n\n---\n\n## ✨ Package Details\n\n### 🕸️ CLI — One Command for Everything\n\n```bash\nnpx @weave_protocol/cli init        # detect framework, scaffold middleware\nnpx @weave_protocol/cli audit       # supply chain scan (Tollere)\nnpx @weave_protocol/cli dashboard   # launch monitoring UI\nnpx @weave_protocol/cli doctor      # environment health check\n```\n\n📄 **Skill:** [`weave-cli`](https://github.com/Tyox-all/Weave_Protocol/blob/main/cli/SKILL.md)\n\n---\n\n### 🛡️ Ward — The Policy Standard\n\nWARD.md files declare what an agent is allowed to do, version-controlled alongside `AGENTS.md` and `SKILL.md`.\n\n| Section | Controls |\n|---|---|\n| **Filesystem** | Read/write/execute/delete/list rules with glob patterns |\n| **Network** | Outbound HTTP allowlist with optional method restrictions |\n| **Capabilities** | Tools the agent may invoke (with optional approval gating) |\n| **Data Boundaries** | Egress classifications (PII, PHI, credentials...) and redaction |\n| **Behavioral Limits** | Iterations, runtime, cost, tokens, tool calls |\n| **Multi-Agent** | Trust chain, isolation level, semantic drift threshold |\n| **Compliance** | SOC2 / HIPAA / GDPR / CCPA / ISO27001 / PCI-DSS |\n| **Verification** | Attestation backend (Dōmere), blockchain, frequency |\n| **Threat Model** | In-scope / out-of-scope threats |\n| **Incident Response** | Actions on violation (log / alert / terminate / attest) |\n\nEnforced at runtime by five independent surfaces: Hundredmen (MCP), adapter-claudecode (Claude Code), adapter-antigravity (Antigravity), adapter-msaf (Microsoft Agent Framework), and browser (Browser agents).\n\n📄 **Skill:** [`ward`](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward/SKILL.md) · 📋 **Spec:** [WARD.md SPEC →](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward/SPEC.md)\n\n---\n\n### 🛡️ The Harness Adapters\n\nAll four enforcement surfaces share the same WARD.md file. Pick the adapter(s) for your harness:\n\n- **[adapter-claudecode](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-claudecode)** — Claude Code via PreToolUse hooks\n- **[adapter-antigravity](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-antigravity)** — Google Antigravity (one install, three surfaces)\n- **[adapter-msaf](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-msaf)** — Microsoft Agent Framework via middleware\n- **[browser](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser)** — Browser agents (Playwright/Stagehand/Puppeteer-driven), 33-pattern IPI scanner\n\nWARD resolution (all adapters): `$WEAVE_WARD_PATH` → `<cwd>/WARD.md` → `<cwd>/.weave/WARD.md` → harness-specific user-global location.\n\n---\n\n### 🛡️ Mund — The Guardian\n\nReal-time security scanning for AI agents. Catches secrets (30+ patterns), PII, prompt injection, dangerous code, malicious MCP server descriptions. Threat intel auto-updates from community feeds.\n\n📄 **Skill:** [`security-scanning`](https://github.com/Tyox-all/Weave_Protocol/blob/main/mund/SKILL.md)\n\n---\n\n### 🏛️ Hord — The Vault\n\nEncrypted storage with the Yoxallismus dual-tumbler cipher. AES-256-GCM, ChaCha20-Poly1305, Argon2id key derivation, secure memory handling.\n\n📄 **Skill:** [`encrypting-data`](https://github.com/Tyox-all/Weave_Protocol/blob/main/hord/SKILL.md)\n\n---\n\n### 🔐 Yoxallismus — Post-Quantum Cipher (open beta)\n\nStandalone post-quantum cryptographic composition layer. NIST FIPS 203 (ML-KEM-768) hybridized with X25519 for the KEM, AES-256-GCM for AEAD, HKDF-SHA-256 for KDF, symmetric ratchet for session forward secrecy. Composition over invention — all primitives NIST-standardized or de facto industry standard.\n\n⚠️ **EXPERIMENTAL. NOT AUDITED.** Do not use for regulated, medical, financial, or legal data. Validation is via public use, forks, and responsible disclosure — not paid audit.\n\n```bash\n# Explicit opt-in required — beta tag not installed by default\nnpm install @weave_protocol/yoxallismus@beta\n\n# CLI subcommands\nweave-yoxall status         # library posture + known limitations\nweave-yoxall keygen         # hybrid keypair (X25519 + ML-KEM-768)\nweave-yoxall encrypt        # encrypt to a recipient's public key\nweave-yoxall decrypt        # decrypt with private key\nweave-yoxall test           # reproducible-claims tests\nweave-yoxall audit-self     # known-attack test vectors\nweave-yoxall benchmark      # perf micro-benchmarks\n```\n\n**Performance** — 3.1 ms hybrid keypair generation · 2.4 ms encap+decap · 0.024 ms AEAD (1 KB), all under the <5 ms target.\n\n📄 **Skill:** [`pq-crypto`](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/SKILL.md) · 📋 **Threat model:** [THREAT_MODEL.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/THREAT_MODEL.md) · 🔒 **Disclosure:** [SECURITY.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/SECURITY.md)\n\n---\n\n### ⚖️ Domere — The Judge\n\nEnterprise-grade verification, orchestration, compliance, and audit infrastructure. SOC2, HIPAA, PCI-DSS, ISO27001, GDPR, CCPA. Solana and Ethereum blockchain anchoring for immutable audit trails.\n\n**Blockchain Anchoring:**\n\n- Solana Mainnet: `6g7raTAHU2h331VKtfVtkS5pmuvR8vMYwjGsZF1CUj2o`\n- Solana Devnet: `BeCYVJYfbUu3k2TPGmh9VoGWeJwzm2hg2NdtnvbdBNCj`\n- Ethereum: `0xAA8b52adD3CEce6269d14C6335a79df451543820`\n\n📄 **Skill:** [`compliance-auditing`](https://github.com/Tyox-all/Weave_Protocol/blob/main/domere/SKILL.md)\n\n---\n\n### 👥 Witan — The Council\n\nMulti-agent consensus and governance. Unanimous, majority, weighted, and quorum protocols. Rule enforcement, escalation, agent bus.\n\n**New in v1.1.0** — autonomous spending caps. Per-window budgets on LLM cost, tokens, tool calls, and per-tool spend limits. Gated by three actions: `block`, `require_approval`, `notify`. Multi-provider LLM pricing built in (Anthropic, OpenAI, Google, local). Interactive TTY prompt or async callback for approval workflows. Safe defaults for non-interactive contexts.\n\n```bash\nnpx @weave_protocol/witan spending caps        # inspect WARD.md spending caps\nnpx @weave_protocol/witan spending simulate    # dry-run scenarios\n```\n\n```typescript\nimport { SpendingTracker } from '@weave_protocol/witan/spending';\n\nconst tracker = new SpendingTracker({\n  caps: [{ window: 'day', budget: { usd: 5.00 }, onExceeded: 'require_approval' }],\n});\nconst check = await tracker.checkAction({ kind: 'tool', tool: 'send_payment', amountUSD: 1000 });\nif (check.blocked) throw new Error(check.reason);\nif (check.requiresApproval && !(await check.approve!())) throw new Error('denied');\n```\n\n📄 **Skill:** [`consensus-governance`](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan/SKILL.md)\n\n---\n\n### 🔍 Hundredmen — The Watchers\n\nReal-time MCP security proxy. v1.1.0 enforces WARD.md as the first gate in the decision flow, ahead of reputation, drift, and approval checks.\n\n📄 **Skill:** [`security-inspection`](https://github.com/Tyox-all/Weave_Protocol/blob/main/hundredmen/SKILL.md)\n\n---\n\n### 🛂 Tollere — The Customs Inspector\n\nSupply chain security for AI-generated code. Catches malicious packages, Docker images, and IDE extensions **before** they reach `node_modules/`, your container, or your editor. npm, PyPI, Cargo, Go, Maven, Docker Hub, VS Code Marketplace, Open VSX, JetBrains.\n\n📄 **Skill:** [`supply-chain-security`](https://github.com/Tyox-all/Weave_Protocol/blob/main/tollere/SKILL.md)\n\n---\n\n### ⚔️ Adversary — The Red Team\n\nWhere the other packages defend, Adversary attacks. 68 documented and novel attacks across 5 categories: IPI (33), tool-use coercion (15), jailbreak (10), extraction (5), goal corruption (5). Three targets: pattern-mock (CI smoke tests, no API), real-LLM (`--real` via Anthropic API, ~$0.02/full run), and real-browser (Playwright with four breach signal channels: network, form, DOM, console). WARD-aware attack selection prioritizes probes against capabilities your policy claims to enforce.\n\n```bash\nnpx @weave_protocol/adversary demo               # mock, ~50ms\nnpx @weave_protocol/adversary demo --real        # real LLM, ~$0.02\nnpx @weave_protocol/adversary attack --url=...   # real browser agent\nnpx @weave_protocol/adversary demo --real --redact-evidence   # shareable scorecard\n```\n\nLocked scorecard schema v1.0 — consumed unchanged by AgentSecBench.\n\n📄 **Skill:** [`adversarial-testing`](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary/SKILL.md)\n\n---\n\n### 🎯 AgentSecBench — The Benchmark\n\nThe interpretation layer on top of Adversary. Locked, versioned attack suites that produce tier-graded reports. `ASB-Browser-v1` (v1.0) is 40 curated attacks: all 33 IPI + 4 critical tool-coercion + 3 highest-impact extraction.\n\n```bash\nnpx @weave_protocol/agentsecbench run                          # default suite, tier-graded report\nnpx @weave_protocol/agentsecbench run --measure-ward-delta     # quantify policy effectiveness\nnpx @weave_protocol/agentsecbench compare baseline.json new.json\n```\n\nTier grades A–F, four trophy attacks (Atlan, EchoLeak, Brave/Comet, Forcepoint), category gap analysis, optional WARD delta, plain-English interpretation prose. Reports are paste-ready Markdown — for blog posts, RFP responses, vendor audits, internal reviews.\n\n📄 **Skill:** [`security-benchmarking`](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench/SKILL.md) · 📋 **Methodology:** [METHODOLOGY.md →](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench/METHODOLOGY.md)\n\n---\n\n### 🔌 API + Operator Dashboard\n\n```bash\nnpx @weave_protocol/api\n# → http://localhost:3000/dashboard\n```\n\nLive monitoring across all five enforcement surfaces in one view. The dashboard renders WARD.md at the top of a hierarchy diagram, fanning out to your configured enforcers (Hundredmen + the three vendor adapters + browser). Surfaces you're not using appear dimmed, so it's instantly clear what's protecting your agent versus what's available.\n\nIncludes a live activity feed (allows / denies / IPI detections / approvals), a WARD policy panel, and 24-hour aggregate stats. Auto-refreshes every 5 seconds. Monochrome design — built for ops rooms, not marketing decks.\n\n📄 **Skill:** [`weave-api-calling`](https://github.com/Tyox-all/Weave_Protocol/blob/main/api/SKILL.md)\n\n---\n\n### 🔗 Langchain — The Bridge\n\nSecurity integration for LangChain.js applications. Drop-in callbacks, secured tool wrappers, RAG retriever scanning with PII redaction.\n\n📄 **Skill:** [`langchain-security`](https://github.com/Tyox-all/Weave_Protocol/blob/main/langchain/SKILL.md)\n\n---\n\n## 🏗️ Architecture\n\n```mermaid\nflowchart TD\n    CLI[\"🕸️ <b>weave init / audit</b><br/><i>front door — @weave_protocol/cli</i>\"]\n    WARD[\"🛡️ <b>WARD.md</b><br/><i>policy standard — declares what the agent can't do</i>\"]\n    CLI --> WARD\n\n    WARD -.->|enforced at runtime by| HM\n    WARD -.->|enforced at runtime by| CC\n    WARD -.->|enforced at runtime by| AG\n    WARD -.->|enforced at runtime by| MSAF\n    WARD -.->|enforced at runtime by| BR\n\n    HM[\"🔍 <b>Hundredmen</b><br/>MCP layer<br/><i>open standard</i>\"]\n    CC[\"🛡️ <b>adapter-claudecode</b><br/>Anthropic<br/>✅ Live\"]\n    AG[\"🛡️ <b>adapter-antigravity</b><br/>Google · desktop + agy + SDK<br/>✅ Live\"]\n    MSAF[\"🛡️ <b>adapter-msaf</b><br/>Microsoft · middleware<br/>✅ Live\"]\n    BR[\"🌐 <b>browser</b><br/>Browser agents<br/>✅ Live\"]\n\n    HM --> AGENT\n    CC --> AGENT\n    AG --> AGENT\n    MSAF --> AGENT\n    BR --> AGENT\n\n    subgraph AGENT[\"🤖 AI Agent System\"]\n        direction TB\n        subgraph CORE[\"Defense — Core security\"]\n            direction LR\n            MUND[\"🛡️ Mund<br/>Guardian<br/><i>scanning</i>\"]\n            HORD[\"🏛️ Hord<br/>Vault<br/><i>encryption</i>\"]\n            DOMERE[\"⚖️ Domere<br/>Judge<br/><i>compliance</i>\"]\n            WITAN[\"👥 Witan<br/>Council<br/><i>consensus</i>\"]\n        end\n        subgraph OPS[\"Operations\"]\n            direction LR\n            TOLLERE[\"🛂 Tollere<br/>Customs<br/><i>supply chain</i>\"]\n            API[\"🔌 API + Dashboard<br/><i>REST + UI</i>\"]\n            LC[\"🔗 LangChain bridge\"]\n        end\n        CORE --> OPS\n    end\n\n    subgraph OFFENSIVE[\"⚔️ Offensive — we attack what we defend\"]\n        direction LR\n        ADV[\"⚔️ <b>Adversary</b><br/>68 attacks · 5 categories<br/><i>offensive engine</i>\"]\n        ASB[\"🎯 <b>AgentSecBench</b><br/>locked suites · tier A–F<br/><i>citable benchmark</i>\"]\n        ADV --> ASB\n    end\n\n    AGENT -.->|attacked by| OFFENSIVE\n    OFFENSIVE -.->|scorecards inform| WARD\n\n    classDef policy fill:#1f2937,stroke:#60a5fa,stroke-width:2px,color:#fff\n    classDef enforcer fill:#064e3b,stroke:#10b981,stroke-width:2px,color:#fff\n    classDef core fill:#312e81,stroke:#818cf8,stroke-width:1px,color:#fff\n    classDef ops fill:#1e3a8a,stroke:#60a5fa,stroke-width:1px,color:#fff\n    classDef offensive fill:#7f1d1d,stroke:#ef4444,stroke-width:2px,color:#fff\n\n    class CLI,WARD policy\n    class HM,CC,AG,MSAF,BR enforcer\n    class MUND,HORD,DOMERE,WITAN core\n    class TOLLERE,API,LC ops\n    class ADV,ASB offensive\n```\n\nThe diagram shows the loop. Defense surfaces enforce the policy at runtime. The offensive engine attacks the agent. Scorecards feed back into WARD as new evidence — what attacks land, which need new policy domains, what regressed since the last release. **The loop is what makes the moat.**\n\n---\n\n## 🔐 Security Model\n\nDefense-in-depth across the entire AI agent lifecycle, validated continuously by an offensive engine that lives in the same monorepo:\n\n1. **🛡️ Ward** declares what the agent can and can't do (policy-as-code)\n2. **🛡️ Harness adapters** enforce WARD inside the IDE / CLI / framework:\n   - `adapter-claudecode` for Claude Code (PreToolUse hooks)\n   - `adapter-antigravity` for Google Antigravity (PreToolUse hooks across desktop/CLI/SDK)\n   - `adapter-msaf` for Microsoft Agent Framework (middleware pipeline)\n   - `browser` for browser-driving agents (runtime IPI scanning)\n3. **🛂 Tollere** inspects every dependency, image, and extension before it enters your project\n4. **🛡️ Mund** scans all inputs for threats before processing\n5. **🏛️ Hord** encrypts sensitive data at rest and in transit\n6. **⚖️ Domere** logs all actions with tamper-evident checksums and blockchain anchoring\n7. **👥 Witan** requires consensus for high-risk operations\n8. **🔍 Hundredmen** intercepts and gates tool calls in real-time — enforcing WARD policy at the MCP layer\n9. **🔗 Langchain / Python** secures LangChain.js and LlamaIndex chains and agents\n10. **⚔️ Adversary** attacks the entire stack with 68 documented and novel attacks\n11. **🎯 AgentSecBench** scores it, grades it A–F, and reports it in a standardized, citable format\n\n### CORS Model Integration\n\n| CORS Layer | Weave Package | Function |\n|---|---|---|\n| **Policy** | 🛡️ Ward | Declares allowed/denied actions, behavioral limits, attestation requirements |\n| **Policy Enforcement (Claude Code)** | 🛡️ adapter-claudecode | Reads WARD, gates Claude Code tool calls via hooks |\n| **Policy Enforcement (Antigravity)** | 🛡️ adapter-antigravity | Reads WARD, gates Antigravity calls across desktop/CLI/SDK |\n| **Policy Enforcement (MSAF)** | 🛡️ adapter-msaf | Reads WARD, gates Microsoft Agent Framework calls via middleware |\n| **Policy Enforcement (Browser)** | 🌐 browser | Runtime IPI scanning for browser-driving agents |\n| **Policy Enforcement (MCP)** | 🔍 Hundredmen | Reads WARD, gates tool calls at the MCP layer |\n| **Supply Chain** | 🛂 Tollere | Vets dependencies, images, extensions before install |\n| **Origin Validation** | 🛡️ Mund | Validates input sources, detects injection |\n| **Context Integrity** | 🏛️ Hord | Protects data integrity through encryption |\n| **Deterministic Enforcement** | ⚖️ Domere | Ensures consistent policy application |\n| **Adversarial Validation** | ⚔️ Adversary + 🎯 AgentSecBench | Continuously tests every layer above |\n\n---\n\n## 🛠️ Development\n\n```bash\ngit clone https://github.com/Tyox-all/Weave_Protocol.git\ncd Weave_Protocol\n\n# Build each package\nfor pkg in mund hord domere witan hundredmen tollere langchain api cli ward \\\n           adapter-claudecode adapter-antigravity adapter-msaf browser \\\n           adversary agentsecbench; do\n  (cd $pkg && npm install && npm run build)\ndone\n```\n\n---\n\n## 🗺️ Roadmap\n\n### Shipped\n\n- [x] GDPR / CCPA / SOC2 / HIPAA / PCI-DSS / ISO27001 compliance frameworks\n- [x] MCP server reputation scoring\n- [x] Automated threat intelligence updates\n- [x] LangChain.js integration package\n- [x] Python/LlamaIndex integration\n- [x] Web dashboard for monitoring\n- [x] Supply chain security (Tollere) — npm, PyPI, Cargo, Go, Maven, Docker images, IDE extensions, sandwich pattern detection\n- [x] Bundle package + CLI (`weave init`)\n- [x] WARD.md agent security policy standard\n- [x] Hundredmen ↔ WARD enforcement integration (v1.1.0)\n- [x] **Claude Code harness adapter** (Anthropic)\n- [x] **Google Antigravity harness adapter** (Google)\n- [x] **Microsoft Agent Framework harness adapter** (Microsoft)\n- [x] **Cross-platform thesis complete — same WARD.md works across all three major vendor harnesses + MCP**\n\n### H2 2026 Q3 — Adoption Quarter\n\n- [x] Browser agent security (`@weave_protocol/browser`)\n- [x] Dashboard v2 with orchestration visualization\n- [x] **[State of AI Agent Security: Q3 Report](https://tyox-all.github.io/Weave_Protocol/q3-2026.html)** — Industry analysis of agent security trends, platform maturity, supply chain risks, and market gaps\n\n### H2 2026 Q4 — Moat Quarter\n\n- [x] **Adversarial agents** (`@weave_protocol/adversary` v0.2.1) — 68 documented + novel attacks, real Playwright browser target, real-LLM demo mode\n- [x] **AgentSecBench** (`@weave_protocol/agentsecbench` v0.1.0) — standardized benchmark, tier grades A–F\n- [x] **Witan autonomous spending caps** (`@weave_protocol/witan` v1.1.0) — per-window budgets on LLM cost + tokens + tool calls, gated by block / approval / notify\n- [x] **Yoxallismus v2** (`@weave_protocol/yoxallismus@0.1.0-beta.0`) — **open beta shipped**. PQ-hybrid KEM (X25519 + ML-KEM-768 / NIST FIPS 203) + AEAD + ratcheting. Unaudited by design; validated by public use, forks, and responsible disclosure. v0.2+ adds DH double-ratchet, cascade cipher, threshold encryption; v0.3+ adds ZK/VDF/QRNG; v0.4+ adds FHE. See [yoxallismus/README.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus).\n\n---\n\n## 🤝 Contributing\n\nBug reports and feature requests welcome via [GitHub Issues](https://github.com/Tyox-all/Weave_Protocol/issues).\n\nFor security issues, please see [SECURITY.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/SECURITY.md).\n\nFor all other inquiries: **<TYox-all@tutamail.com>**\n\nSee [CONTRIBUTING.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/CONTRIBUTING.md) for guidelines.\n\n---\n\n## 📄 License\n\nApache 2.0 — See [LICENSE](https://github.com/Tyox-all/Weave_Protocol/blob/main/LICENSE)\n\n---\n\n## 🔗 Links\n\n- **GitHub:** <https://github.com/Tyox-all/Weave_Protocol>\n- **npm packages:** <https://www.npmjs.com/~tyox-all>\n- **PyPI:** <https://pypi.org/project/weave-protocol-llamaindex/>\n- **MCP Registry:** <https://registry.modelcontextprotocol.io> (search \"mund\")\n- **Q3 2026 Report:** <https://tyox-all.github.io/Weave_Protocol/q3-2026.html>\n- **Adversary on npm:** <https://www.npmjs.com/package/@weave_protocol/adversary>\n- **AgentSecBench on npm:** <https://www.npmjs.com/package/@weave_protocol/agentsecbench>\n\n---\n\n*Built with ❤️ for the AI agent ecosystem. We attack what we defend.*\n",
  "bytes": 43542,
  "sha": "98014586631693cbb7e77c4f90dfdb5297e825e00740e8a331033d4178eb2fde",
  "repo_slug": "tyox-all/weave_protocol",
  "fonte": "repo",
  "truncated": false,
  "api": "https://agentalog.com/api/listings/mcp_io_github_tyox_all_mund_1fce0f49/readme"
}