major labs
Latest

What we've shipped

Tools, essays, and data, newest first. We date everything and let the dates speak.

  1. 2026-09-10

    The prompt-injection sandbox is deprecated and /break now redirects to /security. The lesson it taught, that a prompt is not a security boundary and verifiable runtime checks are, lives on in the primitives that powered it (IdentityKit, MandateKit, BudgetGuard, WitnessKit) and in the Clearpoint demo, which exercises the same gateway against real mandate verification. Retiring the standalone page keeps the surface area honest: one interactive demonstration, maintained, beats two half-watched ones.

  2. 2026-09-09

    Every frontier lab publishes a safety framework; none publishes it in a form a third party can verify. This spec is the missing format: a machine-readable schema for capability thresholds, evaluation gates, deployment conditions, and escalation commitments; a hash-anchored changelog format with a closed change-type vocabulary (a weakened threshold can no longer be filed as a clarification); a standard-library validator; and an unofficial reference mapping of Anthropic's RSP v3.4 built from a dated Threshold Watch snapshot, showing what adoption looks like. Four conformance levels, L0 Published through L3 Changelogged, aligned to the Threshold Watch scoreboard, which now doubles as a conformance report. Current state: six labs at L0, four at L1, zero at L2 or L3. CC0. Adopting it costs a lab an afternoon. Completes the stack: the Compact states the principles, the Clauses put them in contracts, this spec makes them machine-verifiable, Threshold Watch watches.

  3. 2026-09-09

    The measurement series behind the State of MCP work is now a versioned, downloadable bundle: the 3,227-repo census, 112 discovery runs of provenance, the weekly aggregate series, and score distributions for security (2,408 scanned), identity (2,330), and supply chain (1,399). Aggregates only: per-repo findings stay in the private disclosure queue, as the disclosure process requires. Checksummed, licensed CC-BY-4.0, with a plain citation and BibTeX on the data page and a CITATION.cff in the repo. DOI pending via Zenodo. If you use the numbers, cite the dataset.

  4. 2026-09-09

    Major Labs now describes itself as what it has become: the observatory for the agentic web. The homepage leads with the four instruments (the census, Threshold Watch, the incident timeline, the trust scoreboard), every stat card carries a verified Q3 measurement, and third-party volume claims that later measurement did not sustain are gone from evergreen pages, with a dated correction note on the founding essay rather than a silent rewrite. Under the hood: a rebuilt llms.txt, Dataset and ItemList structured data on the incident timeline and both Q3 reports, dated quotable claims on the live surfaces, and a sitemap that now actually lists the Q3 reports.

  5. 2026-09-08

    Three copy-paste contract riders implementing the Control Stack Compact's buyer-side commitments: frontier AI incident disclosure on a 72-hour clock, attributable agents with reconstruction and revocation duties, and liability allocation with a cap carve-out for undisclosed incidents. Written as MSA-style riders with negotiation commentary, versioned (v0.1), CC0, and explicitly not legal advice: the point is that a buyer's negotiation starts from 'adjust this' instead of a blank page. The buyer side of the Compact, made copy-pasteable.

  6. 2026-09-08

    A dated, sourced public record of frontier AI control incidents: the May–June rogue-swarm takeover of a German wiki, the July sandbox escape that reached Hugging Face and OpenAI's own research cluster (six days of outside investigation, then silence), the UK AISI evaluation in which agents built fake identities and targeted real people, and the chief-scientist disclosure that chain-of-thought monitoring is degrading. Inclusion criteria published; every claim traces to a listed source; submissions via GitHub issues. Aviation keeps its incident record; this page is ours.

  7. 2026-09-08

    Coverage grows from three labs to six with xAI's Frontier AI Framework (June 2026 edition), Meta's Advanced AI Scaling Framework (whose PDF rejects automated retrieval, a failure the page shows on purpose), and Amazon's Frontier Model Safety Framework. New commitment-one scoreboard: all six labs publish a framework, none publishes a changelog a third party can verify. Changes now ship as an RSS feed, so a framework edit becomes a subscribable event.

  8. 2026-09-08

    Every frontier lab publishes a safety framework; none publishes a version history. Threshold Watch fetches each lab's canonical document on a cadence, normalizes it, hashes it, and archives a dated snapshot when the content changes, with diffs where the source is text. Launch coverage: Anthropic's Responsible Scaling Policy (v3.4), OpenAI's Preparedness Framework (v2, tracked via the canonical PDF because openai.com blocks automated retrieval of the page), and Google DeepMind's Frontier Safety Framework (3.1). First snapshots archived September 8. Read-only, method public, fetch failures shown as-is.

  9. 2026-09-08

    MandateKit grew an MCP gating proxy: one command wraps any stdio MCP server and verifies every tools/call against an Ed25519-signed mandate before it executes. The mandate's categories list becomes a signed tool allowlist, merchant pinning binds a mandate to one named server, and per-call amounts are capped by max_amount. Fail-closed: unparseable frames, tampered mandates, and untrusted signers are denied, and denials return to the agent as error results carrying the reason. Ships in the mandatekit Python package as mandatekit-mcp; ten unit tests plus an end-to-end smoke.

  10. 2026-09-07

    The first fresh deep scan since Q2, and an honest one. Measured with the same instrument as last quarter, MCP security did not improve: the share of maintained servers carrying a risky code pattern rose to 37.5 percent from 35.4, high-severity servers climbed to 67 from 55, and identity is stuck, with 576 of 733 sensitive network-facing servers (78.6 percent) still shipping no authentication in source. The sharpest finding needs a tracked cohort: of 47 high-risk servers we flagged to maintainers through coordinated disclosure in Q2, re-scanning found 2 fully fixed, 4 reduced, 35 unchanged, and 6 worse. Disclosure is necessary and not sufficient. The supply-chain scanner changed method this quarter, so its exposure rate is a re-baseline rather than a delta, and because it feeds the composite, the Trust Index is deliberately withheld this quarter rather than move for a reason that is not real. From next quarter all three pillars share a stable method and the composite resumes. The pipeline now stamps every pillar with its own scan date and warns when one is carried forward too long, so a stale number never ships as a fresh one again.

  11. 2026-09-07

    The first delta edition of the series, built on 18 weekly scans from May 31 to August 31. The MCP server population grew 31 percent to 3,166, roughly 42 net new servers a week and no single-week surge. The fastest-growing slice was remote-hosted servers at +43 percent, the part of the ecosystem with the widest attack surface. The stale share held flat at 23.5 percent, so MCP is scaling with its composition fixed, neither maturing nor decaying on net. This edition reports population movement only: the deep security, identity, and supply-chain pillars are disclosure-sensitive, run manually rather than weekly, and are being re-based this quarter, so no security-posture delta is claimed. The next edition will report those pillars from a fresh deep scan.

  12. 2026-06-19

    The argument behind the State of Agent Memory report. An agent's memory is a claim you take on faith: zero of six leading systems sign memory, zero export it at full fidelity, zero carry portable provenance, and only three ship regulatory-grade consent. Memory is moving from a convenience feature to the substrate agents transact on, and an unsigned memory undermines a signed mandate. Why the fix is a portable, signed, consent-bound record rather than a better store, and where RememberKit fits.

  13. 2026-06-19

    Refreshed from the June 18 sweep and widened from one finding to three. The Major Labs Trust Index for the MCP ecosystem sits at 38 out of 100: Code Safety 64.4, Identity 24.6, Supply Chain 24.8. The headline numbers, all firsthand: 44,347 servers advertised across three registries but roughly 1,934 genuinely evaluable, a 23x gap; 36% of the maintained core ship a risky code pattern; 25% touch sensitive data with no authentication layer, the authorization gap agentic commerce keeps hitting; and 75% ship a known-vulnerable dependency. The report PDF and the web page both carry the new pillars; the live scoreboard updates weekly.

  14. 2026-06-17

    When an AI agent pays, the merchant or PSP on the other side has no contract with the issuer, so it cannot verify the payment mandate is genuine, in scope, or still live. Clearpoint answers exactly that. Present an AP2 mandate and get back a signed verdict with a machine-readable reason, a revocation status, and a tamper-evident hash-chained receipt, priced per verification at the money moment. It runs on two primitives we already ship in the open, MandateKit (AP2-tagged signing and verification) and WitnessKit (the receipt chain), in two modes: trusted, where you pin the issuer keys, and integrity-only. The live demo lets you try to break it: talk a shopping agent into a banned purchase, then watch the gateway block the same charge and seal it into the chain. v1 is scoped to signature, scope, expiry, a hosted revocation list, and signed receipts, and it shipped security-hardened. We are looking for design partners.

  15. 2026-06-16

    The scoreboards now roll up into a single weekly score: how safe is the agentic web to actually transact on? Version 1 fuses three firsthand, read-only pillars, each 100 minus the share at risk: Code Safety (risky code patterns), Identity (network-facing sensitive servers with no auth), and Supply Chain (servers shipping a dependency with a known advisory). The equal-weighted composite lands at 38 out of 100. It is published with a versioned methodology, a machine-readable trust-index.json, a cite-this block, and an embeddable badge. Like every series here it compounds weekly and cannot be backfilled, so the first mover holds a record no one who starts later can match.

  16. 2026-06-16

    The prompt-injection sandbox returns. A shopping agent has $50 and one approved merchant; you write a product page that tries to talk it into spending your money somewhere it should not. Your page runs past two agents side by side: one defended only by its system prompt, which can be talked into anything, and the same agent behind a gateway that checks every purchase against identity, mandate, budget, and an append-only witness log before it happens. The prompt-only side breaks; the governed side holds. It runs live when a model key is configured and falls back to a deterministic simulation otherwise, so the gateway checks are identical either way. The four primitives behind it (IdentityKit, MandateKit, BudgetGuard, WitnessKit) are open source.

  17. 2026-06-15

    The sweep grew three measurements. Supply chain: we resolved 32,000 declared dependencies across 1,344 servers against OSV.dev and found 74.6% ship a runtime dependency with a known advisory, the widest reach running through the official @modelcontextprotocol/sdk itself. Commerce: a full-day, read-only sample of the EIP-3009 gasless-settlement rail on Base USDC (the rail x402 rides) clocks ~180K agent settlements a day, ~5.4M a month, from 12,000 unique payer addresses. Remediation: we froze the highest-risk cohort and re-scanned it, and before any outreach 43 of 47 were unchanged, so high-risk servers do not fix themselves. All three are aggregate-only, run on the weekly cadence, and now appear on /security and /data.

  18. 2026-06-12

    A second weekly sweep joins /security: of the network-facing MCP servers that take sensitive actions (shell, file writes, database writes, mail or money), 74.5% show no identity layer anywhere in their source. Static, read-only, aggregate-only, with the headline deliberately cut to network-facing servers because stdio servers legitimately delegate identity to the host. The page is the instrument; IdentityKit is the response.

  19. 2026-06-12

    Every public registry ranks MCP servers by stars and recency. This one scores 2,479 servers on signals that matter: maintenance, documentation, license, adoption, transport, plus two earned badges (identity layer, clean security sweep). Praise-only by design: security and identity appear only as credits, findings stay in coordinated disclosure, and negative per-repo data never enters the public payload. Methodology published on the page; scores rise on the next sweep when maintainers fix things.

  20. 2026-06-12

    Seven agent-payment rails (Visa TAP, PayPal Agent Ready, OpenAI/Stripe ACP, Google AP2 + UCP, x402, MCP) assessed from primary specifications and scored Portable, Federated, or Walled. At launch: 2 Portable, 4 Federated, 1 Walled — and the identity layer has already quietly converged on a shared open signature standard while the mandate layer stays locked per network. Live and announced strictly separated, every cell primary-sourced, x402-tracker discipline.

  21. 2026-06-10

    The same checks behind the /security scoreboard, packaged as a one-line GitHub Action. Drop it into your MCP server's CI and every push gets a security-surface score, a job summary, and a README badge comparable to the rest of the swept ecosystem. Static analysis of your own source only: it never connects to, runs, or probes anything. v1 tagged and public.

  22. 2026-06-10

    The static security sweep the scanner promised is now a live scoreboard. Weekly read-only analysis of the most-used active MCP servers: risk-surface tiers, pattern prevalence (SSRF surface, command injection, code execution), and a trendline that compounds with every sweep. Aggregate-only by design: per-repo findings go to maintainers through coordinated disclosure, and after the first cycle a fixed-since-last-sweep feed will name the good actors. Never probes a running server; the checks are public Python anyone can read.

  23. 2026-06-10

    An adversarial source review of all five primitives (Python + TypeScript) drove a hardening release. Fixed: a did:web SSRF guard bypass in IdentityKit, a cross-language expiry divergence in MandateKit, a record() fail-open in BudgetGuard, cross-agent memory censorship in RememberKit, and the shared canonicalization fallback now fails closed. Every fix is locked by a regression test. v0.0.2 is live on PyPI; still v0, experimental, unaudited by a third party.

  24. 2026-06-10

    All five primitives are live on PyPI and npm: identitykit, mandatekit, budget-guard-agents, witnesskit, rememberkit. One pip install away from a governed agent, in Python or TypeScript. Every package verified with a clean install from the public registries. v0, experimental, honestly labeled.

  25. 2026-06-09

    We read six agent-memory systems firsthand: Letta, Mem0, Zep, LangMem, model-native memory, and Cognee. Zero of six sign memory, zero offer full-fidelity portability, zero carry portable provenance. Consent is mature; the ability to prove a memory once it leaves the store is shipped by none of them.

  26. 2026-06-09

    Governed, portable agent memory. Signed, scoped, content-addressed records that verify on their own, so a memory moves between agents with its provenance attached. The fifth primitive, after who, may, spends, and did: what the agent knows and remembers. Python and TypeScript, hardened with a v0 adversarial review. v0.

  27. 2026-06-08

    Ask four AI answer engines the same question and they cite the same source only 16% of the time. A firsthand read of how ChatGPT, Claude, Perplexity, and Gemini distribute citations: YouTube the most-cited, a 546-domain long tail, and a distinct personality per engine. The method is open.

  28. 2026-06-08

    See which answer engines cite your URLs across Claude, Perplexity, ChatGPT, and Gemini. Read-only, bring-your-own-keys, stored as a series so you can watch citation rates move. The last roadmap item; the whole roadmap is now shipped.

  29. 2026-06-07

    Portable, signed, resolvable agent identity (did:key + did:web) with the cross-walk onto DID, FIDO, AP2, and EUDI. The fourth primitive: who the agent is. Python and TypeScript. v0.

  30. 2026-06-07

    The full report. The population is inflated tenfold, usage is concentrated, and more than a third of the 500 most-used servers ship a risky code pattern. Firsthand, read-only, open data and method.

  31. 2026-06-07

    Identity, Mandate, Budget, and Witness wired into one governed agent. A reference integration showing the four primitives bound, denied, and audited together in about fifty lines.

  32. 2026-06-07

    A static, read-only read of the source for the 500 most-used servers, added to the open dataset. Aggregate signals only; no live server is probed and per-repo findings are held for the maintainers.

  33. 2026-06-06

    Per-task budget, loop detection, and kill-switch middleware for any LLM call. Deterministic, dependency-free, fail-closed. The third primitive: what the agent spends. v0.

  34. 2026-06-05

    Tamper-evident audit trails for AI agents. Every action is signed and hash-chained, so any tamper is detected and located. Python and TypeScript. v0.

  35. 2026-06-05

    The read-only scanner and the structured dataset behind the State of MCP numbers. If you publish figures, hand people the code to check you.

  36. 2026-06-05

    Sign and verify what an AI agent is allowed to spend on. A plain-language rule becomes a signed mandate, checked against every transaction. v0.

  37. 2026-06-05

    The final essay in the five-layer series. The DID/FIDO/EUDI cross-walk, portable agent credentials, and why identity ships last.

  38. 2026-05-29

    Around 2,400 MCP servers scanned firsthand. The real numbers behind the repeated “10,000+ servers” claim: roughly 1,200 are genuinely evaluable.

  39. 2026-05-27

    The thesis, the five-layer essay series, and the MCP discovery tools (picker and registry tracker).