Open specifications for AI agent security: identity, trust credentials, threat models, behavioral governance, and the conformance suites that test them. Vendor-neutral. Apache 2.0 unless noted per repo.
- Agent Threat Matrix: tactics and techniques for attacks on AI agent systems. 57 techniques across 9 tactics, mapped to MITRE, ATLAS, and OWASP. MITRE submission in flight.
- Agent Identity Protocol (AIP): open standard for AI agent identity, capabilities, and trust.
- Agent Trust Protocol (ATP): open standard for verifiable trust assertions about AI agents.
- ATX: Agent Trust eXtension credential format and protocol architecture.
- ABGS: Agent Behavioral Governance Specification. What goes in a SOUL.md file.
- AIIS Signatures: AI Injection Signature Standard. YARA-style signatures for AI agent prompt injections in web content.
- OTel SemConv for agent identity: OpenTelemetry semantic conventions for AI agent authorization observability.
Conformance suites:
- ATX Conformance: reference verifiers and fixtures for ATX v1.0.
- A2A-IDF Conformance: canonical conformance suite for A2A-IDF.
- opena2a-parity: cross-CLI parity gate for the OpenA2A CLI fleet.
See GOVERNANCE.md for how decisions are made and how to contribute. The catalog of all OpenA2A organizations and projects lives at opena2a.org/projects.
