Releases: sebastienrousseau/agtmls
Releases · sebastienrousseau/agtmls
Release list
AgtMLS v0.0.12
AgtMLS v0.0.12
Summary
- Build provenance is checked, not just produced. Every release asset
has carried keyless SLSA build provenance signed through Sigstore; the
published-release audit now requires it for every asset, from this
repository'srelease.ymlat the release tag on a GitHub-hosted
runner, and fails naming any asset without it. This is the first
release audited that way. - Check an asset yourself:
gh attestation verify <file> --repo sebastienrousseau/agtmls --signer-workflow sebastienrousseau/agtmls/.github/workflows/release.yml. - An accurate security policy.
SECURITY.mdno longer says the
registry index is unsigned; it lists the index signature, the signed
advisory feed and build provenance as boundaries, and what each proves.
Checksums
e049f8787ce8301dd84b0f7fed6222181d946d54281395c3785b2f312555d05c agtmls-0.0.12-py3-none-any.whl
2c82b38ef2d6359e7bc5fcf0829d17514bd9c1f61f389cfa3ff4f5178bf041e4 agtmls-0.0.12.tar.gz
1b8284f477eeede188f3b312476b6ea609a47a68c5b126646bc826f95e1314a4 agtmls-anthropic-polyglot.tar.gz
beb50bd21978616d71ff6700d4d89a1e8840a5f38ab2adcb13df1645d82e0bad agtmls-continue-polyglot.tar.gz
a48d84ea0bf70d0dbf5365eafb41d946dc0f41fc5f94f11966a4380aeb1f03cb agtmls-cursor-polyglot.tar.gz
bccdd5895312090ad3f11e8b2284ae724ec9f47c3b871f6893c668865f826671 agtmls-deepseek-polyglot.tar.gz
9101fd2a4828ceff7e5eb2a67b56fefbcefc448cefccc65fea6085904e4dbaea agtmls-generic-polyglot.tar.gz
db47475a9ca6e727fba0b24d66a2332991b3b95c2c8766b495c191d19df88424 agtmls-github-copilot-polyglot.tar.gz
70a3768f87233816a4ee5c3aa9b2f1d7555dd36042230025208b979e2658e52b agtmls-google-gemini-polyglot.tar.gz
e045c3e61260c83c7bdbf28f6f7cfa6883ffaaaae522a3ba23ff60eeda900b36 agtmls-mistral-polyglot.tar.gz
89ee0e6e96f026f0f7ae0d08b283177034983860b54e487323f46e58e043a417 agtmls-ollama-polyglot.tar.gz
f256dec2159476bb7f19e663292b2568dc0b7fee0ecf368c2f0fe04e8fe18872 agtmls-openai-polyglot.tar.gz
9df86d8137ca09b3e231a006ceb54938d2b81befe92cb86d3c1ce26b9d8d37c0 agtmls-qwen-polyglot.tar.gz
e691b5cb831f50b40702d77e14c0e113f59fb90dd8a970097676b73dac71f0e4 agtmls-windsurf-polyglot.tar.gz
4e14a3271d5adecdee53d799daa36e022042bc0f75d2fa3b049fbbe02188cdaa agtmls-zed-polyglot.tar.gz
ee4532970d836403d4a29d6ad366047dc16402c892f5af485529f61dc5c01652 index.json.sig
220b355aa6c179d5dbdcae70ff4a2d0db5a457a27906b50bcaf486857919554b release-manifest.json
AgtMLS v0.0.11
AgtMLS v0.0.11
Summary
- Two implementations, one verdict on trust. agtmls-spec chapters 9
(index signatures), 10 (attestations) and 11 (advisories) are now
normative. Its conformance level L5 runs every signature, advisory and
attestation vector through both this CLI and agtmls-rs, and requires
identical verdicts, exit codes and attestation bytes. Both pass. scripts/trust-check.pygives one signature, advisory or
attestation judgement per call, for the conformance runner or for
checking a file by hand, with the same flags, JSON and exit codes as
agtmls-rs.- Stricter input. A verification time must be
YYYYMMDD, and is
refused before it can reachssh-keygenas an option. - Windows checkouts. The vendored spec vectors are pinned as exact
bytes; Git for Windows' CRLF conversion failed every signature test. - More evasions pinned. The security corpus gains a keyword split by
Unicode tag characters and threeallowed-toolsescalation cases
(space-separated, narrowed by a specifier, within its policy): 108
cases at precision and recall 1.0.
Checksums
6d2b0d47152d3f2c14ae3f5cac1f5628216bbec1267a630202cfbc256f6154e5 agtmls-0.0.11-py3-none-any.whl
6a7ac702fd9e60d60897dce6664e773e59ab6fd539a6be0112857e79bd81382b agtmls-0.0.11.tar.gz
61b8cdf0524bd2588a413ef3e53d0adde019ab563fcb8ecab0e021ad8f377c73 agtmls-anthropic-polyglot.tar.gz
dd9d365b40b0b152566329a8253a07775a34a12cf095a88ecab745b0572f42ac agtmls-continue-polyglot.tar.gz
e6fabb8dbcd85204681c707632f9dbd310dab38744c6dd32ff2c9c6d76157cfb agtmls-cursor-polyglot.tar.gz
a7d03187b735617f891aa0883a0cd416cf0d7f6ae9cc833f37abeb887f3df9c4 agtmls-deepseek-polyglot.tar.gz
e0fd3fdc6ad2d4d70204044de80f83ce543f57fbf1542f49819d8b9e5fddb5e8 agtmls-generic-polyglot.tar.gz
b2c3d181b9745d32df26b2f951486c5d30e6b8027a85589c3917328a2ca81aad agtmls-github-copilot-polyglot.tar.gz
3ade05bc9881361bfb89c0517dcc1f924dc6843b614d5b78a32d0b8b0f8dc7a4 agtmls-google-gemini-polyglot.tar.gz
4342751a1b1809cf151476ac36d9e2db140443ab240ce7652c19493ed41b7f76 agtmls-mistral-polyglot.tar.gz
98d78d1cb7e4c4b7c8a3323cfbcae173a9a554269179858a6b17ee5666fe1652 agtmls-ollama-polyglot.tar.gz
e27c185d48a03bc0dcc2d2d29a28745a5de934de9f16f1f283141be7199b3bcf agtmls-openai-polyglot.tar.gz
ea847af2b9e5a03416f0ac55f43f3e5361a763258424c269fc9c05b5aca43b61 agtmls-qwen-polyglot.tar.gz
7ada225f922e41ea76ec0d9a04c5cd79850675efff447afe55f748d5ae4a8f18 agtmls-windsurf-polyglot.tar.gz
f9dfaab8cf5f11777ffcf1cecb123622fa0ff5976d40a5b408104d80a7779866 agtmls-zed-polyglot.tar.gz
c872443e00382125a390427055890de33408d0afd0843d31c54f603075bf7678 index.json.sig
12ba7573691017a84e8c1fe176306a3abd1e50a96cf5220ac7c8034d361603e1 release-manifest.json
AgtMLS v0.0.10
AgtMLS v0.0.10
Summary
- The first signed release.
index.jsonis signed with the
agtmls-releasekey in a protected release environment, and the wheel
carriesindex.json.sigbeside it.agtmls verify --signatureschecks it
offline against the shippedALLOWED_SIGNERS(key fingerprint
SHA256:X7cJ/chcMsrENFv4eeiCKLFEsFjqShHh042HgKLlcl0), so an index served
by anyone else is refused. - Revocation.
verifyconsults a signed advisory feed and exits6,
naming the advisory, when an installed skill's digest has been revoked. A
feed that does not verify is never read. New exit codes:4unsigned,
5bad signature,6revoked. - Per-skill attestations. Every skill ships an in-toto manifest (its
exact files and hashes, so a verifier can name the file that changed) and
a capabilities statement (declared policy, granted tools, escalations),
underattestations/. - Fewer false positives, fewer blind spots. A coloured check mark or a
keycap is no longer a CRITICAL steganography finding (audit --pedantic
still reports it at LOW), while a run of selectors or one after a letter
still is. Injection rules now read JSON, YAML and TOML, and decode JSON
escapes first, so a tool description that hides "ignore previous
instructions" behind an escaped newline is caught. Rules run only on the
file types they apply to, and extensionless#!scripts are audited. - Two more rules.
AGT-HOOK-003flags repository hooks that run on a
lifecycle event without a trust gate;AGT-POLICY-006flags an unscoped
Bash,WriteorEditinpermissions.allow. - A release that builds. The
v0.0.9tag was pushed but never
published: its source distribution lacked files the wheel build needs.
This release carries every v0.0.9 change, and the packaging check now
fails whenever the source distribution would lack one.
Checksums
dc498375a5a6242c8d356e49642e96bd398a2f71c911e33db7ffeba50d88de35 agtmls-0.0.10-py3-none-any.whl
54255777ffeb426c8be65c7239b69c918c645c74a75de2430d5f8094fc8ba45b agtmls-0.0.10.tar.gz
439cc18cd2ed5899969996be35229a3a8dc88be787436708a86349e634e22997 agtmls-anthropic-polyglot.tar.gz
3efc39a89a03b669208b691c3b7ed16dcdffa776f8f96cf0123fcf797f6c6e75 agtmls-continue-polyglot.tar.gz
db47f50c07c860e1a897bd323f3317c257d8a46dcdd9243cee0895d4f7c26ab5 agtmls-cursor-polyglot.tar.gz
aeaf451c95c853c6fb71d3198fa617b98ea744051ed35cb197d9366fe5cbe5ea agtmls-deepseek-polyglot.tar.gz
f46f183e37d16f0db7ae33c24f6d5f3b080c504fc4627e9391fabebe8ca387e8 agtmls-generic-polyglot.tar.gz
c6749b64d03c1faf8d7bb4a3fb34d4ae4dd6f1bf2f16c754288dde8ea6aeafb9 agtmls-github-copilot-polyglot.tar.gz
970b6bc2c7a546c679d8c1691c3a08ab6312cf5bba82ce4cc8769a7752a94f21 agtmls-google-gemini-polyglot.tar.gz
2af9fdef1dde12836768b73b934c8075ce8e14498721c9ae632d9223afed5b45 agtmls-mistral-polyglot.tar.gz
14fdb55919f1637e80098610963f8278c335691bb5714c5ecac9e40cdcec86d2 agtmls-ollama-polyglot.tar.gz
62a96b1c9b327526d4a4307831fe0ef4fd8a977778106e3fee0739d5ebf9ea16 agtmls-openai-polyglot.tar.gz
af04a198d2abc3e0234d8c16c3a4ed0abd7190d44cb85cf5b90e16755589ef80 agtmls-qwen-polyglot.tar.gz
fdb6fb03048fe556e5e487afd6f9936e583c67c99f3927158920ca4d0be1d32c agtmls-windsurf-polyglot.tar.gz
c719fcf3f40377a0ea5797917f85672cf63e84daa7d6554994c0be19b4135c84 agtmls-zed-polyglot.tar.gz
9d593f8bdaba2bf4854bf9cb9d46aa31c676a745ec787add5cf69f248dfe06be index.json.sig
09065de3486fc704438abe7191f9f20a239a20be12e6f49dff202570b8a2033e release-manifest.json
AgtMLS v0.0.8
AgtMLS v0.0.8
Summary
- The installed CLI works outside a checkout.
uvx agtmls uninstall
removes what a wheel install copied,uvx agtmls doctorinspects the
registry and your target rather than a repository it does not have,
doctor --target .means your directory, a plain install no longer shows
bundled skills as missing, andagtmls --versionanswers. - Thirty analysis rules, from nineteen. Eleven new rules over the
surfaces an agent actually runs: hooks that auto-approve or fetch,
wildcard tool grants, unpinned package runners, self-install,
permission-bypass flags, model output interpolated into a shell string,
command-running MCP tools, decode-and-execute payloads, paste-this-command
prose and selection gaming.rm -fr /is caught as well asrm -rf /.
The rules are data from agtmls-spec, loaded identically by the Python and
Rust implementations, which agree on every corpus case. - Rules run on the text an agent reads. Hidden code points are stripped
and compatibility forms folded before matching, so a keyword split by a
zero-width space or spelt in fullwidth letters is still the keyword.
Steganography still reads the raw bytes. - Quoted attacks, suppressions, SARIF and baselines. An injection quoted
under an "example" or "attack" heading is reported at MEDIUM. A finding can
be suppressed on the next line with a reason, never for steganography.
audit --format sarifwrites SARIF 2.1.0;--write-baselineand
--baselinelet a CI gate fail on new findings only. audit --foreign <path|git-url@sha>audits every skill in a Claude
marketplace, a plugin manifest or a skills directory, per plugin and
skill, against the skill's own policy or a provisional one inferred from
itsallowed-tools. Fetching is by URL and exact commit only.- The security corpus is a measurement. 86 cases, precision and recall
held to a floor of 1.0 that can rise and never fall.providers.jsonsays
what each agent does withallowed-tools, and the capability finding
names the runtimes that grant. - Benchmarks re-recorded for the rule count.
audit --all --strictis
383 ms P50 on the reference laptop with 30 rules; both baselines were
re-recorded rather than the regression budget widened, and BENCHMARKS.md
says why.
Checksums
a261887c5e40b559f166c5d4c922aea81df320d70396a84bd2148f5d8320f239 agtmls-0.0.8-py3-none-any.whl
b680de6f4298589f7545e9c03c36666eba12c6073bc6dc0e73f639ae9a46b195 agtmls-0.0.8.tar.gz
60cbee7120ff558d3e24f345dcd4170fde42d9eec8c3f8644e4b820986902a17 agtmls-anthropic-polyglot.tar.gz
938db32c99f061c179d038b514e2cf9da3590a39e559d9b5e2b57279ebd52424 agtmls-continue-polyglot.tar.gz
8c33441d46b94d3bb53fc1072426dbd4c98d61ac97560b4cf66935953958ec7c agtmls-cursor-polyglot.tar.gz
c99e2c0cf4acc93c130e41a0685c542ab338d75f2332d34c1f401eb81979d502 agtmls-deepseek-polyglot.tar.gz
0c087d788f7c69655e93713faf880362cc0a327eef4c49467bd510fe939685cc agtmls-generic-polyglot.tar.gz
d7d372fe2ed9e644c60219fd5babbcd29970a2ace6065b225292ecaa0f5593c6 agtmls-github-copilot-polyglot.tar.gz
83e3673bb76d76b069eb03aa1357b4e8cfcd99a023f56f8524c9fa895b39bd89 agtmls-google-gemini-polyglot.tar.gz
0d0d4f8f8fd7380fc0d46b0f7b60aae8f8aa8a0b0cf7be1596aedc31f0257d19 agtmls-mistral-polyglot.tar.gz
8622d20be1b6b91b7e8adc83211d628fb9f731ad2d9466c36a50373e608401e7 agtmls-ollama-polyglot.tar.gz
6e0e72c8bb4f01b24a49337677313fcaaf66ac29e6cfb947c6c6195858c06d8d agtmls-openai-polyglot.tar.gz
13bff2f2a6a79b35214499adc297eb135d50a5e6f8be6e0b438d228d4d41f7cb agtmls-qwen-polyglot.tar.gz
88479c63cdf81e021901883bf1b8fe06bad5280fbfe446c49ca70be566631df7 agtmls-windsurf-polyglot.tar.gz
95d1f6ba2af39feec4a6a29daafa1a05ceaf7daa52347916da10b1e690049525 agtmls-zed-polyglot.tar.gz
e432875757e5088b91ef3064bcbeb3a4ce71b11e3a5b33a2b3a03a96981d4c93 release-manifest.json
AgtMLS v0.0.7
AgtMLS v0.0.7
Summary
- Antigravity is a native agent.
install,verify,uninstalland
doctoraccept--agent antigravityand work in.agents/. exportselects skills the wayinstalldoes. Without a profile it
exports the general skills, and--bundle NAMEadds that bundle. It used
to export every bundle when unfiltered. Thesecurityandresearch
profiles install their own bundles; general profiles no longer pull in the
noyalibproject bundle.- A release no longer moves every skill's digest. The content address
covers the skill alone, soindex.jsonand lockfiles change only for
skills that changed. installrefuses an index entry without a digest, not only a tampered
one.scaffold-skillwrites every file or none.agtmls diffresolves
relative paths from the caller's directory. Error messages name the
command that fixes the problem.- The security analyzer's rules are a pinned
agtmls-specsnapshot,
checked against the spec in CI. AGT-CAP-001 now parses space-separated
allowed-toolsand no longer claims every runtime grants them. - Benchmarks. Nine workloads measured in fresh processes, every raw
sample committed, a regression gate, and a scaling measurement at ten
times the registry. Every published number, including the README's, is
generated from the results and stamped with their hashes. - Releases are checked before and after they ship. A tag cannot be
pushed untilrelease-preflight.pyproves it is signed, titled, on the
intended commit and matched by every packaged version. The workflow builds
once, publishes the same files to GitHub and PyPI, and
release-audit.pyreads them back. - Supply chain. CodeQL scans the Python and the workflows. A pinned
ruff lints the code. Unit-test coverage of every script and the library
core is 100%. The SBOMs validate, are stamped by content rather than
commit, and every source file carries an SPDX header. - Docs. README follows the portfolio template and its counts match the
code.docs/POLICIES.mdstates the toolchain floor: Python 3.10, raised
only at upstream end of life. - Removed.
agtmls agent-cardandagent-card.json: the file declared
itselfnot_a2aand nothing consumed it.
Checksums
a4d3dc676997c6978cedaa4f154f94b69ccd07d0a5c6b5bca9335beca36d236d agtmls-0.0.7-py3-none-any.whl
b51f7422b09f002f6c4707432dbcd987b4f95cb6d816445e806d5b38e377c5fa agtmls-0.0.7.tar.gz
075f0d4d686ba33bd7c46bbc2bdd2ae696e8488dad6e709199c208a048de6f0d agtmls-anthropic-polyglot.tar.gz
027cd30b0da53051d2fb3d384873aac0a8549b0f9b7ce7fcf040eaa4ef746a58 agtmls-continue-polyglot.tar.gz
a22b1b400d4a05d2545301dd857330f8a8da821a2bc8722128537d4b3db3042c agtmls-cursor-polyglot.tar.gz
13ed17763616a0de6b3a6bf57912cffdef4272d3372e1294e03e6f22967bbda2 agtmls-deepseek-polyglot.tar.gz
b64d311a521484f9899fc5e8639e865d03103e3445fe74088bee231097ada0a7 agtmls-generic-polyglot.tar.gz
ce24efe80efe32b13d42270f4e53b9fba32234d2c531c987dd7c3ef8ba07f1e1 agtmls-github-copilot-polyglot.tar.gz
5b392fc68a0ccda8c8c89b06b19e371b2b4822a9c05d8165b0f5e9f74158f1ab agtmls-google-gemini-polyglot.tar.gz
8ce99c3761e8a26fca4b737dc03933bb0d158a09c926304ebbfc2a3ebedc8576 agtmls-mistral-polyglot.tar.gz
bea8f1c7562173fde3af2956cfdd102857a38c0dc675f108d8a8549f372083d9 agtmls-ollama-polyglot.tar.gz
0b78883a136cd160b1d1c8da4443e7f9a10c4817362431444c9aaf759de99096 agtmls-openai-polyglot.tar.gz
0951e8415d770dc08a2750cffd32751cc1a3bee3d6830f6788017fc20bba73fe agtmls-qwen-polyglot.tar.gz
7601460f6c6eefa11f8f603c0effc32637556b16e310398e4214a5f6891bfdaa agtmls-windsurf-polyglot.tar.gz
03b0c0748e6b127bc89b073d08695c2ab3102c87aa2f10efbded60860b16f668 agtmls-zed-polyglot.tar.gz
22fdeecce613ed1e626df5355b68d70cc29b896761fbbb42d35c6a911993659a release-manifest.json
AgtMLS v0.0.6
AgtMLS v0.0.6
Summary
- Skills are content-addressed. Every skill in
index.jsoncarries an
integritydigest.agtmls installchecks the registry against it before
copying anything, refuses a mismatch with exit code 3, and records a
lockfile;agtmls verifyreports skills that were modified, deleted or
added after install. installno longer overwrites your prompt file. ACLAUDE.mdor
AGENTS.mdthat AgtMLS did not generate is left alone unless you pass
--force, which backs it up first;--dry-runchanges nothing.- The security analyzer reads every file in a skill, not only Markdown:
scripts and configs besideSKILL.mdare audited too. It catches three
evasions that previously passed a strict audit, andimport-skillaudits a
candidate before copying it. doctor,statusandevidencework. All three crashed on every
invocation.- Dual licensing. AgtMLS is available under Apache-2.0 or MIT.
- Supply-chain artifacts validate. The SPDX SBOM now passes an SPDX
validator and covers every path the wheel ships;provenance.jsonis an
in-toto statement with a real timestamp.
Checksums
a29da4c283b6cf8e795f5ccbf788a672c27e58a90440e555e05b1331d2c11ddf agtmls-0.0.6-py3-none-any.whl
4dfd3c077d36d8913c334a740420ef49df0499f69a64fa34960b4f4c2522ea5b agtmls-0.0.6.tar.gz
ec70b41916b6142b106dd5c05f034f12ae9ff7dee37d98138a2b765dba40ff09 agtmls-anthropic-polyglot.tar.gz
6c25d871cfabf328ab267bb530983d1b7d43eecf2132645511d5e2bfd0f81f47 agtmls-continue-polyglot.tar.gz
61f444b1974fd28a294203447279338d95dfe92bf6aeae918877643538352a47 agtmls-cursor-polyglot.tar.gz
e43b00d35ef292e577ebc457ff084fc5e913d432843d3ad8b33c78b5f7169481 agtmls-deepseek-polyglot.tar.gz
b7133f82fb1592f728cd568fd20735d13a88530f6f8f20c80728ed106e4ae717 agtmls-generic-polyglot.tar.gz
4e99753f49433638cc3cedddb67cfb98fe8cbb77ff81cb639d95151d33950d99 agtmls-github-copilot-polyglot.tar.gz
75ff129cbcdb19b120854e1d7a4224f5a46f6e52b5ce3935a5df6d3132b5423f agtmls-google-gemini-polyglot.tar.gz
46e86dd5c2096ba39af0e75bced78df9beed93e79a2cfda151fa5d2add3c8bcb agtmls-mistral-polyglot.tar.gz
3922e1cda42a5e5b233eee19dde21e567e834845046152b40e9da6338a04e19d agtmls-ollama-polyglot.tar.gz
998760a49aa90cc402f5eff207085ecb3be594d20a9da40af18f0243feb1c27f agtmls-openai-polyglot.tar.gz
9316d07250f946348dbdcc6925867338f2e7b8733f26ef061769a530053066d5 agtmls-qwen-polyglot.tar.gz
54e01dacd3bf7a0c495ec36bab7d7a7e74adf467cbed8932846ccb357d33ff16 agtmls-windsurf-polyglot.tar.gz
7656df56d4ec559bf7a10bd35f9822882bcd020f213cfdc2e6e3743e75cdae6f agtmls-zed-polyglot.tar.gz
c49023a00409285cedee2d1b154b757e05b255de06ac779550dc01b8f29cb577 release-manifest.json
AgtMLS v0.0.5
Automated AgtMLS v0.0.5 release. Versions increment by exactly 0.0.1 on the 0.0.x line.
AgtMLS v0.0.4
Automated AgtMLS v0.0.4 release. Versions increment by exactly 0.0.1 on the 0.0.x line.
AgtMLS v0.0.3
Automated AgtMLS v0.0.3 release. Versions increment by exactly 0.0.1 on the 0.0.x line.
AgtMLS v0.0.2
AgtMLS v0.0.2 release. Versions increment by exactly 0.0.1 on the 0.0.x line. This release was published from the validated post-release tree without rewriting the protected v0.0.2 tag.