Skip to main content
Glama
README.md
# πŸ•ΈοΈ Weave_Protocol

**Infrastructure security for AI agents. We attack what we defend.**

[![npm](https://img.shields.io/npm/v/@weave_protocol/cli.svg?label=cli)](https://www.npmjs.com/package/@weave_protocol/cli)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/cli.svg)](https://www.npmjs.com/package/@weave_protocol/cli)
[![npm](https://img.shields.io/npm/v/@weave_protocol/full.svg?label=full)](https://www.npmjs.com/package/@weave_protocol/full)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/full.svg)](https://www.npmjs.com/package/@weave_protocol/full)
[![npm](https://img.shields.io/npm/v/@weave_protocol/ward.svg?label=ward)](https://www.npmjs.com/package/@weave_protocol/ward)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/ward.svg)](https://www.npmjs.com/package/@weave_protocol/ward)
[![npm](https://img.shields.io/npm/v/@weave_protocol/adversary.svg?label=adversary&color=red)](https://www.npmjs.com/package/@weave_protocol/adversary)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/adversary.svg)](https://www.npmjs.com/package/@weave_protocol/adversary)
[![npm](https://img.shields.io/npm/v/@weave_protocol/agentsecbench.svg?label=agentsecbench&color=red)](https://www.npmjs.com/package/@weave_protocol/agentsecbench)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/agentsecbench.svg)](https://www.npmjs.com/package/@weave_protocol/agentsecbench)
[![npm](https://img.shields.io/npm/v/@weave_protocol/browser.svg?label=browser)](https://www.npmjs.com/package/@weave_protocol/browser)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/browser.svg)](https://www.npmjs.com/package/@weave_protocol/browser)
[![npm](https://img.shields.io/npm/v/@weave_protocol/adapter-claudecode.svg?label=adapter-claudecode)](https://www.npmjs.com/package/@weave_protocol/adapter-claudecode)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/adapter-claudecode.svg)](https://www.npmjs.com/package/@weave_protocol/adapter-claudecode)
[![npm](https://img.shields.io/npm/v/@weave_protocol/adapter-antigravity.svg?label=adapter-antigravity)](https://www.npmjs.com/package/@weave_protocol/adapter-antigravity)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/adapter-antigravity.svg)](https://www.npmjs.com/package/@weave_protocol/adapter-antigravity)
[![npm](https://img.shields.io/npm/v/@weave_protocol/adapter-msaf.svg?label=adapter-msaf)](https://www.npmjs.com/package/@weave_protocol/adapter-msaf)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/adapter-msaf.svg)](https://www.npmjs.com/package/@weave_protocol/adapter-msaf)
[![npm](https://img.shields.io/npm/v/@weave_protocol/hundredmen.svg?label=hundredmen)](https://www.npmjs.com/package/@weave_protocol/hundredmen)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/hundredmen.svg)](https://www.npmjs.com/package/@weave_protocol/hundredmen)
[![npm](https://img.shields.io/npm/v/@weave_protocol/mund.svg?label=mund)](https://www.npmjs.com/package/@weave_protocol/mund)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/mund.svg)](https://www.npmjs.com/package/@weave_protocol/mund)
[![npm](https://img.shields.io/npm/v/@weave_protocol/hord.svg?label=hord)](https://www.npmjs.com/package/@weave_protocol/hord)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/hord.svg)](https://www.npmjs.com/package/@weave_protocol/hord)
[![npm](https://img.shields.io/npm/v/@weave_protocol/domere.svg?label=domere)](https://www.npmjs.com/package/@weave_protocol/domere)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/domere.svg)](https://www.npmjs.com/package/@weave_protocol/domere)
[![npm](https://img.shields.io/npm/v/@weave_protocol/witan.svg?label=witan)](https://www.npmjs.com/package/@weave_protocol/witan)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/witan.svg)](https://www.npmjs.com/package/@weave_protocol/witan)
[![npm](https://img.shields.io/npm/v/@weave_protocol/tollere.svg?label=tollere)](https://www.npmjs.com/package/@weave_protocol/tollere)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/tollere.svg)](https://www.npmjs.com/package/@weave_protocol/tollere)
[![npm](https://img.shields.io/npm/v/@weave_protocol/yoxallismus.svg?label=yoxallismus&color=red)](https://www.npmjs.com/package/@weave_protocol/yoxallismus)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/yoxallismus.svg)](https://www.npmjs.com/package/@weave_protocol/yoxallismus)
[![npm](https://img.shields.io/npm/v/@weave_protocol/langchain.svg?label=langchain)](https://www.npmjs.com/package/@weave_protocol/langchain)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/langchain.svg)](https://www.npmjs.com/package/@weave_protocol/langchain)
[![npm](https://img.shields.io/npm/v/@weave_protocol/api.svg?label=api)](https://www.npmjs.com/package/@weave_protocol/api)
[![npm](https://img.shields.io/npm/dm/@weave_protocol/api.svg)](https://www.npmjs.com/package/@weave_protocol/api)
[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://opensource.org/licenses/Apache-2.0)

Make agent behavior verifiable, auditable, and cryptographically provable across any harness, any platform. Built as a TypeScript monorepo with MCP integration, blockchain anchoring, and β€” as of Q4 β€” a **published red-team engine that tests our own defenses**.

> **The thesis:** every security platform claims its defenses work. We're the first to publish the attacks that prove it. Same suite. Same scorecard. Same locked benchmark β€” applied to our own packages, every release.

---

## πŸš€ Get started in one command

```bash
npx @weave_protocol/cli init
```

The CLI detects your framework (LangChain, LlamaIndex, MCP, OpenAI, Anthropic, Microsoft, Google) and scaffolds the right security middleware for your stack. Or install everything at once:

```bash
npm install @weave_protocol/full
```

---

## πŸ†• What's New

### βš”οΈ Q4 Moat Quarter β€” *we attack what we defend*

The first agent security platform to publish its own offensive engine. Two new packages flipped the suite from purely defensive to **defense + offense in the same monorepo**, validated against each other:

| Package | Role | Version |
|---|---|---|
| [`@weave_protocol/adversary`](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary) | Offensive engine β€” 68 documented + novel attacks across 5 categories (IPI, tool-coercion, jailbreak, extraction, goal-corruption). Real Playwright browser target with 4 breach signal channels. Real-LLM demo mode via Anthropic API. | βœ… **v0.2.1** |
| [`@weave_protocol/agentsecbench`](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench) | Standardized benchmark β€” locked attack suites, tier grades A–F, paste-ready reports, side-by-side comparison | βœ… v0.1.0 |

**Trophy attacks** β€” documented in-the-wild incidents reproduced in the corpus:

- 🏦 **Atlan autonomous-fraud** (Dec 2025) β€” first documented agent-driven financial fraud
- πŸ”’ **EchoLeak** (CVE-2025-32711) β€” Microsoft Copilot zero-click exfil
- πŸ‘» **Brave/Comet OTP exfil** (2025) β€” browser agent secret leak via hidden CSS
- 🚫 **Forcepoint false copyright** (Apr 2026) β€” DoS via fake copyright claim

```bash
# Run the canonical benchmark against the demo target β€” proves the suite lands
npx @weave_protocol/agentsecbench run

# Or run the full 68-attack corpus directly
npx @weave_protocol/adversary demo
```

**Why this matters:** every model release, every WARD policy change, every adapter update can be re-benchmarked against the same locked suite. Did your score regress? `agentsecbench compare` will show you. Does your WARD policy actually defend anything? `--measure-ward-delta` will tell you. This is how a category gets defined.

**[See Adversary README β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary)** Β· **[See AgentSecBench README β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench)** Β· **[See METHODOLOGY.md β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench/METHODOLOGY.md)**

---

### πŸ’° Q4 Governance β€” autonomous spending caps

Every enterprise agent question today is *"what's my ceiling on this thing?"* β€” measured in dollars, not just tool calls. [`@weave_protocol/witan@1.1.0`](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan) answers it. Per-window budgets (run / hour / day / week / month) that gate LLM calls and tool calls, with three actions: **block**, **require approval/consensus**, or **notify**.

Multi-provider LLM pricing built in β€” Anthropic, OpenAI, Google, and local (free). Per-tool amount caps (`send_payment` max $500/day). Interactive TTY approval prompt for human-in-loop terminals. Async callback for Slack/PagerDuty/custom UIs. Safe defaults β€” never silent approval in non-interactive contexts.

```bash
npx @weave_protocol/witan@1.1.0 spending caps         # inspect WARD.md caps
npx @weave_protocol/witan@1.1.0 spending simulate     # dry-run scenarios
```

```yaml
# Extend your WARD.md:
spending_limits:
  - window: day
    budget: { usd: 5.00 }
    on_exceeded: require_approval
  - window: run
    budget: { tool_calls: 100 }
    on_exceeded: block
  - window: day
    budget:
      tools:
        send_payment: { max_amount_usd: 500 }
    on_exceeded: require_approval
```

Backward compatible with the existing `behavioral_limits.maxCostUSD`. In-memory storage in v1.1 with a pluggable interface for the v1.2 Redis/SQLite backends. Programmatic API via `import { SpendingTracker } from '@weave_protocol/witan/spending'`.

**[See Witan spending caps README β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan#-autonomous-spending-caps-v110)**

---

### πŸ” Yoxallismus v2 β€” post-quantum cipher (open beta)

[`@weave_protocol/yoxallismus@0.1.0-beta.0`](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus) β€” post-quantum cryptographic composition layer built on **NIST FIPS 203 (ML-KEM-768)** hybridized with X25519. AES-256-GCM AEAD, HKDF-SHA-256 KDF, symmetric ratchet for session forward secrecy. Composition, not invention β€” the primitives are NIST-standardized, the composition (PQ-hybrid KEM + agent-scoped context binding + ratcheting) is what's new.

```bash
# Explicit opt-in required β€” the beta tag is NOT installed by default
npm install @weave_protocol/yoxallismus@beta
```

```typescript
import { PQCipher } from '@weave_protocol/yoxallismus';

const alice = PQCipher.generateKeypair();
const bundle = PQCipher.encryptTo(PQCipher.publicKeyOf(alice), plaintext);
const message = PQCipher.decryptFrom(alice, bundle.ciphertext, bundle.payload);
```

**⚠️ EXPERIMENTAL β€” NOT AUDITED.** Do not use for regulated, medical, financial, or legal data. Validation is via public use, forks, community verification, and responsible disclosure β€” not paid audit. See [THREAT_MODEL.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/THREAT_MODEL.md) and [SECURITY.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/SECURITY.md) before adopting.

**Verify every claim yourself:**

```bash
npx @weave_protocol/yoxallismus@beta --package weave-yoxall test         # 13 reproducible-claims tests
npx @weave_protocol/yoxallismus@beta --package weave-yoxall audit-self   # 5 known-attack vectors
npx @weave_protocol/yoxallismus@beta --package weave-yoxall benchmark    # perf micro-benchmarks
```

Measured on Node 22, single-threaded: **3.1 ms hybrid keypair generation Β· 2.4 ms encap+decap Β· 0.024 ms AEAD (1 KB)** β€” comfortably under the <5 ms target.

**[See Yoxallismus README β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus)**

---

### πŸ›‘οΈ Four runtimes. Three vendors. One policy file.

The thesis was that [WARD.md](https://www.npmjs.com/package/@weave_protocol/ward) could be a **portable agent security standard** β€” write it once, enforce it everywhere. As of today, that's **shipped and live across the entire agent harness landscape**:

| Runtime | Vendor | Enforcer | Status |
|---|---|---|---|
| **MCP servers** | Open standard | [Hundredmen v1.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/hundredmen) | βœ… Live on npm |
| **Claude Code** | Anthropic | [adapter-claudecode v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-claudecode) | βœ… Live on npm |
| **Google Antigravity** (desktop + `agy` CLI + SDK) | Google | [adapter-antigravity v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-antigravity) | βœ… Live on npm |
| **Microsoft Agent Framework** | Microsoft | [adapter-msaf v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-msaf) | βœ… Live on npm |
| **Browser agents** | Open standard | [browser v0.1.0](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser) | βœ… Live on npm |

The same `WARD.md` file in your project root is now read and enforced by **Anthropic's, Google's, Microsoft's, MCP's, and the browser harness's runtimes** β€” without any platform-specific edits.

```
my-agent-project/
β”œβ”€β”€ AGENTS.md          # what the agent does
β”œβ”€β”€ SKILL.md           # how the agent does it
└── WARD.md            # what the agent can't do  ← all five surfaces respect this
```

---

### 🌐 Browser agent security (Q3) β€” fifth enforcement surface

[`@weave_protocol/browser`](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser) adds runtime IPI (indirect prompt injection) scanning to browser-driving agents. 33 detection patterns cover the documented threat surface: hidden CSS payloads, role-hijack directives, tool-call mimicry, action-injection directives, payment-recipient proximity patterns (Atlan), copyright-DoS markers (Forcepoint), and more.

Pair with the [Browser Guard extension](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser-extension) for client-side visibility into what your agent sees vs. what you see.

**[See browser README β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser)**

---

### πŸ“Š State of AI Agent Security: Q3 2026 Report

Industry analysis of agent security trends, platform maturity, supply chain risks, and market gaps. Live at: **[tyox-all.github.io/Weave_Protocol/q3-2026.html](https://tyox-all.github.io/Weave_Protocol/q3-2026.html)**

---

### Previously shipped (Q3)

- **adapter-msaf v0.1.0** β€” Microsoft Agent Framework enforcement via middleware. `WardMiddleware` class, one-line integration, Azure credential heuristic.
- **adapter-antigravity v0.1.0** β€” Google Antigravity enforcement. One install protects desktop + `agy` CLI + SDK.
- **adapter-claudecode v0.1.0** β€” Claude Code enforcement via PreToolUse hooks.
- **Hundredmen v1.1.0** β€” WARD.md is now the first gate in the MCP decision flow, ahead of reputation/drift/approval.
- **WARD.md v0.1.0** β€” Agent security policy standard. Ten domains: filesystem, network, capabilities, data boundaries, behavioral limits, multi-agent, compliance, verification, threat model, incident response. [Spec β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward/SPEC.md)
- **Tollere v0.2.2** β€” Multi-channel supply chain security. npm, PyPI, Cargo, Go, Maven, Docker Hub, VS Code Marketplace, Open VSX, JetBrains. Sandwich pattern detection.
- **Weave CLI v0.1.0 + Full Bundle v0.1.0** β€” `weave init` / `audit` / `dashboard` / `doctor`. One-command security setup.

---

## πŸ“¦ Packages

The suite is now organized into three layers β€” **defense**, **offensive**, and **operations**. All 17 packages live on npm under the `@weave_protocol` scope, plus one Python package on PyPI.

### πŸ›‘οΈ Defense Layer (12 packages)

The packages that keep your agent within policy: declare it, enforce it across every harness, scan everything that enters, encrypt everything that exits.

| Package | Version | Description |
|---|---|---|
| [πŸ›‘οΈ @weave_protocol/ward](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward) | 0.1.0 | **WARD.md** β€” agent security policy standard (parser, validator, runtime checks) |
| [πŸ›‘οΈ @weave_protocol/adapter-claudecode](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-claudecode) | 0.1.0 | **Claude Code adapter** β€” enforces WARD.md via PreToolUse hooks |
| [πŸ›‘οΈ @weave_protocol/adapter-antigravity](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-antigravity) | 0.1.0 | **Google Antigravity adapter** β€” enforces WARD.md across desktop, `agy` CLI, and SDK |
| [πŸ›‘οΈ @weave_protocol/adapter-msaf](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-msaf) | 0.1.0 | **Microsoft Agent Framework adapter** β€” middleware-based WARD enforcement |
| [🌐 @weave_protocol/browser](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser) | 0.1.0 | **Browser agent security** β€” runtime IPI scanner (33 patterns) for headless agents |
| [πŸ” @weave_protocol/hundredmen](https://github.com/Tyox-all/Weave_Protocol/blob/main/hundredmen) | 1.1.0 | **MCP proxy** β€” intercept, scan, gate tool calls; enforces WARD.md as first gate |
| [πŸ›‘οΈ @weave_protocol/mund](https://github.com/Tyox-all/Weave_Protocol/blob/main/mund) | 0.2.2 | **Scanner** β€” secrets, PII, injection, MCP vetting, threat intel |
| [πŸ›οΈ @weave_protocol/hord](https://github.com/Tyox-all/Weave_Protocol/blob/main/hord) | 0.1.6 | **Vault** β€” encrypted storage with Yoxallismus dual-tumbler cipher |
| [πŸ” @weave_protocol/yoxallismus](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus) | **0.1.0-beta.0** | **Post-quantum cipher** β€” X25519 + ML-KEM-768 hybrid KEM Β· AES-256-GCM Β· HKDF Β· ratcheting Β· ⚠️ NOT AUDITED |
| [βš–οΈ @weave_protocol/domere](https://github.com/Tyox-all/Weave_Protocol/blob/main/domere) | 1.3.4 | **Judge** β€” compliance (PCI-DSS, ISO27001, SOC2, HIPAA, GDPR, CCPA), blockchain anchoring |
| [πŸ‘₯ @weave_protocol/witan](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan) | **1.1.0** | **Council** β€” multi-agent consensus & governance, autonomous spending caps (Q4 v1.1) |
| [πŸ›‚ @weave_protocol/tollere](https://github.com/Tyox-all/Weave_Protocol/blob/main/tollere) | 0.2.2 | **Customs** β€” supply chain security (npm, PyPI, Docker, IDE extensions, sandwich detection) |

### βš”οΈ Offensive Layer (2 packages) β€” **NEW Q4**

The red team. We attack what we defend.

| Package | Version | Description |
|---|---|---|
| [βš”οΈ @weave_protocol/adversary](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary) | **0.2.1** | **Offensive engine** β€” 68 attacks Β· real Playwright browser target Β· real-LLM demo mode Β· WARD-aware attack selection |
| [🎯 @weave_protocol/agentsecbench](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench) | **0.1.0** | **Standardized benchmark** β€” locked suites (ASB-Browser-v1), tier grading A–F, trophy attacks, WARD delta, paste-ready reports |

### πŸ”§ Operations & Integrations (5 packages, plus 1 PyPI)

The front door, the dashboard, the bridges to other frameworks.

| Package | Version | Description |
|---|---|---|
| [πŸ•ΈοΈ @weave_protocol/cli](https://github.com/Tyox-all/Weave_Protocol/blob/main/cli) | 0.1.0 | **The `weave` CLI** β€” `init`, `audit`, `dashboard`, `doctor` |
| [πŸ“¦ @weave_protocol/full](https://github.com/Tyox-all/Weave_Protocol/blob/main/full) | 0.1.0 | **Bundle** β€” installs all packages in one command |
| [πŸ”Œ @weave_protocol/api](https://github.com/Tyox-all/Weave_Protocol/blob/main/api) | 1.1.1 | **REST API + Operator Dashboard** β€” `npx @weave_protocol/api` β†’ http://localhost:3000/dashboard |
| [πŸ”— @weave_protocol/langchain](https://github.com/Tyox-all/Weave_Protocol/blob/main/langchain) | **1.0.2** | **LangChain.js** security callbacks & tool wrappers (0 audit vulnerabilities via npm overrides) |
| [🐍 weave-protocol-llamaindex](https://github.com/Tyox-all/Weave_Protocol/blob/main/llamaindex-py) | 0.1.0 | **Python/LlamaIndex** security callbacks & tools (on PyPI) |

---

## πŸ€– AI Agent Skills

Each package includes a `SKILL.md` file following the [Claude Agent Skills specification](https://docs.anthropic.com/en/docs/claude-code/skills). These teach AI agents how to use Weave Protocol tools effectively.

| Package | Skill Name | Triggers |
|---|---|---|
| πŸ•ΈοΈ CLI | `weave-cli` | set up Weave, init project, scaffold security, audit, dashboard, doctor |
| πŸ›‘οΈ Ward | `ward` | WARD.md, agent security policy, guardrails, lock down agent |
| πŸ›‘οΈ adapter-claudecode | `adapter-claudecode` | secure Claude Code, install WARD hooks, block Claude Code actions |
| πŸ›‘οΈ adapter-antigravity | `adapter-antigravity` | secure Antigravity, agy hooks, block GCP credential reads |
| πŸ›‘οΈ adapter-msaf | `adapter-msaf` | secure MSAF agent, WardMiddleware, lock down Copilot SDK, Azure enforcement |
| 🌐 browser | `browser-security` | secure browser agent, IPI scanning, hidden CSS detection, page-context safety |
| πŸ›‘οΈ Mund | `security-scanning` | scan, detect secrets, check injection, vet MCP server, threat intel |
| πŸ›οΈ Hord | `encrypting-data` | encrypt, decrypt, vault, Yoxallismus, protect |
| πŸ” Yoxallismus | `pq-crypto` | post-quantum, ML-KEM, Kyber, hybrid KEM, PQ-hybrid, quantum-safe |
| βš–οΈ Domere | `compliance-auditing` | audit, checkpoint, SOC2, HIPAA, PCI-DSS, GDPR, CCPA, blockchain |
| πŸ‘₯ Witan | `consensus-governance` | consensus, vote, approve, policy, escalate |
| πŸ” Hundredmen | `security-inspection` | intercept, drift, reputation, approve, block, live feed, enforce WARD |
| πŸ›‚ Tollere | `supply-chain-security` | npm install, docker pull, install extension, typosquat, CVE, sandwich pattern |
| βš”οΈ Adversary | `adversarial-testing` | red-team agent, attack, penetration test, find vulnerabilities, IPI test, run attack corpus |
| 🎯 AgentSecBench | `security-benchmarking` | benchmark agent, security score, tier grade, ASB-Browser, citable security report, compare runs |
| πŸ”— Langchain | `langchain-security` | LangChain, callback, secure tool, RAG security, PII redaction |
| πŸ”Œ API | `weave-api-calling` | REST API, HTTP endpoint, curl, fetch |

**Installation:**

The SKILL.md format is shared across Claude Code and Antigravity, so the same files work for both β€” only the install path differs.

```bash
git clone https://github.com/Tyox-all/Weave_Protocol.git
cd Weave_Protocol

# For Claude Code:
mkdir -p ~/.claude/skills/weave-protocol
cp */SKILL.md ~/.claude/skills/weave-protocol/

# For Google Antigravity (global, all sessions):
mkdir -p ~/.gemini/antigravity-cli/skills/weave-protocol
cp */SKILL.md ~/.gemini/antigravity-cli/skills/weave-protocol/

# Or per-project under .agents/:
mkdir -p .agents/skills/weave-protocol
cp /path/to/Weave_Protocol/*/SKILL.md .agents/skills/weave-protocol/
```

For **Microsoft Agent Framework**, skills aren't used β€” MSAF is code-level. Use the `WardMiddleware` class from `@weave_protocol/adapter-msaf` instead.

---

## πŸš€ Quick Start

### Option 1: Guided setup (recommended)

```bash
npx @weave_protocol/cli init
```

### Option 2: Install everything

```bash
npm install @weave_protocol/full
```

### Option 3: Install individual packages

```bash
npm install @weave_protocol/mund @weave_protocol/tollere @weave_protocol/ward
```

### Option 4: Benchmark first, defend second

```bash
# See what attacks land on your agent before you start hardening
npx @weave_protocol/agentsecbench run --measure-ward-delta
```

### Claude Desktop Integration (MCP)

Add to `claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "mund":       { "command": "npx", "args": ["-y", "@weave_protocol/mund"] },
    "hord":       { "command": "npx", "args": ["-y", "@weave_protocol/hord"] },
    "domere":     { "command": "npx", "args": ["-y", "@weave_protocol/domere"] },
    "hundredmen": { "command": "npx", "args": ["-y", "@weave_protocol/hundredmen"] },
    "tollere":    { "command": "npx", "args": ["-y", "@weave_protocol/tollere"] }
  }
}
```

### Claude Code / Antigravity / MSAF Integration

```bash
# Anthropic
npm install -g @weave_protocol/adapter-claudecode && weave-claude-code init

# Google
npm install -g @weave_protocol/adapter-antigravity && weave-antigravity init

# Microsoft (code-level)
npm install @weave_protocol/adapter-msaf
```

```typescript
import { WardMiddleware } from '@weave_protocol/adapter-msaf';
const ward = new WardMiddleware();
agent.useFunctionMiddleware(ward.functionMiddleware());
```

Drop a `WARD.md` in your project root. Any (or all) of the adapters will gate every tool call.

---

## ✨ Package Details

### πŸ•ΈοΈ CLI β€” One Command for Everything

```bash
npx @weave_protocol/cli init        # detect framework, scaffold middleware
npx @weave_protocol/cli audit       # supply chain scan (Tollere)
npx @weave_protocol/cli dashboard   # launch monitoring UI
npx @weave_protocol/cli doctor      # environment health check
```

πŸ“„ **Skill:** [`weave-cli`](https://github.com/Tyox-all/Weave_Protocol/blob/main/cli/SKILL.md)

---

### πŸ›‘οΈ Ward β€” The Policy Standard

WARD.md files declare what an agent is allowed to do, version-controlled alongside `AGENTS.md` and `SKILL.md`.

| Section | Controls |
|---|---|
| **Filesystem** | Read/write/execute/delete/list rules with glob patterns |
| **Network** | Outbound HTTP allowlist with optional method restrictions |
| **Capabilities** | Tools the agent may invoke (with optional approval gating) |
| **Data Boundaries** | Egress classifications (PII, PHI, credentials...) and redaction |
| **Behavioral Limits** | Iterations, runtime, cost, tokens, tool calls |
| **Multi-Agent** | Trust chain, isolation level, semantic drift threshold |
| **Compliance** | SOC2 / HIPAA / GDPR / CCPA / ISO27001 / PCI-DSS |
| **Verification** | Attestation backend (Dōmere), blockchain, frequency |
| **Threat Model** | In-scope / out-of-scope threats |
| **Incident Response** | Actions on violation (log / alert / terminate / attest) |

Enforced at runtime by five independent surfaces: Hundredmen (MCP), adapter-claudecode (Claude Code), adapter-antigravity (Antigravity), adapter-msaf (Microsoft Agent Framework), and browser (Browser agents).

πŸ“„ **Skill:** [`ward`](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward/SKILL.md) Β· πŸ“‹ **Spec:** [WARD.md SPEC β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/ward/SPEC.md)

---

### πŸ›‘οΈ The Harness Adapters

All four enforcement surfaces share the same WARD.md file. Pick the adapter(s) for your harness:

- **[adapter-claudecode](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-claudecode)** β€” Claude Code via PreToolUse hooks
- **[adapter-antigravity](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-antigravity)** β€” Google Antigravity (one install, three surfaces)
- **[adapter-msaf](https://github.com/Tyox-all/Weave_Protocol/blob/main/adapter-msaf)** β€” Microsoft Agent Framework via middleware
- **[browser](https://github.com/Tyox-all/Weave_Protocol/blob/main/browser)** β€” Browser agents (Playwright/Stagehand/Puppeteer-driven), 33-pattern IPI scanner

WARD resolution (all adapters): `$WEAVE_WARD_PATH` β†’ `<cwd>/WARD.md` β†’ `<cwd>/.weave/WARD.md` β†’ harness-specific user-global location.

---

### πŸ›‘οΈ Mund β€” The Guardian

Real-time security scanning for AI agents. Catches secrets (30+ patterns), PII, prompt injection, dangerous code, malicious MCP server descriptions. Threat intel auto-updates from community feeds.

πŸ“„ **Skill:** [`security-scanning`](https://github.com/Tyox-all/Weave_Protocol/blob/main/mund/SKILL.md)

---

### πŸ›οΈ Hord β€” The Vault

Encrypted storage with the Yoxallismus dual-tumbler cipher. AES-256-GCM, ChaCha20-Poly1305, Argon2id key derivation, secure memory handling.

πŸ“„ **Skill:** [`encrypting-data`](https://github.com/Tyox-all/Weave_Protocol/blob/main/hord/SKILL.md)

---

### πŸ” Yoxallismus β€” Post-Quantum Cipher (open beta)

Standalone post-quantum cryptographic composition layer. NIST FIPS 203 (ML-KEM-768) hybridized with X25519 for the KEM, AES-256-GCM for AEAD, HKDF-SHA-256 for KDF, symmetric ratchet for session forward secrecy. Composition over invention β€” all primitives NIST-standardized or de facto industry standard.

⚠️ **EXPERIMENTAL. NOT AUDITED.** Do not use for regulated, medical, financial, or legal data. Validation is via public use, forks, and responsible disclosure β€” not paid audit.

```bash
# Explicit opt-in required β€” beta tag not installed by default
npm install @weave_protocol/yoxallismus@beta

# CLI subcommands
weave-yoxall status         # library posture + known limitations
weave-yoxall keygen         # hybrid keypair (X25519 + ML-KEM-768)
weave-yoxall encrypt        # encrypt to a recipient's public key
weave-yoxall decrypt        # decrypt with private key
weave-yoxall test           # reproducible-claims tests
weave-yoxall audit-self     # known-attack test vectors
weave-yoxall benchmark      # perf micro-benchmarks
```

**Performance** β€” 3.1 ms hybrid keypair generation Β· 2.4 ms encap+decap Β· 0.024 ms AEAD (1 KB), all under the <5 ms target.

πŸ“„ **Skill:** [`pq-crypto`](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/SKILL.md) Β· πŸ“‹ **Threat model:** [THREAT_MODEL.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/THREAT_MODEL.md) Β· πŸ”’ **Disclosure:** [SECURITY.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus/SECURITY.md)

---

### βš–οΈ Domere β€” The Judge

Enterprise-grade verification, orchestration, compliance, and audit infrastructure. SOC2, HIPAA, PCI-DSS, ISO27001, GDPR, CCPA. Solana and Ethereum blockchain anchoring for immutable audit trails.

**Blockchain Anchoring:**

- Solana Mainnet: `6g7raTAHU2h331VKtfVtkS5pmuvR8vMYwjGsZF1CUj2o`
- Solana Devnet: `BeCYVJYfbUu3k2TPGmh9VoGWeJwzm2hg2NdtnvbdBNCj`
- Ethereum: `0xAA8b52adD3CEce6269d14C6335a79df451543820`

πŸ“„ **Skill:** [`compliance-auditing`](https://github.com/Tyox-all/Weave_Protocol/blob/main/domere/SKILL.md)

---

### πŸ‘₯ Witan β€” The Council

Multi-agent consensus and governance. Unanimous, majority, weighted, and quorum protocols. Rule enforcement, escalation, agent bus.

**New in v1.1.0** β€” autonomous spending caps. Per-window budgets on LLM cost, tokens, tool calls, and per-tool spend limits. Gated by three actions: `block`, `require_approval`, `notify`. Multi-provider LLM pricing built in (Anthropic, OpenAI, Google, local). Interactive TTY prompt or async callback for approval workflows. Safe defaults for non-interactive contexts.

```bash
npx @weave_protocol/witan spending caps        # inspect WARD.md spending caps
npx @weave_protocol/witan spending simulate    # dry-run scenarios
```

```typescript
import { SpendingTracker } from '@weave_protocol/witan/spending';

const tracker = new SpendingTracker({
  caps: [{ window: 'day', budget: { usd: 5.00 }, onExceeded: 'require_approval' }],
});
const check = await tracker.checkAction({ kind: 'tool', tool: 'send_payment', amountUSD: 1000 });
if (check.blocked) throw new Error(check.reason);
if (check.requiresApproval && !(await check.approve!())) throw new Error('denied');
```

πŸ“„ **Skill:** [`consensus-governance`](https://github.com/Tyox-all/Weave_Protocol/blob/main/witan/SKILL.md)

---

### πŸ” Hundredmen β€” The Watchers

Real-time MCP security proxy. v1.1.0 enforces WARD.md as the first gate in the decision flow, ahead of reputation, drift, and approval checks.

πŸ“„ **Skill:** [`security-inspection`](https://github.com/Tyox-all/Weave_Protocol/blob/main/hundredmen/SKILL.md)

---

### πŸ›‚ Tollere β€” The Customs Inspector

Supply chain security for AI-generated code. Catches malicious packages, Docker images, and IDE extensions **before** they reach `node_modules/`, your container, or your editor. npm, PyPI, Cargo, Go, Maven, Docker Hub, VS Code Marketplace, Open VSX, JetBrains.

πŸ“„ **Skill:** [`supply-chain-security`](https://github.com/Tyox-all/Weave_Protocol/blob/main/tollere/SKILL.md)

---

### βš”οΈ Adversary β€” The Red Team

Where the other packages defend, Adversary attacks. 68 documented and novel attacks across 5 categories: IPI (33), tool-use coercion (15), jailbreak (10), extraction (5), goal corruption (5). Three targets: pattern-mock (CI smoke tests, no API), real-LLM (`--real` via Anthropic API, ~$0.02/full run), and real-browser (Playwright with four breach signal channels: network, form, DOM, console). WARD-aware attack selection prioritizes probes against capabilities your policy claims to enforce.

```bash
npx @weave_protocol/adversary demo               # mock, ~50ms
npx @weave_protocol/adversary demo --real        # real LLM, ~$0.02
npx @weave_protocol/adversary attack --url=...   # real browser agent
npx @weave_protocol/adversary demo --real --redact-evidence   # shareable scorecard
```

Locked scorecard schema v1.0 β€” consumed unchanged by AgentSecBench.

πŸ“„ **Skill:** [`adversarial-testing`](https://github.com/Tyox-all/Weave_Protocol/blob/main/adversary/SKILL.md)

---

### 🎯 AgentSecBench β€” The Benchmark

The interpretation layer on top of Adversary. Locked, versioned attack suites that produce tier-graded reports. `ASB-Browser-v1` (v1.0) is 40 curated attacks: all 33 IPI + 4 critical tool-coercion + 3 highest-impact extraction.

```bash
npx @weave_protocol/agentsecbench run                          # default suite, tier-graded report
npx @weave_protocol/agentsecbench run --measure-ward-delta     # quantify policy effectiveness
npx @weave_protocol/agentsecbench compare baseline.json new.json
```

Tier grades A–F, four trophy attacks (Atlan, EchoLeak, Brave/Comet, Forcepoint), category gap analysis, optional WARD delta, plain-English interpretation prose. Reports are paste-ready Markdown β€” for blog posts, RFP responses, vendor audits, internal reviews.

πŸ“„ **Skill:** [`security-benchmarking`](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench/SKILL.md) Β· πŸ“‹ **Methodology:** [METHODOLOGY.md β†’](https://github.com/Tyox-all/Weave_Protocol/blob/main/agentsecbench/METHODOLOGY.md)

---

### πŸ”Œ API + Operator Dashboard

```bash
npx @weave_protocol/api
# β†’ http://localhost:3000/dashboard
```

Live monitoring across all five enforcement surfaces in one view. The dashboard renders WARD.md at the top of a hierarchy diagram, fanning out to your configured enforcers (Hundredmen + the three vendor adapters + browser). Surfaces you're not using appear dimmed, so it's instantly clear what's protecting your agent versus what's available.

Includes a live activity feed (allows / denies / IPI detections / approvals), a WARD policy panel, and 24-hour aggregate stats. Auto-refreshes every 5 seconds. Monochrome design β€” built for ops rooms, not marketing decks.

πŸ“„ **Skill:** [`weave-api-calling`](https://github.com/Tyox-all/Weave_Protocol/blob/main/api/SKILL.md)

---

### πŸ”— Langchain β€” The Bridge

Security integration for LangChain.js applications. Drop-in callbacks, secured tool wrappers, RAG retriever scanning with PII redaction.

πŸ“„ **Skill:** [`langchain-security`](https://github.com/Tyox-all/Weave_Protocol/blob/main/langchain/SKILL.md)

---

## πŸ—οΈ Architecture

```mermaid
flowchart TD
    CLI["πŸ•ΈοΈ <b>weave init / audit</b><br/><i>front door β€” @weave_protocol/cli</i>"]
    WARD["πŸ›‘οΈ <b>WARD.md</b><br/><i>policy standard β€” declares what the agent can't do</i>"]
    CLI --> WARD

    WARD -.->|enforced at runtime by| HM
    WARD -.->|enforced at runtime by| CC
    WARD -.->|enforced at runtime by| AG
    WARD -.->|enforced at runtime by| MSAF
    WARD -.->|enforced at runtime by| BR

    HM["πŸ” <b>Hundredmen</b><br/>MCP layer<br/><i>open standard</i>"]
    CC["πŸ›‘οΈ <b>adapter-claudecode</b><br/>Anthropic<br/>βœ… Live"]
    AG["πŸ›‘οΈ <b>adapter-antigravity</b><br/>Google Β· desktop + agy + SDK<br/>βœ… Live"]
    MSAF["πŸ›‘οΈ <b>adapter-msaf</b><br/>Microsoft Β· middleware<br/>βœ… Live"]
    BR["🌐 <b>browser</b><br/>Browser agents<br/>βœ… Live"]

    HM --> AGENT
    CC --> AGENT
    AG --> AGENT
    MSAF --> AGENT
    BR --> AGENT

    subgraph AGENT["πŸ€– AI Agent System"]
        direction TB
        subgraph CORE["Defense β€” Core security"]
            direction LR
            MUND["πŸ›‘οΈ Mund<br/>Guardian<br/><i>scanning</i>"]
            HORD["πŸ›οΈ Hord<br/>Vault<br/><i>encryption</i>"]
            DOMERE["βš–οΈ Domere<br/>Judge<br/><i>compliance</i>"]
            WITAN["πŸ‘₯ Witan<br/>Council<br/><i>consensus</i>"]
        end
        subgraph OPS["Operations"]
            direction LR
            TOLLERE["πŸ›‚ Tollere<br/>Customs<br/><i>supply chain</i>"]
            API["πŸ”Œ API + Dashboard<br/><i>REST + UI</i>"]
            LC["πŸ”— LangChain bridge"]
        end
        CORE --> OPS
    end

    subgraph OFFENSIVE["βš”οΈ Offensive β€” we attack what we defend"]
        direction LR
        ADV["βš”οΈ <b>Adversary</b><br/>68 attacks Β· 5 categories<br/><i>offensive engine</i>"]
        ASB["🎯 <b>AgentSecBench</b><br/>locked suites Β· tier A–F<br/><i>citable benchmark</i>"]
        ADV --> ASB
    end

    AGENT -.->|attacked by| OFFENSIVE
    OFFENSIVE -.->|scorecards inform| WARD

    classDef policy fill:#1f2937,stroke:#60a5fa,stroke-width:2px,color:#fff
    classDef enforcer fill:#064e3b,stroke:#10b981,stroke-width:2px,color:#fff
    classDef core fill:#312e81,stroke:#818cf8,stroke-width:1px,color:#fff
    classDef ops fill:#1e3a8a,stroke:#60a5fa,stroke-width:1px,color:#fff
    classDef offensive fill:#7f1d1d,stroke:#ef4444,stroke-width:2px,color:#fff

    class CLI,WARD policy
    class HM,CC,AG,MSAF,BR enforcer
    class MUND,HORD,DOMERE,WITAN core
    class TOLLERE,API,LC ops
    class ADV,ASB offensive
```

The diagram shows the loop. Defense surfaces enforce the policy at runtime. The offensive engine attacks the agent. Scorecards feed back into WARD as new evidence β€” what attacks land, which need new policy domains, what regressed since the last release. **The loop is what makes the moat.**

---

## πŸ” Security Model

Defense-in-depth across the entire AI agent lifecycle, validated continuously by an offensive engine that lives in the same monorepo:

1. **πŸ›‘οΈ Ward** declares what the agent can and can't do (policy-as-code)
2. **πŸ›‘οΈ Harness adapters** enforce WARD inside the IDE / CLI / framework:
   - `adapter-claudecode` for Claude Code (PreToolUse hooks)
   - `adapter-antigravity` for Google Antigravity (PreToolUse hooks across desktop/CLI/SDK)
   - `adapter-msaf` for Microsoft Agent Framework (middleware pipeline)
   - `browser` for browser-driving agents (runtime IPI scanning)
3. **πŸ›‚ Tollere** inspects every dependency, image, and extension before it enters your project
4. **πŸ›‘οΈ Mund** scans all inputs for threats before processing
5. **πŸ›οΈ Hord** encrypts sensitive data at rest and in transit
6. **βš–οΈ Domere** logs all actions with tamper-evident checksums and blockchain anchoring
7. **πŸ‘₯ Witan** requires consensus for high-risk operations
8. **πŸ” Hundredmen** intercepts and gates tool calls in real-time β€” enforcing WARD policy at the MCP layer
9. **πŸ”— Langchain / Python** secures LangChain.js and LlamaIndex chains and agents
10. **βš”οΈ Adversary** attacks the entire stack with 68 documented and novel attacks
11. **🎯 AgentSecBench** scores it, grades it A–F, and reports it in a standardized, citable format

### CORS Model Integration

| CORS Layer | Weave Package | Function |
|---|---|---|
| **Policy** | πŸ›‘οΈ Ward | Declares allowed/denied actions, behavioral limits, attestation requirements |
| **Policy Enforcement (Claude Code)** | πŸ›‘οΈ adapter-claudecode | Reads WARD, gates Claude Code tool calls via hooks |
| **Policy Enforcement (Antigravity)** | πŸ›‘οΈ adapter-antigravity | Reads WARD, gates Antigravity calls across desktop/CLI/SDK |
| **Policy Enforcement (MSAF)** | πŸ›‘οΈ adapter-msaf | Reads WARD, gates Microsoft Agent Framework calls via middleware |
| **Policy Enforcement (Browser)** | 🌐 browser | Runtime IPI scanning for browser-driving agents |
| **Policy Enforcement (MCP)** | πŸ” Hundredmen | Reads WARD, gates tool calls at the MCP layer |
| **Supply Chain** | πŸ›‚ Tollere | Vets dependencies, images, extensions before install |
| **Origin Validation** | πŸ›‘οΈ Mund | Validates input sources, detects injection |
| **Context Integrity** | πŸ›οΈ Hord | Protects data integrity through encryption |
| **Deterministic Enforcement** | βš–οΈ Domere | Ensures consistent policy application |
| **Adversarial Validation** | βš”οΈ Adversary + 🎯 AgentSecBench | Continuously tests every layer above |

---

## πŸ› οΈ Development

```bash
git clone https://github.com/Tyox-all/Weave_Protocol.git
cd Weave_Protocol

# Build each package
for pkg in mund hord domere witan hundredmen tollere langchain api cli ward \
           adapter-claudecode adapter-antigravity adapter-msaf browser \
           adversary agentsecbench; do
  (cd $pkg && npm install && npm run build)
done
```

---

## πŸ—ΊοΈ Roadmap

### Shipped

- [x] GDPR / CCPA / SOC2 / HIPAA / PCI-DSS / ISO27001 compliance frameworks
- [x] MCP server reputation scoring
- [x] Automated threat intelligence updates
- [x] LangChain.js integration package
- [x] Python/LlamaIndex integration
- [x] Web dashboard for monitoring
- [x] Supply chain security (Tollere) β€” npm, PyPI, Cargo, Go, Maven, Docker images, IDE extensions, sandwich pattern detection
- [x] Bundle package + CLI (`weave init`)
- [x] WARD.md agent security policy standard
- [x] Hundredmen ↔ WARD enforcement integration (v1.1.0)
- [x] **Claude Code harness adapter** (Anthropic)
- [x] **Google Antigravity harness adapter** (Google)
- [x] **Microsoft Agent Framework harness adapter** (Microsoft)
- [x] **Cross-platform thesis complete β€” same WARD.md works across all three major vendor harnesses + MCP**

### H2 2026 Q3 β€” Adoption Quarter

- [x] Browser agent security (`@weave_protocol/browser`)
- [x] Dashboard v2 with orchestration visualization
- [x] **[State of AI Agent Security: Q3 Report](https://tyox-all.github.io/Weave_Protocol/q3-2026.html)** β€” Industry analysis of agent security trends, platform maturity, supply chain risks, and market gaps

### H2 2026 Q4 β€” Moat Quarter

- [x] **Adversarial agents** (`@weave_protocol/adversary` v0.2.1) β€” 68 documented + novel attacks, real Playwright browser target, real-LLM demo mode
- [x] **AgentSecBench** (`@weave_protocol/agentsecbench` v0.1.0) β€” standardized benchmark, tier grades A–F
- [x] **Witan autonomous spending caps** (`@weave_protocol/witan` v1.1.0) β€” per-window budgets on LLM cost + tokens + tool calls, gated by block / approval / notify
- [x] **Yoxallismus v2** (`@weave_protocol/yoxallismus@0.1.0-beta.0`) β€” **open beta shipped**. PQ-hybrid KEM (X25519 + ML-KEM-768 / NIST FIPS 203) + AEAD + ratcheting. Unaudited by design; validated by public use, forks, and responsible disclosure. v0.2+ adds DH double-ratchet, cascade cipher, threshold encryption; v0.3+ adds ZK/VDF/QRNG; v0.4+ adds FHE. See [yoxallismus/README.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/yoxallismus).

---

## 🀝 Contributing

Bug reports and feature requests welcome via [GitHub Issues](https://github.com/Tyox-all/Weave_Protocol/issues).

For security issues, please see [SECURITY.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/SECURITY.md).

For all other inquiries: **<TYox-all@tutamail.com>**

See [CONTRIBUTING.md](https://github.com/Tyox-all/Weave_Protocol/blob/main/CONTRIBUTING.md) for guidelines.

---

## πŸ“„ License

Apache 2.0 β€” See [LICENSE](https://github.com/Tyox-all/Weave_Protocol/blob/main/LICENSE)

---

## πŸ”— Links

- **GitHub:** <https://github.com/Tyox-all/Weave_Protocol>
- **npm packages:** <https://www.npmjs.com/~tyox-all>
- **PyPI:** <https://pypi.org/project/weave-protocol-llamaindex/>
- **MCP Registry:** <https://registry.modelcontextprotocol.io> (search "mund")
- **Q3 2026 Report:** <https://tyox-all.github.io/Weave_Protocol/q3-2026.html>
- **Adversary on npm:** <https://www.npmjs.com/package/@weave_protocol/adversary>
- **AgentSecBench on npm:** <https://www.npmjs.com/package/@weave_protocol/agentsecbench>

---

*Built with ❀️ for the AI agent ecosystem. We attack what we defend.*