Agentic runtime for KAOS: Runner, SessionMemory (with reflexion lessons), 5 patterns (Chat/PlanExecute/Research/Findings/Router), 14 MCP tools, FastAPI REST API, audit-trail telemetry recorder.
- capability exposure inferred + 28
- recent drift inferred + 12
- tool safety inferred + 12
- trust mitigators mixed − 3
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 1m ago · see ecosystem CVEs →
- B · 25 → C · 49
- A · 0 → B · 25
No known CVEs for this server.
- high dangerous code
committed secret: Anthropic key · dynamic exec: eval()/exec(), __import__()
analyzed commit 2984dfb · analyzer v28 · 3h ago
skills & prompt files 2
- agent-rules 273v-kaos-agents-2984dfb/AGENTS.md
- agent-rules 273v-kaos-agents-2984dfb/CLAUDE.md
danger signals5
- dynamic code execution eval()/exec() 273v-kaos-agents-2984dfb/tests/integration/test_patterns_live.py :55
result = eval(expr, {"__builtins__": {}}, {}) - dynamic code execution eval()/exec() 273v-kaos-agents-2984dfb/tests/integration/test_streaming_live.py :117
result = eval(expr, {"__builtins__": {}}, {}) - dynamic code execution __import__() 273v-kaos-agents-2984dfb/tests/scratch/cli_smoke_post_release.py :36
mod = __import__(pkg) - dynamic code execution __import__() 273v-kaos-agents-2984dfb/tests/unit/events/test_emission_coverage.py :63
__import__(f"{events_pkg.__name__}.{mod_info.name}") - committed secret Anthropic key 273v-kaos-agents-2984dfb/tests/integration/test_auth_failure_live.py :55
sk-ant…(43 chars, redacted)
- recent drift +12 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of 273v.