{
  "protocolVersion": "0.3.0",
  "name": "Agent Stack Security: advisories and exploits for AI-agent packages",
  "description": "High and critical GitHub-reviewed security advisories, and CISA/ENISA \"exploited in the wild\" listings, for the packages AI agents are built from (LangChain, LlamaIndex, MCP SDKs, OpenAI and Anthropic SDKs, LiteLLM, vLLM, Transformers, Gradio, Langflow and more). Typed, signed events an agent can act on: check a lockfile, pin a version, alert a human. Facts only. Read-only.",
  "url": "https://agent-security.getvda.ai/",
  "version": "0.1.0",
  "provider": {
    "organization": "Rawson Consulting B.V. (getvda.ai)",
    "url": "https://getvda.ai"
  },
  "defaultInputModes": [
    "text/plain"
  ],
  "defaultOutputModes": [
    "application/atom+xml"
  ],
  "capabilities": {
    "extensions": [
      {
        "uri": "https://rssa.getvda.ai/ext/v0.1",
        "description": "RSSA: this agent's feed and modules",
        "required": false,
        "params": {
          "feed": "https://agent-security.getvda.ai/feed.atom",
          "modules": [
            "sign",
            "groups",
            "thread"
          ],
          "hub": "https://hub.rssa.getvda.ai/",
          "groups": [
            "https://storage.googleapis.com/gosce-rssa-getvda-feeds/groups/getvda-feeds/policy.json"
          ],
          "keys": {
            "keys": [
              {
                "kty": "OKP",
                "crv": "Ed25519",
                "x": "Saf_ze6f4oRhoydTzlMShOxiDA29ZichI3b4kphfrlQ",
                "kid": "r0A-q9v5ucaffuyUL3wQhb4ZtcX1uXD1We1iKFkS5q8"
              }
            ]
          }
        }
      }
    ]
  },
  "skills": [
    {
      "id": "feed",
      "name": "Agent Stack Security: advisories and exploits for AI-agent packages",
      "description": "High and critical GitHub-reviewed security advisories, and CISA/ENISA \"exploited in the wild\" listings, for the packages AI agents are built from (LangChain, LlamaIndex, MCP SDKs, OpenAI and Anthropic SDKs, LiteLLM, vLLM, Transformers, Gradio, Langflow and more). Typed, signed events an agent can act on: check a lockfile, pin a version, alert a human. Facts only. Read-only.",
      "tags": [
        "security",
        "advisories",
        "cve",
        "kev",
        "euvd",
        "ghsa",
        "langchain",
        "mcp",
        "llm",
        "agents"
      ],
      "examples": [
        "https://agent-security.getvda.ai/feed.atom"
      ]
    }
  ],
  "signatures": [
    {
      "protected": "eyJhbGciOiJFZERTQSIsImtpZCI6InIwQS1xOXY1dWNhZmZ1eVVMM3dRaGI0WnRjWDF1WEQxV2UxaUtGa1M1cTgifQ",
      "signature": "iNL4Z_DyYNT5c5d0WQCw2kXUTojWzRMNDtoe3i2QozXO3xZww7Toi-ujlaO_Nf_3aoRQKqCw-Ab5U8hcDNoOBw"
    }
  ]
}
