This program
APRF Research
- · StackRail originates the report
- · Public repository pinned to a SHA
- · APRF Auditor / CLI + defensive simulate
- · Triage, then upstream issue or hardening PR
Technical reports · APRF v0.11.0
StackRail assesses public AI, agent, MCP, and sandbox hosts at a pinned commit, records APRF Check evidence, and proposes the smallest upstream hardening. These are lab reports on a public tree—not news postmortems, not a vendor FAIL scorecard, and not exploit write-ups.
This program
APRF Research
Not this page
01 Pin
Clone URL, exact SHA, profile (Core / Framework), lenses.
02 Audit
APRF CLI against the tree, optionally a live base URL.
03 Simulate
Defensive gap + intended fix. No public exploit steps.
04 Triage
Vulnerability (CVE when earned), security bug, or control gap.
05 Harden
Upstream issue and/or PR. Private disclose first if CVE-track.
06 Report
Human-gated technical report on this catalog.
Protocol: docs/aprf-research/RUNBOOK.md. CVE only when earned. No public exploit payloads.
0 reports
No reports yet. Approved assessments appear here as technical reports (subject, SHA, method, triage, Checks, recommended hardening)—not as Incident Analysis articles.
Public tree @ SHA, not a production breach
Reports come from assessing a public repository at a pinned commit. Git is not the only source of truth: runtime config, cloud IAM, secrets stores, vendor consoles, CI variables, and production prompts often never appear in the tree. Incomplete evidence is not a vendor FAIL. We do not invent customers or CVE IDs, or publish exploit payloads.