← APRF

Technical reports · APRF v0.11.0

APRF Research

StackRail assesses public AI, agent, MCP, and sandbox hosts at a pinned commit, records APRF Check evidence, and proposes the smallest upstream hardening. These are lab reports on a public tree—not news postmortems, not a vendor FAIL scorecard, and not exploit write-ups.

This program

APRF Research

  • · StackRail originates the report
  • · Public repository pinned to a SHA
  • · APRF Auditor / CLI + defensive simulate
  • · Triage, then upstream issue or hardening PR

Not this page

Incident Analysis

  • · News, advisory, or CVE comes first
  • · Disclosed event, not our assessment
  • · Postmortem mapped to APRF Checks
  • · Lives under Articles

Method

  1. 01 Pin

    Clone URL, exact SHA, profile (Core / Framework), lenses.

  2. 02 Audit

    APRF CLI against the tree, optionally a live base URL.

  3. 03 Simulate

    Defensive gap + intended fix. No public exploit steps.

  4. 04 Triage

    Vulnerability (CVE when earned), security bug, or control gap.

  5. 05 Harden

    Upstream issue and/or PR. Private disclose first if CVE-track.

  6. 06 Report

    Human-gated technical report on this catalog.

Protocol: docs/aprf-research/RUNBOOK.md. CVE only when earned. No public exploit payloads.

Catalog

0 reports

No reports yet. Approved assessments appear here as technical reports (subject, SHA, method, triage, Checks, recommended hardening)—not as Incident Analysis articles.

Public tree @ SHA, not a production breach

Reports come from assessing a public repository at a pinned commit. Git is not the only source of truth: runtime config, cloud IAM, secrets stores, vendor consoles, CI variables, and production prompts often never appear in the tree. Incomplete evidence is not a vendor FAIL. We do not invent customers or CVE IDs, or publish exploit payloads.