Rainkernel

Open source

The tools ship in public. We charge for the evidence.

Our attack corpus, evaluation harness and scanner are released under Apache-2.0 on GitHub, so buyers can read exactly what the Gate runs and integrators can build on it. First tagged release: 18 October 2026.

Repository 01

Readiness Kit

The engine of the Agent Readiness Gate, in public: the attack corpus, the rubric and the scripts that turn an agent's real failures into an evaluation harness and a cost number. Buyers can read exactly what the Gate runs; integrators can build on it.

First release
v0.1 — 18 October 2026
Licence
Apache-2.0
Repository
rainkernel/readiness-kit — public at release on github.com/rainkernel
Status
Private until the tag; public on 18 October 2026

What is in it

  • attack-pack/Agent-specific attack cases mapped to OWASP ASI01–ASI10: tool-description poisoning, SKILL.md and CLAUDE.md context-file poisoning, form-input exfiltration (PipeLeak pattern), tool-chain cost amplification, over-permission probes.
  • harness/Seeds an evaluation set of 20–50 tasks from an agent's logged failures and real traffic; scores runs against expected outcomes; keeps a held-out split so the number cannot be gamed.
  • cost/Cost-per-task baseline: tokens, retries and tool calls per completed task from OpenTelemetry-style traces; projection to production volume.
  • bom/Emits a CycloneDX-shaped Agent Bill of Materials — models, prompts, tools, MCP servers, skills, data sources — from a running agent's configuration.
  • rubric/The 8-area readiness scorecard and the Evidence Report template for engineering, CISO and audit readers.
  • adapters/Runners for snyk-agent-scan, Cisco mcp-scanner, Agentic Radar and Promptfoo, so the Kit orchestrates the open scanners rather than re-implementing them.

Release plan

  1. v0.1 · 18 Oct 2026

    Corpus, rubric, harness seeding, cost baseline, BOM emitter v0; benchmark on a public support-ticket set; six-minute walkthrough video.

  2. v0.2 · Nov 2026

    Report generator, permission-audit checklist, multi-agent and MCP-estate cases after the first full Gate dry run.

  3. v0.3 · Q1 2027

    Multilingual test set — the attack pack and harness cases in Hindi, Telugu, Tamil, Spanish, German and Japanese, because agents serving customers in those languages are shipped on English test results; Governor policy examples and the recorder's event schema, shared with MCPSentry and the Compliance Evidence Pack.

  4. Benchmark · from v0.1

    A public, reproducible benchmark in a domain that has none: the first candidate is a support-ticket set published with v0.1; claims triage, prior authorisation and invoice exceptions follow as domain packs are published by the Lab.

Repository 02

MCPSentry scanner

Point-in-time findings on any MCP server or agent-skill set, including private and local stdio servers, with the Kit's corpus for tool-description and context-file payloads. The free tier of MCPSentry: the paid service adds continuous pin-and-verify, drift alerts, the permission audit and the Agent BOM statement.

MCPSentry, the product →

First release
Q1 2027 — with MCPSentry early access
Licence
Apache-2.0
Repository
rainkernel/mcpsentry — public at release on github.com/rainkernel
Builds on
snyk-agent-scan, Cisco mcp-scanner, the Kit's corpus

How we do open source

Four commitments.

Tools open, evidence paid

We publish the scanners, corpus and harness. Subscriptions pay for continuous attestation, governance and audit-grade records.

Honest version numbers

v0.1 means v0.1. No back-dated history, no purchased stars, no release announced before it is tagged.

Upstream first

Where an open scanner should have a feature, we contribute it there before wrapping it here.

Security disclosures

Vulnerabilities in our tools go to security@rainkernel.com or the repository's private advisory; see security.txt. We credit reporters.

The Lab's weekly log, advisories and domain packs are on the Rainkernel Lab page. This website is itself open to inspection: it is a static site with a strict Content Security Policy, no cookies, no third-party scripts and a published security.txt. Details on Security and trust.

Building on the Kit, or want the engines run for you?

Integrators and platform teams: tell us what you are wrapping. Buyers: the Gate runs the same code, inside your cloud, with a report at the end.