Open source
The tools ship in public. We charge for the evidence.
Our attack corpus, evaluation harness and scanner are released under Apache-2.0 on GitHub, so buyers can read exactly what the Gate runs and integrators can build on it. First tagged release: 18 October 2026.
Repository 01
Readiness Kit
The engine of the Agent Readiness Gate, in public: the attack corpus, the rubric and the scripts that turn an agent's real failures into an evaluation harness and a cost number. Buyers can read exactly what the Gate runs; integrators can build on it.
What is in it
attack-pack/Agent-specific attack cases mapped to OWASP ASI01–ASI10: tool-description poisoning, SKILL.md and CLAUDE.md context-file poisoning, form-input exfiltration (PipeLeak pattern), tool-chain cost amplification, over-permission probes.harness/Seeds an evaluation set of 20–50 tasks from an agent's logged failures and real traffic; scores runs against expected outcomes; keeps a held-out split so the number cannot be gamed.cost/Cost-per-task baseline: tokens, retries and tool calls per completed task from OpenTelemetry-style traces; projection to production volume.bom/Emits a CycloneDX-shaped Agent Bill of Materials — models, prompts, tools, MCP servers, skills, data sources — from a running agent's configuration.rubric/The 8-area readiness scorecard and the Evidence Report template for engineering, CISO and audit readers.adapters/Runners for snyk-agent-scan, Cisco mcp-scanner, Agentic Radar and Promptfoo, so the Kit orchestrates the open scanners rather than re-implementing them.
Release plan
- v0.1 · 18 Oct 2026
Corpus, rubric, harness seeding, cost baseline, BOM emitter v0; benchmark on a public support-ticket set; six-minute walkthrough video.
- v0.2 · Nov 2026
Report generator, permission-audit checklist, multi-agent and MCP-estate cases after the first full Gate dry run.
- v0.3 · Q1 2027
Multilingual test set — the attack pack and harness cases in Hindi, Telugu, Tamil, Spanish, German and Japanese, because agents serving customers in those languages are shipped on English test results; Governor policy examples and the recorder's event schema, shared with MCPSentry and the Compliance Evidence Pack.
- Benchmark · from v0.1
A public, reproducible benchmark in a domain that has none: the first candidate is a support-ticket set published with v0.1; claims triage, prior authorisation and invoice exceptions follow as domain packs are published by the Lab.
Repository 02
MCPSentry scanner
Point-in-time findings on any MCP server or agent-skill set, including private and local stdio servers, with the Kit's corpus for tool-description and context-file payloads. The free tier of MCPSentry: the paid service adds continuous pin-and-verify, drift alerts, the permission audit and the Agent BOM statement.
How we do open source
Four commitments.
Tools open, evidence paid
We publish the scanners, corpus and harness. Subscriptions pay for continuous attestation, governance and audit-grade records.
Honest version numbers
v0.1 means v0.1. No back-dated history, no purchased stars, no release announced before it is tagged.
Upstream first
Where an open scanner should have a feature, we contribute it there before wrapping it here.
Security disclosures
Vulnerabilities in our tools go to security@rainkernel.com or the repository's private advisory; see security.txt. We credit reporters.
The Lab's weekly log, advisories and domain packs are on the Rainkernel Lab page. This website is itself open to inspection: it is a static site with a strict Content Security Policy, no cookies, no third-party scripts and a published security.txt. Details on Security and trust.
Building on the Kit, or want the engines run for you?
Integrators and platform teams: tell us what you are wrapping. Buyers: the Gate runs the same code, inside your cloud, with a report at the end.