Contribute
Submit an incident
Seen an AI agent cause a real problem, or a disclosed agent vulnerability that belongs in the registry? Send the source. We fetch it, quote it, code the record and mint an id, under the same verification rule we hold ourselves to.
What we need
Three things
A record needs a source that can actually be fetched and a sentence that confirms what happened. Anything we cannot verify is quarantined rather than counted, so a link to the primary write-up is worth more than a summary of it.
Submission received. We will fetch the source, quote it, and code the record if it clears verification. You do not need to send it again.
What happens next
- We fetch the source. A record needs at least one source actually retrieved during curation, plus a verbatim quote from it confirming the report. Nothing is written from memory.
- We code it. Class, attack surface, autonomy, initial vector, guardrail presence and outcome, who acted, and whether harm was realized — then a crosswalk to the OWASP Top 10 for Agentic Applications and MITRE ATLAS.
- It gets an id. If it clears verification it is minted as
AIR-YYYY-NNNNwith a permanent permalink, crediting you in its publicsubmitted_byfield. Ids are never reused or renumbered. If it does not clear, it is quarantined, not quietly dropped. - Duplicates are expected. Send it anyway. We dedupe across titles, shared quotes, shared exclusive sources and codenames by hand.
Read the method for the full contract, or about AIR for what the registry is and is not.