From unsafe fallback to auditable security response.
Antigense reproduces a deliberately vulnerable agent-worker failure in a controlled software fixture, identifies the authorization flaw using Semgrep, uses cloud model advice without delegating patch authority, and preserves all results as FCO/FCG custody relationships and ordered Merkle/MMR commitments.
How to evaluate
1 · Watch
Play the approved three-minute narrated 053R3 compilation at /video/. Nimble is represented with credential-redacted footage; follow the evidence limits and retain the earlier 039R1 recording as backup.
2 · Recompute
Run the proof check on the walkthrough; then use the separate judge proof page for the later recorded local review action and its exact 12-leaf root.
3 · Inspect
Compare source/scan receipts, provider calls, readback rows and explicit failures in the private GitHub repository (judge access required).
Technical stack
| Security fixture | Python controlled byte corruption, checksum detection, fail-open teaching fixture, four-case deny/allow regression matrix. |
|---|---|
| Scan and advisory | Semgrep CE rules and broad audit scans; separately recorded Akash GPU/qwen2.5:0.5b incident summary; no automatic patch application. |
| Review and custody | Human review occurrence (unsigned), SHA-256 content addressing, distinct context/occurrence identity, typed FCG predecessor edges, ordered Merkle/MMR prefixes, independent Python and browser JS recomputation. |
| Evidence analytics | ClickHouse Cloud historical incident checkpoint ingestion, idempotence-oriented replay, query and exact bounded readback. |
| Distribution and monitoring | Local macOS health sampler and localhost Python server; Vercel HTML/CSS/JavaScript, WebCrypto, archived proof JSON and MP4 video. Static demo is not an internet connection to localhost. |
Where a customer would use each part
Stop an AI-generated authorization regression
Customer: scan an agent's changed code before merging; bind exact source bytes and rule to a finding, require a regression matrix after remediation. Observed: 1 narrow fixture finding before, 0 after. A later scan of 26 agent files returned 0 errors/findings but does not test every project path: independent review still found another fixture-code execution surface.
EXECUTED · NARROW COVERAGESecurity triage without delegated authority
Customer: submit sanitized incident facts to separately provisioned GPU inference; retain lease, inference response and closure receipts; prohibit output from directly changing authorization. Observed: historical GPU lease, HTTP 200 model response and successful close API reply. Final closed-state readback, actual bill, GPU/TEE attestation NOT_TESTED / NOT_COMPUTED.
HISTORICAL OBSERVED · NO TEE CLAIMRetrieve exactly what happened
Customer: compare event sequences across cases; query incident rows by run/occurrence and reconcile their hashes against canonical FCO receipts. Observed: historical bounded 11-checkpoint Cloud ingestion, replay and exact readback; single query 160.706 ms. No extrapolated enterprise performance or cost savings.
HISTORICAL OBSERVED · BOUNDED SAMPLEValidate exploit and repair variants
Customer: use a supported provider sandbox to reproduce an unsafe route, verify the repair, and preserve a review report. Only an intake packet and integration requirements exist here. No Pi provider API request, job ID, executed exploit validation or report artifact is claimed.
PROPOSED · PROVIDER NOT_TESTEDAn actual persisted review action
Run run-20261009T204741Z-5cb3db65; 12 ordered MMR leaves; event 9 08 Local review action; typed edge DEPENDS_ON_RECORDED_PREDECESSOR. The independently recomputed root is:
02d102de2d19334b582a5a9ebde4e55de184533a607d81cc2b317c000423ddc3
This is a preserved exact local receipt and browser-verifiable snapshot. It is not a live provider call, signed operator action or production patch. Open the public proof verifier ↗.
Explicit open failures: The later silent 040 screen recording does not include recorded narration for its additional scenes. A subsequent 040 v2 review-tree verifier and source working-tree comparison require repair; no new 040 claim should be upgraded to VERIFIED. Pi provider API, billing, final Akash GET, operator signature, hardware attestation and physical fault remain outside verified scope. Merkle equality proves only integrity of declared bytes and ordered leaves, not scientific truth or causality.
Sources, reproduction and access
Public demonstration requires no credentials. Local sponsor executions require an authorized environment and may incur charges; avoid rerunning GPU deployments just to inspect archived evidence. Exact source/receipt steps reside in the public GitHub repository. Latest local Judge 050 source is on the public 050 branch. No credentials are required for watching or verifying the published historical proof.
Research ancestry: FCO provenance preprint and FCO v4/v5 publication package. These precede the event and do not experimentally validate the hackathon security fixture. Creator: LinkedIn / Biobitworks.