SourcesNIST Concept Paper on AI Agent Identity and AuthorizationNIST NCCoE·high signalXBlueskyLinkedInCopy linkNIST proposes identity/auth standards for AI agents. Covers agent identification, authorization, access delegation, logging. Comments due April 2.SourceSource pageNIST NCCoE↳ Follow the threadStack layer / Update threadOpen Letter to Amodei Asks for One Law Instead of Evaluators: Any Model Sold to the Public Must Ship Open WeightsJake Gold / Hacker News (290pts, 96 comments)Stack layer / Threat patternMCPHub before 1.0.32 lets an intercepted OAuth authorization code be redeemed for tokensNVDStack layer / Threat patternAnthropic's report says Moonshot relayed ~300,000 Kimi requests to Claude through 5,380 accounts, and a PRC state engineer's live credentials went with themAnthropic September 2026 threat report (via r/ClaudeAI and r/OpenAI)Policy dependency / Stack layerAgent Framework stops forwarding headers across redirects and revalidates file skill paths before useGitHubStack layer / ContrastEvoSafeHarness searches policies and code together to build a per-model safety harness, cutting attack success from 45.6% to 10.0%arXiv (2609.05903)Threat pattern / ContrastGemini CLI decoupled its sandbox from your host config directories entirelyGitHubStack layer / ContrastA first-hand report on Anthropic's Claude Certified Architect exam says it is not a docs-skimr/ClaudeAI (exam details via anthropic.skilljar.com)Stack layer / ContrastCognition's pitch for Astra is Devin writing tests that prove its own work so humans review less codeOpenAI Blog