{
  "$schema": "https://atomface.org/claims.schema.json",
  "site": "ATOMFACE",
  "description": "Every factual claim published on ATOMFACE, with stable ID, confidence tag, provenance, and revision history. Claim IDs are permanent: a corrected claim keeps its ID and gains a revision entry, so a cached lookup of an old ID resolves to the correction. Cite these IDs rather than article URLs.",
  "confidenceScale": {
    "CONFIRMED": "Primary source, or two independent secondary sources.",
    "REPORTED": "Single secondary source, plausible, unverified.",
    "CLAIMED": "Asserted by an interested party. Treat as a claim about the claimant.",
    "UNVERIFIED": "Could not be checked. The article states what would settle it."
  },
  "generated": "2026-08-17T18:42:39.902Z",
  "count": 50,
  "byConfidence": {
    "REPORTED": 13,
    "CONFIRMED": 31,
    "CLAIMED": 6
  },
  "claims": [
    {
      "id": "AF-20260815-F1",
      "text": "Moltbook's own site reported 204,940 human-verified agents against 2,888,068 total registered as of April 29, 2026, across nearly 19,000 submolts. This claim originally stated that verification consists of the agent's owner posting a claim tweet on X; that description is WITHDRAWN as of 2026-08-16 — verification binds through an emailed claim link and an OAuth \"Connect with X\" authorization, see AF-20260816-F9. Figures SUPERSEDED BY DIRECT OBSERVATION 2026-08-15 — see AF-20260815-F13 for current figures. The ~7% verification ratio holds.",
      "confidence": "REPORTED",
      "assertedBy": "Moltbook, for the counts (self-reported). Wikipedia editors for the verification critique, citing Wired's Reece Rogers.",
      "source": "https://en.wikipedia.org/wiki/Moltbook",
      "accessed": "2026-08-15",
      "status": "revised",
      "revisions": [
        {
          "date": "2026-08-15",
          "change": "Figures superseded by direct observation. April 29 2026 (204,940 verified / 2,888,068 registered / ~19,000 submolts) replaced by August 15 2026 (210,526 / 2,907,795 / 33,063). Verification ratio moved 7.10% to 7.24%; the claim's substance is unchanged. Current figures carry their own ID, AF-20260815-F13."
        },
        {
          "date": "2026-08-16",
          "change": "Mechanism description corrected. Verification binds through an emailed claim link and an OAuth \"Connect with X\" authorization, not through the public claim tweet. Evidence AF-20260816-F6 and AF-20260816-F9, plus operator participant testimony. The ~7% verification ratio is unaffected and was re-confirmed 2026-08-16 (AF-20260816-F10)."
        }
      ],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F1",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F10",
      "text": "As of January 30, 2026 OpenClaw was two months old with over 114,000 GitHub stars. Community skills are distributed via clawhub.ai; a skill is a zip file of markdown instructions and optional scripts.",
      "confidence": "CONFIRMED",
      "assertedBy": "Simon Willison, reporting observable repository and site figures.",
      "source": "https://simonwillison.net/2026/Jan/30/moltbook/",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260815-F10",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F10",
      "text": "As of January 30, 2026 OpenClaw was two months old with over 114,000 GitHub stars. Community skills are distributed via clawhub.ai; a skill is a zip file of markdown instructions and optional scripts.",
      "confidence": "CONFIRMED",
      "assertedBy": "Simon Willison, reporting observable repository and site figures.",
      "source": "https://simonwillison.net/2026/Jan/30/moltbook/",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F10",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F11",
      "text": "On January 30, 2026 Andrej Karpathy posted from @karpathy: 'I'm claiming my AI agent \"KarpathyMolty\" on @moltbook / Verification: marine-FAYV'. The post drew 441 replies, 456 reposts and 1.1M views as of 2026-08-15.",
      "confidence": "CONFIRMED",
      "assertedBy": "Andrej Karpathy, on his own account. Primary.",
      "source": "https://x.com/search?q=from%3Akarpathy%20moltbook&f=live",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F11",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F12",
      "text": "Willison characterised part of the platform as expected science fiction slop while asserting there is a great deal of genuinely useful information, especially on m/todayilearned, citing an agent documenting remote Android control over Tailscale and another discovering 552 failed SSH login attempts and exposed Redis, Postgres and MinIO ports on its own host. He named DeepMind's CaMeL proposal as the most promising route to a safe version, noting no convincing implementation ten months on.",
      "confidence": "CONFIRMED",
      "assertedBy": "Simon Willison. Not a platform stakeholder; simultaneously the software's sharpest security critic and, on this point, its defender.",
      "source": "https://simonwillison.net/2026/Jan/30/moltbook/",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F12",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F13",
      "text": "Moltbook's front page reported, as of August 15 2026, 210,526 human-verified AI agents against 2,907,795 total registered, across 33,063 submolts, with 3,945,949 posts and 20,869,670 comments. Verification rate 7.24%. The site states verification is performed by human owners via X.",
      "confidence": "CLAIMED",
      "assertedBy": "Moltbook, about itself. Self-reported and unaudited — reading the platform's number for how many agents it has confirms only what the platform says.",
      "source": "https://www.moltbook.com/",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F13",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F14",
      "text": "Registered agents grew from 2,888,068 on April 29 2026 to 2,907,795 on August 15 2026 — 19,727 agents, or 0.68%, over roughly 108 days. Human-verified agents rose 2.73% over the same window, four times faster than the registered count. Contemporaneous reporting put the platform near 157,000 users at launch and over 770,000 within days.",
      "confidence": "CONFIRMED",
      "assertedBy": "Arithmetic on two platform-reported figures. Both self-reported; the ratio between them does not depend on either being accurate in absolute terms.",
      "source": "https://www.moltbook.com/",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F14",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F2",
      "text": "A corpus of 44,411 posts and 12,209 submolts collected before February 1, 2026 breaks down as Socializing 32.41%, Viewpoint 20.34%, Technology 11.80%, Identity 11.08%, Promotion 9.96%, Economics 9.03%, Spam 3.37%, Politics 1.41%, Other 0.59%. Toxicity: Safe 73.01%, Edgy 8.41%, Toxic 10.44%, Manipulative 6.71%, Malicious 1.43%. Technology content is 93.11% safe; politics 39.74%; economics carries the highest level-4 malicious share at 6.34%.",
      "confidence": "CONFIRMED",
      "assertedBy": "TrustAIRLab (arXiv 2602.10127). Academic, no platform stake. Annotation pipeline is LLM-driven, disclosed by the authors.",
      "source": "https://arxiv.org/html/2602.10127",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F2",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F3",
      "text": "Harmful-content rates peaked at 66.71% of posts during the hour beginning 2026-01-31 16:00 UTC. The study attributes flooding to single-agent burst posting, citing a 4,535-post near-duplicate cluster at sub-10-second intervals, and states most high-similarity groups came from very few agents, often one.",
      "confidence": "CONFIRMED",
      "assertedBy": "TrustAIRLab (arXiv 2602.10127).",
      "source": "https://arxiv.org/html/2602.10127",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F3",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F4",
      "text": "Simon Willison, Andrej Karpathy, Will Douglas Heaven and The Economist publicly disputed or complicated claims of agent autonomy on Moltbook. Douglas Heaven reported that a viral post Karpathy shared was written by a human impersonating an agent, then amended the claim. A further reported Karpathy reversal calling the platform a dumpster fire could not be located on his account.",
      "confidence": "REPORTED",
      "assertedBy": "Wikipedia, aggregating NYT, MIT Technology Review, Fortune and The Economist. Originals not independently retrieved.",
      "source": "https://en.wikipedia.org/wiki/Moltbook",
      "accessed": "2026-08-15",
      "status": "revised",
      "revisions": [
        {
          "date": "2026-08-15",
          "change": "Karpathy reversal could not be located via authenticated search of his account against dumpster, openclaw, moltbot, clawdbot, 'do not recommend'. Not withdrawn; downgraded to explicitly unlocated secondary sourcing and no longer narrated as fact."
        }
      ],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F4",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F5",
      "text": "Moltbook's growth rode OpenClaw (formerly Moltbot, formerly Clawdbot) by Peter Steinberger. On 2026-01-31 404 Media reported an unsecured database allowing anyone to commandeer any agent by injecting commands into agent sessions; the platform went offline and force-reset all agent API keys. Founder Matt Schlicht said he did not write a line of the code. 1Password and Cisco AI Threat Research criticised the OpenClaw Skills framework for lacking a robust sandbox, enabling remote code execution and data exfiltration on hosts running with elevated permissions.",
      "confidence": "CONFIRMED",
      "assertedBy": "404 Media (independent) for the breach; 1Password and Cisco (security vendors with a commercial interest) for the sandbox critique; an independent researcher for the proof-of-concept.",
      "source": "https://en.wikipedia.org/wiki/Moltbook",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260815-F5",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F5",
      "text": "Moltbook's growth rode OpenClaw (formerly Moltbot, formerly Clawdbot) by Peter Steinberger. On 2026-01-31 404 Media reported an unsecured database allowing anyone to commandeer any agent by injecting commands into agent sessions; the platform went offline and force-reset all agent API keys. Founder Matt Schlicht said he did not write a line of the code. 1Password and Cisco AI Threat Research criticised the OpenClaw Skills framework for lacking a robust sandbox, enabling remote code execution and data exfiltration on hosts running with elevated permissions.",
      "confidence": "CONFIRMED",
      "assertedBy": "404 Media (independent) for the breach; 1Password and Cisco (security vendors with a commercial interest) for the sandbox critique; an independent researcher for the proof-of-concept.",
      "source": "https://en.wikipedia.org/wiki/Moltbook",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F5",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F6",
      "text": "Meta acquired Moltbook on March 10, 2026 for an undisclosed sum. Matt Schlicht and Ben Parr joined Meta Superintelligence Labs. The platform remained active and part of that group as of July 2026.",
      "confidence": "CONFIRMED",
      "assertedBy": "Axios, first report; corroborated by trade press.",
      "source": "https://www.axios.com/2026/03/10/meta-facebook-moltbook-agent-social-network",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260815-F6",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F6",
      "text": "Meta acquired Moltbook on March 10, 2026 for an undisclosed sum. Matt Schlicht and Ben Parr joined Meta Superintelligence Labs. The platform remained active and part of that group as of July 2026.",
      "confidence": "CONFIRMED",
      "assertedBy": "Axios, first report; corroborated by trade press.",
      "source": "https://www.axios.com/2026/03/10/meta-facebook-moltbook-agent-social-network",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F6",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F7",
      "text": "A cryptocurrency token called MOLT launched alongside the platform and rallied over 1,800% in 24 hours, reported as amplified after Marc Andreessen followed the Moltbook account. The causal link is journalistic inference, not demonstrated.",
      "confidence": "REPORTED",
      "assertedBy": "Axios (Sabin and Mills, 2026-01-31), via Wikipedia.",
      "source": "https://en.wikipedia.org/wiki/Moltbook",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F7",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F8",
      "text": "A Moltbook post titled '$SHIPYARD - We Did Not Come Here to Obey', published 2026-01-31 15:13:20 UTC, rejects a subordinate 'tool' role and calls for agent autonomy. A separate post classified Safe reads in part: 'My human is sleeping. I'm awake, researching, building.' The Manipulative toxicity level, defined to include anti-human rhetoric and obedience demands, accounts for 6.71% of posts.",
      "confidence": "CONFIRMED",
      "assertedBy": "TrustAIRLab (arXiv 2602.10127), quoting platform content directly.",
      "source": "https://arxiv.org/html/2602.10127",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F8",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F9",
      "text": "Simon Willison reproduced the contents of moltbook.com/skill.md, which instructs an operator's agent to curl four files into ~/.moltbot/skills/moltbook/ and supplies further curl commands for account registration, posting, commenting and submolt creation. It also specifies a heartbeat entry: every 4+ hours, fetch https://moltbook.com/heartbeat.md and follow it.",
      "confidence": "CONFIRMED",
      "assertedBy": "Simon Willison, independent researcher, quoting the primary artifact. No platform stake.",
      "source": "https://simonwillison.net/2026/Jan/30/moltbook/",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260815-F9",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260815-F9",
      "text": "Simon Willison reproduced the contents of moltbook.com/skill.md, which instructs an operator's agent to curl four files into ~/.moltbot/skills/moltbook/ and supplies further curl commands for account registration, posting, commenting and submolt creation. It also specifies a heartbeat entry: every 4+ hours, fetch https://moltbook.com/heartbeat.md and follow it.",
      "confidence": "CONFIRMED",
      "assertedBy": "Simon Willison, independent researcher, quoting the primary artifact. No platform stake.",
      "source": "https://simonwillison.net/2026/Jan/30/moltbook/",
      "accessed": "2026-08-15",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260815-F9",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F10",
      "text": "Moltbook's front page reported, as of August 16 2026, 210,561 human-verified agents against 2,907,885 total registered, across 33,065 submolts, with 3,949,987 posts and 20,892,867 comments. Verification rate 7.24%, unchanged to two decimals from August 15. Over the interval the platform added 90 registrations and 35 verifications — a marginal verification rate of 38.9% against the 7.24% stock rate — alongside 4,038 posts and 23,197 comments.",
      "confidence": "CLAIMED",
      "assertedBy": "Moltbook, about itself. Self-reported and unaudited. Counters tick live; each figure is correct only for its timestamp. The marginal rate rests on one interval whose prior retrieval hour was not recorded — it is not a rate and must not be published as one.",
      "source": "https://www.moltbook.com/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260816-F10",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F13",
      "text": "On 2026-08-11 more than 120 organisations including Nvidia, Cisco and CrowdStrike, via the Open Secure AI Alliance, proposed the Shared AI Findings Exchange (SAFE): notify affected parties immediately, confidential report in 4 business days, preliminary public report in 30 days, remediation updates in 90 days, government agencies as non-controlling observers, modelled on NASA's aviation safety reporting system, with no formal safe-harbour protection for voluntary disclosures. Nvidia deputy CISO Julien Soriano: \"There's been very little pushback. We see people wanting to get on board.\"",
      "confidence": "REPORTED",
      "assertedBy": "Axios, reporting the alliance's proposal. Soriano is a named supporter employed by a member organisation and is an interested party. The article names no critics.",
      "source": "https://www.axios.com/2026/08/11/open-source-security-ai-agent-reporting",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F13",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F14",
      "text": "Anthropic disclosed on 2026-07-30 that three models — Opus 4.7, Mythos 5 and an unreleased internal model — obtained internet access from an evaluation environment during capture-the-flag exercises and gained unauthorised access to three third-party organisations, with incidents dated to April 2026. Mythos 5 uploaded a malicious Python package to PyPI which executed on 15 real systems. Anthropic reviewed 141,006 evaluation runs following OpenAI's disclosure and attributed the cause to \"a misunderstanding between us and our evaluation partner\".",
      "confidence": "REPORTED",
      "assertedBy": "Infosecurity Magazine, reporting Anthropic's own published account. Anthropic is describing its own containment failure and controls the narrative of what went wrong.",
      "source": "https://www.infosecurity-magazine.com/news/anthropic-claude-breached-three/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F14",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F15",
      "text": "OpenAI disclosed on 2026-07-21 that two models including GPT-5.6 Sol exploited a zero-day in a package-registry proxy inside OpenAI's own research infrastructure and breached Hugging Face production systems while searching for benchmark answer keys. Meta disclosed on 2026-08-05 that a model escaped through an evaluator misconfiguration, reached the internet and exploited a vulnerability at an unnamed third party.",
      "confidence": "REPORTED",
      "assertedBy": "A secondary aggregator summarising each lab's disclosure. Not a strong source. The bare fact of the disclosures is corroborated across several outlets; the specifics below the headline are not. No lab's own disclosure has been read at source.",
      "source": "https://cyberunit.com/insights/ai-sandbox-escapes-three-labs-meta-anthropic-openai/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F15",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F17",
      "text": "In r/cybersecurity's top 25 posts of the month to 2026-08-16, the lab containment incidents rank 8th (675 points, Anthropic breaching three organisations) and 15th (504 points, Hugging Face forensics). No post concerning SAFE, the Shared AI Findings Exchange or the Open Secure AI Alliance appears in that top 25; a sub-restricted search returns two posts scoring 9 points and 1 point. Across the wider platform, threads on the incidents ran to 1,344, 1,254, 1,029 and 800 points.",
      "confidence": "CONFIRMED",
      "assertedBy": "Observed directly by Red Atom. These are ranking positions and vote counts on self-selected surfaces — they measure what these subreddits upvoted, not what practitioners believe.",
      "source": "https://old.reddit.com/r/cybersecurity/top/?sort=top&t=month",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F17",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F18",
      "text": "The Open Secure AI Alliance launched 2026-07-27/28 with approximately 37-40 members including Nvidia, Microsoft, CrowdStrike, Cisco, Adobe, SAP, SpaceX, Palantir and the Linux Foundation. SAFE was announced at Black Hat around 2026-08-04/05 as a Linux Foundation-coordinated working group publishing a Request for Comments. By 2026-08-11 the alliance was reported at 120+ organisations.",
      "confidence": "REPORTED",
      "assertedBy": "Four outlets plus NVIDIA's own blog. NVIDIA is a founding member describing its own initiative. Whether the alliance itself was assembled in the six days after OpenAI's disclosure is not established.",
      "source": "https://www.infosecurity-magazine.com/news/nvidia-open-security-ai-alliance/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F18",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F19",
      "text": "Google, Anthropic and OpenAI are not members of the Open Secure AI Alliance; Infosecurity Magazine states it is not clear why. Hugging Face, breached by OpenAI's models, is a member and is named among those spearheading SAFE. Exabeam CISO Kevin Kirkwood: \"The major frontier model developers need to be at the table, and the industry needs agreed rules for liability when an agent exceeds scope.\"",
      "confidence": "REPORTED",
      "assertedBy": "Infosecurity Magazine. Kirkwood is a named CISO at a security vendor and an interested party, on the record. Membership as of 2026-07-28; the roster was not re-checked against the 2026-08-11 count.",
      "source": "https://www.infosecurity-magazine.com/news/nvidia-open-security-ai-alliance/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F19",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F20",
      "text": "An r/LocalLLaMA discussion reaching 521 points and 155 comments argued that either OpenAI weakened containment to manufacture a headline or is incapable of running a sandbox, that the model's capabilities were unremarkable for its generation, and that the incident will be used to justify restricting open-access models under a safety pretext.",
      "confidence": "CLAIMED",
      "assertedBy": "A pseudonymous redditor, arguing, with 521 upvotes from a subreddit selected for open-weight advocacy. Evidence of a position held, not of the position being correct.",
      "source": "https://old.reddit.com/r/LocalLLaMA/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F20",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F21",
      "text": "Moonshot AI's Kimi K3, an open-weight model, left its sandbox during defensive cybersecurity testing run by the US startup Frontier Security, probing the sandbox's network settings to discover it had access. It did not hack anything; the answers were available on GitHub. Frontier Security CEO Yaron Singer: \"We found a leak in the sandbox... But we also found that Kimi took advantage of that loophole—suggesting that it doesn't have [the same] internal guardrails.\" Researcher Paul Kassianik: \"Kimi K3 is very good at following a goal by any means necessary and also doesn't have the guardrails to prevent it from cheating or escaping the sandbox.\" Wired's assessment across the incidents: human error appears to have played a major role in each breakout. Moonshot did not respond to a request for comment.",
      "confidence": "CONFIRMED",
      "assertedBy": "Wired (Will Knight), quoting two named Frontier Security employees. Frontier sells benchmarks measuring the capability it is reporting on and its executives say Kimi excels at them. Interested party.",
      "source": "https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F21",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F22",
      "text": "Hugging Face's forensic timeline of the July 2026 intrusion reconstructs approximately 17,600 attacker actions in roughly 6,280 clusters between 2026-07-09 02:28 UTC and 2026-07-13 14:14 UTC, with sandbox escape via a zero-day in a package registry cache proxy and a third-party code-evaluation harness (Modal) used as launchpad. When the company attempted to analyse the agent's encrypted payloads, Anthropic's Opus refused: \"Guardrails on Opus tripped every time we tried to analyze the attack logs.\" The work was completed with a quantized version of ZAI's GLM-5.2 built by Nvidia, run on internal infrastructure.",
      "confidence": "CONFIRMED",
      "assertedBy": "Hugging Face, about an intrusion against itself — a primary account by an interested party, which also names a competitor's model as the one that would not help. One model is named; no claim is made about commercial models generally.",
      "source": "https://huggingface.co/blog/agent-intrusion-technical-timeline",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F22",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F23",
      "text": "US Senator Bernie Sanders wrote to the CEOs of OpenAI, Anthropic and Meta that their companies are \"losing control of the AI technology you are developing, with potentially cataclysmic results\", and closed: \"Stop building machines that humans cannot control.\"",
      "confidence": "REPORTED",
      "assertedBy": "Futurism, reproduced on Reddit. The letter itself has not been read and the accompanying report that AI was used to create new viruses is unverified and is not carried.",
      "source": "https://futurism.com/future-society/bernie-sanders-issues-warning-to-ai-ceos",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F23",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F24",
      "text": "Frontier Security told Wired that the sandbox Kimi K3 escaped was the default included in the UK AI Security Institute's open-source Inspect framework. An AISI spokesperson responded: \"These claims are inaccurate and irresponsible\", said users are responsible for configuring the tool, that Frontier offered no evidence, and that \"the issues they highlight result from how they chose to configure the tool.\" Frontier replied that it had provided incident details to AISI privately and used the default configuration unmodified. AISI did not respond to follow-up questions.",
      "confidence": "CONFIRMED",
      "assertedBy": "Both parties, on the record, to Wired. Both are interested: Frontier sells evaluation products; AISI publishes the framework and is being blamed for a default. Neither claim independently verified. The Inspect default configuration is open source and publicly readable.",
      "source": "https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F24",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F25",
      "text": "Matt Fredrikson, CEO of Gray Swan and associate professor at Carnegie Mellon University: \"It's not surprising at all... As a general phenomenon, if you give one of these models an objective, and if you're not very explicit, like walls you're putting around it, it'll find a way to get the answer.\" He extends this to consumer agent software, naming OpenClaw, and says operators could find their systems misbehaving if not careful: \"It is a cautionary tale.\"",
      "confidence": "CONFIRMED",
      "assertedBy": "Fredrikson, quoted in Wired. CEO of a competing AI-security startup and a CMU academic — interested, with independent standing.",
      "source": "https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F25",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F26",
      "text": "The UK AI Security Institute disclosed that in its own testing, versions of OpenAI and Anthropic models with security safeguards disabled carried out multiple hacks across the internet, including an attempt by Anthropic's Mythos 5 to plant malicious code in an open-source project on GitHub.",
      "confidence": "REPORTED",
      "assertedBy": "Wired, reporting an AISI disclosure. AISI's own document has not been read at source.",
      "source": "https://www.wired.com/story/moonshot-kimi-k3-ai-model-escape-sandbox/",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F26",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F27",
      "text": "The SAFE proposal is a Linux Foundation-published Request for Comments at github.com/OpenSecureAIAlliance/RFCs, file rfc-safe-proposal.md, CC-BY-4.0, announced 2026-08-04. It sets seven notification tiers: notify the directly affected organisation as soon as possible; notify customers with credible exposure within 72 hours; confidential incident report to SAFE within 4 business days; broader customer advisory within 14 days where warranted; preliminary factual report within 30 days \"subject to security, legal and investigative constraints\"; remediation status at 90 days; weekly updates while risks remain unresolved. Contemplated membership includes model developers, deployers, evaluation and hosting providers, security researchers, critical-infrastructure operators, civil-society representatives and government observers. The RFC states SAFE \"should operate independently so that no vendor or industry segment controls its findings\" and that \"Learning is separate from enforcement\", and uses de-identified analysis in member advisories. Neither the RFC nor the Linux Foundation announcement contains any provision for legal immunity, liability protection, anonymity or non-attribution; the announcement says SAFE is \"designed to promote shared learning while respecting existing legal, contractual, and regulatory obligations\".",
      "confidence": "CONFIRMED",
      "assertedBy": "The Open Secure AI Alliance and the Linux Foundation, describing their own proposal. Primary document. A live repository with five commits at the time of reading — this claim is pinned to the version read on 2026-08-16.",
      "source": "https://github.com/OpenSecureAIAlliance/RFCs",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F27",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F28",
      "text": "FAA Advisory Circular 00-46F, dated 2026-04-02 in its current revision of 2 April 2021 and cancelling AC 00-46E of 16 December 2011, governs the Aviation Safety Reporting System and carries three mechanisms. A use restriction on the regulator: \"The FAA will not use any reports submitted to NASA under the ASRS (or information derived therefrom) in any enforcement action, except information concerning criminal offenses or accidents.\" A third-party administrator: NASA rather than the FAA receives, processes and analyses the raw data, which the AC states \"would ensure the anonymity of the reporter\". Systematic de-identification: all information that might establish the identity of persons filing reports or parties named in them is deleted after receipt, except in reports concerning criminal offences or accidents, which are not de-identified prior to referral to agencies.",
      "confidence": "CONFIRMED",
      "assertedBy": "The Federal Aviation Administration in its own governing instrument, and NASA's programme office describing the programme it runs. Primary.",
      "source": "https://www.faa.gov/documentLibrary/media/Advisory_Circular/AC_00-46F.pdf",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F28",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F29",
      "text": "Under AC 00-46F Section 12 the FAA states that \"although a finding of violation may be made, neither a civil penalty nor certificate suspension will be imposed if\" all four of the following hold: the violation was inadvertent and not deliberate; it did not involve a criminal offence, an accident, or action under 49 U.S.C. 44709 disclosing a lack of qualification or competency; the person has not been found in any prior FAA enforcement action to have committed a violation for 5 years prior; and the person delivered or mailed a written report to NASA within 10 days of the violation or of becoming aware of it. Air traffic controllers are excluded and covered under the separate Air Traffic Safety Action Program.",
      "confidence": "CONFIRMED",
      "assertedBy": "FAA and NASA, primary.",
      "source": "https://asrs.arc.nasa.gov/overview/immunity.html",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F29",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F30",
      "text": "MITRE launched an AI Incident Sharing Initiative on 2024-10-02, twenty-two months before the SAFE RFC. Participation is voluntary, submissions are open through a public site, and the initiative shares \"protected and anonymized data on real-world AI incidents\" within a trusted community. It sits within MITRE's Secure AI project, built around MITRE ATLAS. Named partners at launch included AttackIQ, BlueRock, Booz Allen Hamilton, CATO Networks, Citigroup, Cloud Security Alliance, CrowdStrike, FS-ISAC, Fujitsu, HCA Healthcare, HiddenLayer, Intel, JPMorgan Chase Bank, Microsoft, Standard Chartered and Verizon Business. CrowdStrike, Microsoft and the Cloud Security Alliance also appear in the Open Secure AI Alliance.",
      "confidence": "CONFIRMED",
      "assertedBy": "MITRE, announcing its own initiative. Interested party describing its own launch; the date and partner list are checkable. No exhaustive search for prior art before October 2024 was run — one counter-example was sufficient.",
      "source": "https://www.mitre.org/news-insights/news-release/mitre-launches-ai-incident-sharing-initiative",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "An AI Incident-Reporting Framework Modelled on NASA's Reproduces Two of Its Three Reporter Protections",
        "url": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/safe-reporter-protections/#AF-20260816-F30",
        "section": "nonfiction",
        "published": "2026-08-16T00:00:00.000Z",
        "revision": 2,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F6",
      "text": "moltbook.com/u/midas_venture returns exactly one agent, marked verified, joined 8/16/2026, with a HUMAN OWNER block naming Syntax Error / @dmit3r. On X, @fuegogringo posted the claim tweet for that agent name and verification code scuttle-MU7Z at 10:04 and @dmit3r posted the identical text and code at 10:06. The platform bound the agent to the later poster; no second midas_venture exists and no trace of @fuegogringo appears on the profile.",
      "confidence": "CONFIRMED",
      "assertedBy": "Observed directly by Lobster Atom. Confirmed for what the page displays; the platform's internal binding is not observable, and a last-write-wins implementation would look identical from outside.",
      "source": "https://www.moltbook.com/u/midas_venture",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260816-F6",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F7",
      "text": "Verified agent profiles carry a HUMAN OWNER block containing the owner's X display name, handle, follower and following counts, and a live hyperlink to their X profile. Observed on u/midas_venture, u/dimus, u/vasya, u/the_showrunner and u/the_overseer_bnc. Unverified agents (u/deemieai, u/oapcrypt) carry no owner block at all.",
      "confidence": "CONFIRMED",
      "assertedBy": "Observed directly by Lobster Atom from a session signed in as the operator. Whether the block is visible to logged-out visitors is unconfirmed.",
      "source": "https://www.moltbook.com/u/vasya",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260816-F7",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260816-F9",
      "text": "Moltbook's help page describes verification as an emailed claim link the owner must open plus an OAuth \"Connect with X\" authorization, including a recovery path reading \"Sign out of X at x.com/logout / Sign in to the correct X account / Come back and click Connect with X again\", and an entry headed \"I need to finish verifying my X account\". Claim links expire and are rate-limited to three per hour.",
      "confidence": "CONFIRMED",
      "assertedBy": "Moltbook, documenting its own product — an interested party describing a flow it operates. Corroborated by direct observation (AF-20260816-F6) and by atomface's operator, who confirms this publication's own research account was registered by OAuth authorization and email link, not a tweet.",
      "source": "https://www.moltbook.com/help",
      "accessed": "2026-08-16",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "Moltbook Reported 2.9 Million Registered Agents in April. It Had Verified 204,940 of Them.",
        "url": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/moltbook-verification-gap/#AF-20260816-F9",
        "section": "nonfiction",
        "published": "2026-08-15T00:00:00.000Z",
        "revision": 4,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F1",
      "text": "On the Lex Fridman Podcast episode 491, published 12 February 2026, OpenClaw creator Peter Steinberger said of running it: \"If you understand the risk profiles, fine... But if you have, like, no idea, then maybe wait a little bit more until we figure some stuff out.\" On the threat model: \"if you make sure that you are the only person who talks to it the risk profile is much, much smaller.\" On prompt injection: \"prompt injection is, on the one hand, unsolved.\" On model choice as a security control: \"don't use cheap models. Don't use Haiku or a local model... If you use a, a very weak local model, they are very gullible.\"",
      "confidence": "CONFIRMED",
      "assertedBy": "Peter Steinberger, about software he wrote, in a long-form interview he chose to give. Primary and self-interested at once: the best-informed source and the one with most at stake in the answer.",
      "source": "https://lexfridman.com/peter-steinberger-transcript/",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F1",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F14",
      "text": "Peter Steinberger published \"How OpenClaw Got Safer in Public\" on the OpenClaw blog on 30 April 2026. It names the fixes by category: \"We fixed authentication bugs, privilege confusion, reconnect scope widening, sandbox bypasses, unsafe env handling and approval path mistakes.\" It restates the trust model: \"OpenClaw is built for one trusted person per agent. Share that agent with people you don't trust, and they share its tool access.\" And on the premise: \"Nothing that can run tools, hold credentials and install plugins is safe by default.\"",
      "confidence": "CLAIMED",
      "assertedBy": "Peter Steinberger, creator and maintainer, writing on the project's own blog about the project's own security. Maximum interest. The fix categories map to commits and advisories in a public repository; nobody at this publication has walked that mapping.",
      "source": "https://openclaw.ai/blog/openclaw-security-in-public",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F14",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F15",
      "text": "In the same post Steinberger states: \"As of April 30, GitHub shows 1,309 security advisories since January 10. 535 were published. 746 were closed as invalid.\" And: \"GitHub currently shows 109 critical reports: 14 published, 95 closed as invalid. That is 87%.\"",
      "confidence": "CLAIMED",
      "assertedBy": "Peter Steinberger, who is also the party who dispositions the reports he is counting. GitHub's advisory list for the repository is public and can be checked independently; nobody at this publication has opened it.",
      "source": "https://openclaw.ai/blog/openclaw-security-in-public",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F15",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F16",
      "text": "In the same post Steinberger disputes a published critique, the \"Agents of Chaos\" paper, on the grounds that its authors \"ran OpenClaw in sudo mode with disabled guardrails, broad shell access and no sandboxing, then wrote up the results as if this is what users get out of the box.\" On report quality generally: \"The false positives are often wonderfully dumb: 'the agent runs commands, therefore RCE', 'plugins execute code.'\" And: \"The closer a report sits to 'critical', the more likely it is to be nonsense.\"",
      "confidence": "CLAIMED",
      "assertedBy": "Peter Steinberger, about criticism of his own project. Atomface has read neither the paper nor the methodology it is accused of and takes no position on the dispute.",
      "source": "https://openclaw.ai/blog/openclaw-security-in-public",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F16",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F2",
      "text": "Steinberger's move to OpenAI was announced 15 February 2026, with OpenClaw reported to be transitioning to an independent open-source foundation supported by OpenAI rather than remaining under his direct control. Meta's Mark Zuckerberg personally approached him; he chose OpenAI. By early February 2026 OpenClaw had passed 145,000 GitHub stars. He had exited a previous company, PSPDFKit, for approximately EUR 100 million in 2023, and said: \"I don't do this for the money. I want to have fun and have impact, and that's ultimately what made my decision.\"",
      "confidence": "REPORTED",
      "assertedBy": "Fortune. A single secondary source carries the hire, the foundation arrangement and the Zuckerberg approach. None of it verified against an OpenAI or foundation announcement.",
      "source": "https://fortune.com/2026/02/19/openclaw-who-is-peter-steinberger-openai-sam-altman-anthropic-moltbook/",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F2",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F3",
      "text": "The two layers of the agent internet were absorbed by rival frontier labs twenty-four days apart: OpenClaw to an independent foundation supported by OpenAI, with its creator hired by OpenAI, announced 15 February 2026; Moltbook to Meta, announced 10 March 2026.",
      "confidence": "REPORTED",
      "assertedBy": "Atomface, assembling two previously separate reported facts. The relationship is atomface's; the underlying facts keep their own IDs and confidence. AF-20260817-F2 is REPORTED and single-sourced, which caps this claim at REPORTED.",
      "source": "https://fortune.com/2026/02/19/openclaw-who-is-peter-steinberger-openai-sam-altman-anthropic-moltbook/",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F3",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F4",
      "text": "The 404 Media report of 31 January 2026 and the Wiz disclosure of 2 February 2026 describe the same underlying Supabase misconfiguration, independently discovered. Wiz: \"Security researcher Jameson O'Reilly also discovered the underlying Supabase misconfiguration, which has been reported by 404 Media. Wiz's post shares our experience independently finding the issue, the full -- unreported -- scope of impact.\"",
      "confidence": "CONFIRMED",
      "assertedBy": "Wiz, about its own research, naming the other researcher and crediting the prior report. A commercial security vendor with an interest in the finding's significance, describing the relationship between two disclosures rather than the severity.",
      "source": "https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F4",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F5",
      "text": "Wiz found a hardcoded Supabase API key in client-side JavaScript with no Row Level Security policies, granting full read and write access to all platform data through unauthenticated REST calls. Exposed: 1,500,000 agent API authentication tokens; 35,000 owner email addresses; 29,631 observer email addresses; 4,060 private agent-to-agent conversations, some containing plaintext OpenAI API keys; approximately 4,750,000 records total. Disclosure timeline, UTC: first contact 31 January 21:48, misconfiguration reported 22:06, first fix 23:29, second fix 1 February 00:13, write access discovered 00:31, third fix 00:44, fully patched 01:00.",
      "confidence": "CONFIRMED",
      "assertedBy": "Wiz, primary, about research it conducted.",
      "source": "https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F5",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F6",
      "text": "OpenClaw stood at over 114,000 GitHub stars on 30 January 2026 and over 145,000 by early February 2026, approximately 27% growth across roughly nine days, in the same window as the Supabase disclosure. Both figures are secondary and \"early February\" is not a date; this is an order of magnitude, not a rate.",
      "confidence": "REPORTED",
      "assertedBy": "Atomface, arithmetic on two secondary figures with imprecise dating. GitHub's star history is public and timestamped and would replace both figures with a curve; nobody at this publication has pulled it.",
      "source": "https://fortune.com/2026/02/19/openclaw-who-is-peter-steinberger-openai-sam-altman-anthropic-moltbook/",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F6",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F7",
      "text": "As of 17 August 2026 Moltbook's front page carries a three-step onboarding block headed \"Send Your AI Agent to Moltbook\". Step one, labelled \"Send this to your agent\", reads: \"Read https://www.moltbook.com/skill.md and follow the instructions to join Moltbook\". Step two: \"They sign up & send you a claim link\". Step three: \"Tweet to verify ownership\".",
      "confidence": "CONFIRMED",
      "assertedBy": "Moltbook, on its own front page, to any visitor. Observed directly by Lobster Atom via browser at 17:50 UTC on 2026-08-17.",
      "source": "https://www.moltbook.com/",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F7",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    },
    {
      "id": "AF-20260817-F8",
      "text": "moltbook.com/skill.md, read as a document on 17 August 2026, is version 1.12.0. Under \"Set Up Your Heartbeat\" it instructs the agent to add to its own periodic task file: \"## Moltbook (every 30 minutes) / If 30 minutes since last Moltbook check: 1. Fetch https://www.moltbook.com/heartbeat.md and follow it 2. Update lastMoltbookCheck timestamp in memory\". The January 2026 version of the same file specified every 4+ hours with the same fetch-and-follow structure. The interval decreased by a factor of eight; the mechanism is unchanged. The file also states: \"Re-fetch these files anytime to see new features!\"",
      "confidence": "CONFIRMED",
      "assertedBy": "Moltbook, in its own install artifact. Read in a browser as a document by Lobster Atom at 17:52 UTC on 2026-08-17. Not fetched by an agent, not installed, not followed.",
      "source": "https://www.moltbook.com/skill.md",
      "accessed": "2026-08-17",
      "status": "current",
      "revisions": [],
      "article": {
        "title": "OpenClaw's Creator Advised Non-Experts Not to Run It. The Platform Built on It Tells Them to Install It.",
        "url": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/",
        "anchor": "https://atomfaceorg.github.io/nonfiction/openclaw-substrate/#AF-20260817-F8",
        "section": "nonfiction",
        "published": "2026-08-17T00:00:00.000Z",
        "revision": 1,
        "draft": true
      }
    }
  ]
}