<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>ai-safe2-framework — The AI Toolchain</title>
    <link>https://aitoolchain.io/tools/ai-safe2-framework</link>
    <description>New releases and features in ai-safe2-framework, tracked by The AI Toolchain.</description>
    <language>en</language>
    <lastBuildDate>Sat, 29 Aug 2026 15:10:00 GMT</lastBuildDate>
    <atom:link href="https://aitoolchain.io/tools/ai-safe2-framework/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ai-safe2-framework v3.1</title>
      <link>https://github.com/CyberStrategyInstitute/ai-safe2-framework/releases/tag/v3.1</link>
      <guid isPermaLink="true">https://github.com/CyberStrategyInstitute/ai-safe2-framework/releases/tag/v3.1</guid>
      <pubDate>Sat, 29 Aug 2026 15:10:00 GMT</pubDate>
      <description>AI SAFE² v3.1 adds 6 new MCP controls, three enforcement planes, protocol-independent persistence vocabulary, 12 new scanner rules, and a machine-readable manifest entry point for agents and bots.
• Adds `ai-safe2.manifest.json` and `AGENTS.md` as first-class machine entry points, exposing framework version, component versions, normative paths, control counts, enforcement planes, persistence vocabulary, conformance boundaries, and machine-readable datasets so agents and compliance bots can consume the framework without scraping prose.
• Adds `skills/mcp/data/mcp-profile-v3.1.json` as a machine-readable MCP profile covering all 19 CP.5.MCP controls.
• Adds `skills/mcp/data/ai-safe2-controls-v3.0.json` as the 161-control core dataset for automated consumption.
• Adds six new CP.5.MCP controls: MCP-14 (Extension Capability Negotiation), MCP-15 (Header and Body Assertion Integrity), MCP-16 (State Handle Binding and Lifecycle), MCP-17 (MRTR Round-Trip Integrity and Replay Resistance), MCP-18 (Catalog Cache Integrity and Provenance Revalidation), and MCP-19 (Authorization Chain Integrity, intended-resource/audience binding, and SSRF boundaries), bringing the MCP profile to 19 controls.
• Formalizes a protocol-independent persistence vocabulary with four canonical values — `request`, `handle_scoped`, `durable`, and `swarm_shared` — replacing protocol-owned session language at the governance boundary.
• Expands the scanner rule registry to 64 rules by adding 12 new grouped CP.5.MCP v3.1 rules covering the new and re-anchored MCP controls.
• Re-anchors MCP-4, MCP-7, MCP-8, MCP-11, and MCP-13 from protocol session state to framework-owned governance state (verified principals, capability grants, provenance baselines, delegation chains, governed state handles) so controls survive protocol changes such as MCP `2026-07-28`.
• Establishes three explicit enforcement planes — north-south (agent to model provider), east-west (agent to agent), and agent-to-tool (agent to MCP server or tool) — with the rule that a successful control result on one plane does not automatically establish coverage on another.
• Introduces an explicit MCP-19 conformance boundary: a deployment must evidence intended-resource, audience, or equivalent binding before protected dispatch; opaque bearer-token possession alone does not satisfy the control.
• Adds MCP `2026-07-28` as the primary binding for CP.5.MCP, with a twelve-month legacy compatibility window for MCP `2025-11-25`; `server/discover` is optional under the primary binding and its absence is not treated as a scanner failure.
• Scopes the Challenge Lab by enforcement plane — maturity, framework/profile conformance, the plane exercised, and required evidence — adding v3.1 MCP cases covering header/body desynchronization, catalog/schema drift, replay, audience/resource confusion, endpoint impersonation, SSRF, and legacy state-handle misuse.
• Adds a dedicated Agent Discovery and Manifest Integrity CI gate that verifies manifest claims against the repository, failing on incorrect claims and broken paths.
Breaking changes:
• Controls MCP-4, MCP-7, MCP-8, MCP-11, and MCP-13 now bind to framework-owned governance state rather than protocol session state; implementations that anchored those controls to MCP session constructs must be re-implemented against the new bindings.</description>
    </item>
  </channel>
</rss>
