Research seriesL3data science
Static analysis can find real defects in an agent's software substrate, but a clean report cannot prove that model-mediated intent, framework semantics, delegated authority, and multi-step behavior are secure. This series measures that boundary and develops an honest assurance envelope for reporting what was checked, what was missed, and what remains unknown.
A report with no findings is evidence about a bounded search, not a certificate of safety — and for AI-agent software that boundary is unusually narrow.