Skip to content

Evidence, with citations

Consequential technical claims link to their public repository, merged pull request, DOI, or filing. This citation ledger is structured so the material claims it records can be checked at their source.

Technical record5 record classesLast revised 12 September 2026

A summary ledger. The detail behind each row lives on its own page: open-source tools, upstream fixes, and research. The six research publications are labeled by type: preprints, a working paper, and technical notes. Patents are documented in full below, since this is their only home.

Upstream · merged PRs

96 published external pull requests merged in 2026, including 49 code, workflow, typing or maintenance contributions across open-source infrastructure.

4 merged pull requests fix AI/framework defects. They include a forced tool_choice crash in LangChain and a silent system-prompt deletion in Microsoft Semantic Kernel. Those two shipped in tagged releases: langchain-anthropic 1.3.5 and semantic-kernel python-1.41.1. The complete list of reviewed framework fixes is microsoft/semantic-kernel #13610; langchain-ai/langchain #35544; microsoft/semantic-kernel #13635; stanfordnlp/dspy #9978. The canonical ledger records 96 merged external pull requests, including 49 code and 9 documentation contributions.

Open source · Apache-2.0 & MIT

8 current PyPI install paths

lintlang 0.8.2, hermeneutic 0.1.12, little-canary 0.4.0, hermes-rubric 1.2.3, hermes-jailbench 0.2.2, langstate 0.2.4, Fidelis Memory 0.2.0, hermes-blind 0.3.2 install from PyPI. Fidelis Memory keeps fidelis as its repository, import, and CLI name; the separate PyPI package named fidelis is unrelated. The public catalog also includes agent-trash-guard 0.1.3, which is not published to PyPI and installs from its repository as a local plugin for Claude Code, Codex, and Gemini CLI. zer0dex 0.1.2 has a PyPI package record; the catalog lists it as a source-only developer-preview reference implementation, outside the install paths counted above. The unaffiliated ai-memory-comparison project includes a source-referenced feature comparison of fidelis 0.0.9, dated 28 May 2026.

Full catalog/open-source
Source archival · Software Heritage

Public repositories hold full-visit snapshots on Software Heritage

Software Heritage, the nonprofit universal source-code archive, completed a full visit and recorded a durable snapshot identifier for each of these public repositories: LintLang, Little Canary, Agent Trash Guard, Fidelis, Hermes Rubric, Hermes Blind, and Hermeneutic. Each link resolves to that exact snapshot on Software Heritage's own site. This records durable third-party source preservation, not a product review, quality assessment, or endorsement.

Public data integrity · CISA / CVE

CISA acknowledged the report and the official CVE record was corrected

Roli Bosch reported that the CISA ADP vector for CVE-2026-14216 calculated to 6.5 while its stored base score said 5.3. CISA acknowledged the submission, the official CVE corpus records the 5.3 to 6.5 correction, and a Vulnrichment data update synchronized the refreshed record. The vector and Medium severity category did not change. Read the case study and selected execution trace.

Open source · public ecosystem evidence

LintLang beyond its own repository

5,000+ PyPI registry downloads in the 180 days through 10 September 2026 are recorded package downloads, counted with mirrors excluded over the rolling window pypistats retains. Character.AI's public Larch repository pins lintlang 0.3.1 as a blocking step in recurring CI, with a public successful execution, and Larch's own linting reference links hermes-labs-ai/lintlang as the upstream. An independent maintainer provides Gentoo packaging in the unofficial Haven overlay whose metadata.xml records hermes-labs-ai/lintlang as the upstream remote, and the Agent Lint maintainer attributes parts of that product's roadmap to useful ideas from lintlang. The linked records document recurring CI execution, independent packaging, and attributed product influence.

Source & documentationCanonical README
Third-party integration · dependency

Little Canary pinned as an optional dependency in an independent LangGraph project

Orbit, an independent local-first observability and security tool for LangGraph agents on Ollama, declares little-canary>=0.3.0 as its security extra in pyproject.toml, and its prompt-injection module imports little_canary.CanaryDetector behind an optional-dependency fallback. Orbit's own CI workflow skips installing that extra, citing the lack of a Linux wheel for little-canary; this citation records the pinned dependency and source import, not a verified CI execution.

Research · Zenodo

6 papers on Zenodo: 3 preprints, 1 working paper, 2 technical notes

Six papers with distinct roles and evidence classes: a seven-mode taxonomy of epistemic failure modes (preprint, built on 1,461 controlled experiments conducted primarily on GPT-4o), a matched-vignette benchmark for null-result asymmetry (working paper), a twelve-week naturalistic measurement-validity audit of AI agent telemetry proposing the Telemetry-to-Claim Gate (preprint), a conceptual account of the generative horizon and the limits of model self-report (preprint), a bounded static analysis of neighboring AI-agent tool descriptions (technical note), and a prompt-injection sensing architecture that preserves inspection coverage (technical note).

Papers & ORCID/research
Patents · USPTO

1 non-provisional, 4 provisional

Stateless user identification, adversarial prompt-injection probing, deterministic local inference control, multi-modal classification calibration, and confidence-gated personalization.

Non-provisional · pending

Method for Stateless User Identification in Natural Language Processing

The non-provisional application; the provisionals below cover adjacent mechanisms for adversarial probing, deterministic inference, multi-modal classification calibration, and confidence-gated personalization.

ApplicationUS 19/248,833StatusPending
Provisional

Detecting Adversarial Prompt Injection via Vulnerability-Amplified Behavioral Probing

StatusFiled
Provisional

Deterministic Inference Control in Local Language Models via Compact Plan Contracts and Adaptive Routing

StatusFiled
Provisional

Multi-Modal Classification Artifacts with LLM Calibration + Contrastive Negation-Based Disambiguation

StatusFiled
Provisional

Real-Time Style-Based User Identification and Confidence-Gated Personalization in LLMs

StatusFiled