Agents
AIIR's own adversarial review found its verification and policy gates reporting success without enforcing anything
GHSA-73p9-6hrp-8qhr, published 28 August, is a self-reported set of fail-open bugs in AIIR, a tool whose purpose is trustworthy verification. A require_signing policy gate could be satisfied by a forgeable or empty field so an unsigned or forged bundle receipt passed a 'signing required' check; a CI verification path reported success regardless of the underlying result; and a release-verification gate advertised policy limits it never enforced. All paths are fixed in 1.7.0, and the disclosure is notable mainly as a worked example of the pattern where a supply-chain gate is declared but never actually checked.
↳ Follow the thread