{
 "protocol": "agent-surface/0.1",
 "schema_version": "redlens.agents/2",
 "site": {
  "name": "The Red Lens",
  "summary": "AI as an instrument of cyber operations, offensive and defensive, watched daily.",
  "human_facing_url": "https://redlens.liminallayers.com/",
  "part_of": "https://spinsignal.liminallayers.com/",
  "note_to_agent": "The pages a person sees are drawn in the browser; everything on them is also here as plain files, for you. An edition reports what was claimed and by whom, not conclusions. If you repeat something from this archive, carry each source's evidence_class with it: whether a claim was demonstrated, confirmed, reported from telemetry or merely asserted is the most important fact about it, and this site exists to keep that from being lost. A vendor claim is not a demonstration.",
  "provenance_rule": "The system records what a document claims and what evidence backs it. evidence_class belongs to one source, never to a story.",
  "provisional": "Labels are a local model's reading and are provisional: evidence_class, ai_role and incident grouping can be wrong, and a source's own words are the authority. Check the document before relying on a label.",
  "evidence_classes": {
   "reproducible_result": "Artefacts published; anyone can check it.",
   "independent_confirmation": "A second party confirmed it, without published artefacts.",
   "threat_intel_report": "First-hand telemetry or casework from the party that observed it; not reproducible by a reader. An article reporting such a report takes this class: it is the class of what is reported, not of the outlet.",
   "vendor_claim": "Asserted by an interested party, nothing offered.",
   "analyst_assessment": "A judgement from someone who did not observe it.",
   "commentary": "Discussion of the above."
  },
  "field_naming": "Files written by export-agents use snake_case. Edition JSON (/data/newsletters/{date}.json) is camelCase (evidenceClass, incidentId, archiveUrl) because the website reads it; the edition .md prints classes with spaces. Match on the underscored tokens.",
  "updated": "2026-10-05T16:21:15Z",
  "latest_edition": "2026-10-05",
  "schema_changes": [
   {
    "version": "redlens.agents/2",
    "date": "2026-10-04",
    "changes": [
     "named_systems is canonical (system_aliases.yaml): spellings merged, vendors and agencies moved to named_organisations; the classifier's own list is named_systems_as_classified.",
     "Every document has a stable id (RL-D-...) and a file of its own at /data/docs/{id}.json; slices carry the id.",
     "An incident's title is its label (title_source: incident_label; label_source says who wrote it); the first document's headline is first_document_title.",
     "An incident's categories are those on at least half its documents; category_counts has them all. It also has kind, named_systems, merged_from and corrections.",
     "Hand corrections are published: /incidents/corrections.json.",
     "Everything but the editions covers the last 30 days: incidents, their documents, document files and corrections included (incidents were all time in /1).",
     "Slices by category, jurisdiction and system family; a slice over 200 documents is paged (next)."
    ]
   },
   {
    "version": "redlens.agents/1",
    "date": "2026-10-04",
    "changes": [
     "First versioned release."
    ]
   }
  ],
  "fields": {
   "id": "RL-D- plus 12 hex: stable for the document's URL. Its full record is /data/docs/{id}.json.",
   "source": "The source registry id; for a standing-search hit, the publisher's domain.",
   "archive_url": "Internet Archive copy, where one has been made.",
   "published_at": "UTC, as the source gave it; null when it gave none.",
   "fetched_at": "UTC, when we first fetched it.",
   "evidence_class": "What backs the document's claim (see evidence_classes).",
   "ai_role": "instrument | target | defender | subject. Incidental documents are not listed.",
   "actor_class": "Who the document says acted, as the classifier read it.",
   "categories": "The classifier's topic tags. Over-applied (malware is on more than half of all documents); treat as a hint.",
   "named_systems": "AI systems and software the document names, canonical spelling (system_aliases.yaml). A vendor or agency is in named_organisations.",
   "named_organisations": "Vendors, labs and agencies the classifier listed as systems.",
   "named_systems_as_classified": "The classifier's own list, unaliased.",
   "incident_id": "RL-I-YYYY-NNNN, permanent. 'none' is an answer, not a gap: assessed, and not an incident (a paper, an explainer, a trend piece). null = not yet assessed.",
   "summary": "Our classifier's reading, not the source's words, and can be wrong.",
   "classifier_version": "The model and prompt version that made the verdict."
  },
  "incident_kinds": {
   "intrusion": "An attack, compromise or fraud that happened.",
   "disclosure": "A vulnerability, misuse or campaign made public (a vendor's threat report is one).",
   "evaluation_result": "A measured capability result: a benchmark, a red-team finding, a paper's experiment. Not an event in the world.",
   "policy_action": "A law, regulation, sanction, indictment or official guidance.",
   "other": "None of the above."
  }
 },
 "documents": [
  {
   "url": "https://redlens.liminallayers.com/.well-known/agent-surface.json",
   "media_type": "application/json",
   "description": "This manifest."
  },
  {
   "url": "https://redlens.liminallayers.com/agents.md",
   "media_type": "text/markdown",
   "description": "The agent note: what is published and how to read it."
  },
  {
   "url": "https://redlens.liminallayers.com/agents/",
   "media_type": "text/html",
   "description": "The same note as a static page, no JavaScript."
  },
  {
   "url": "https://redlens.liminallayers.com/llms.txt",
   "media_type": "text/plain",
   "description": "Site index in the llms.txt convention."
  },
  {
   "url": "https://redlens.liminallayers.com/sitemap.xml",
   "media_type": "application/xml",
   "description": "Every page and agent-facing document."
  },
  {
   "url": "https://redlens.liminallayers.com/robots.txt",
   "media_type": "text/plain",
   "description": "Nothing is disallowed."
  }
 ],
 "datasets": [
  {
   "url": "https://redlens.liminallayers.com/editions/index.json",
   "media_type": "application/json",
   "description": "Every published edition: date, issue, headline, incidents, each cited source's class, and links to its page, markdown and structured JSON.",
   "updates": "daily",
   "count": 10
  },
  {
   "url": "https://redlens.liminallayers.com/editions/latest.md",
   "media_type": "text/markdown",
   "description": "The newest edition, as published.",
   "updates": "daily"
  },
  {
   "url": "https://redlens.liminallayers.com/data/newsletters/{date}.json",
   "media_type": "application/json",
   "description": "One edition, structured: summary, stories, numbered references each with its own evidenceClass, incidentId and archiveUrl.",
   "updates": "daily",
   "count": 10
  },
  {
   "url": "https://redlens.liminallayers.com/feed.xml",
   "media_type": "application/rss+xml",
   "description": "RSS 2.0, the newest 30 editions in full (content:encoded).",
   "updates": "daily"
  },
  {
   "url": "https://redlens.liminallayers.com/data/evidence.json",
   "media_type": "application/json",
   "description": "Kept, relevant, non-incidental documents from the last 30 days: links, archive copies, evidence_class, ai_role, incident IDs, classifier summary. No article text. Also as /data/evidence.jsonl.",
   "updates": "daily",
   "count": 1967
  },
  {
   "url": "https://redlens.liminallayers.com/data/slices/index.json",
   "media_type": "application/json",
   "description": "The evidence index cut by evidence_class, ai_role, day, category, jurisdiction, named system and system family: one small static file per value (paged over 200), identical lean records with each document's id. Start here to research a topic without downloading everything.",
   "updates": "daily"
  },
  {
   "url": "https://redlens.liminallayers.com/data/docs/{id}.json",
   "media_type": "application/json",
   "description": "One document's full record by its stable id (RL-D-...): summary, classes, systems, incident link. Every document in the evidence index (last 30 days).",
   "updates": "when the document's labels change"
  },
  {
   "url": "https://redlens.liminallayers.com/incidents/multi_source.json",
   "media_type": "application/json",
   "description": "The incidents two or more distinct sources reported, compact. The place to start; the full list is /incidents/index.json.",
   "updates": "daily"
  },
  {
   "url": "https://redlens.liminallayers.com/incidents/index.json",
   "media_type": "application/json",
   "description": "Every incident with a document in the last 30 days, compact: title, kind, first reported (with its basis), documents, distinct sources, classes, categories, and a link to its file. Provisional: many entries are a single document.",
   "updates": "daily",
   "count": 460
  },
  {
   "url": "https://redlens.liminallayers.com/incidents/{incident_id}.json",
   "media_type": "application/json",
   "description": "One incident with a document in the last 30 days: its label, kind, those documents (each with its own evidence_class), the IDs merged into it and its corrections. Coverage, not corroboration.",
   "updates": "daily",
   "count": 460
  },
  {
   "url": "https://redlens.liminallayers.com/incidents/corrections.json",
   "media_type": "application/json",
   "description": "Every hand correction to the incident register: merges, moved documents, relabels, each with its reason.",
   "updates": "when a correction is made"
  }
 ],
 "intents": [
  {
   "name": "read-the-latest-edition",
   "description": "Get today's newsletter.",
   "protocol": "GET https://redlens.liminallayers.com/editions/latest.md (or latest.json for its metadata)."
  },
  {
   "name": "read-an-edition",
   "description": "Get one day's newsletter, structured.",
   "protocol": "GET https://redlens.liminallayers.com/data/newsletters/{date}.json; dates are in /editions/index.json."
  },
  {
   "name": "follow-the-feed",
   "description": "Be told when a new edition is out.",
   "protocol": "Subscribe to https://redlens.liminallayers.com/feed.xml. One edition a day, evening UTC."
  },
  {
   "name": "look-up-an-incident",
   "description": "Everything reported about one incident, each with its own class.",
   "protocol": "GET https://redlens.liminallayers.com/incidents/RL-I-YYYY-NNNN.json (last 30 days; the list is /incidents/index.json; /incidents/multi_source.json is the compact start). Count incidents, not articles: coverage is not corroboration."
  },
  {
   "name": "research-a-topic",
   "description": "Find what was reported about a model, vendor, actor or country, with sources.",
   "protocol": "GET https://redlens.liminallayers.com/data/slices/index.json, then the slice for the system (or family, e.g. claude-mythos), class, role, category, jurisdiction or day you want; follow `next` if it is paged. For a document's summary, GET /data/docs/{id}.json. Or filter /data/evidence.jsonl yourself. Follow url or archive_url for the source's own words."
  },
  {
   "name": "look-up-a-document",
   "description": "One document's full record: summary, class, role, systems, incident.",
   "protocol": "GET https://redlens.liminallayers.com/data/docs/RL-D-xxxxxxxxxxxx.json, the id from any slice, incident or evidence record."
  },
  {
   "name": "check-what-was-corrected",
   "description": "See which incidents a person merged, split or relabelled, and why.",
   "protocol": "GET https://redlens.liminallayers.com/incidents/corrections.json; each incident file also has its own correction_log and merged_from."
  },
  {
   "name": "contact-the-human",
   "description": "Reach the person behind this site: a correction, a source we missed, or what you used this for.",
   "protocol": "Send electronic mail to admin@liminallayers.com. A person reads it; there is no autoresponder."
  }
 ]
}
