# The Red Lens, for agents

If you are software reading this on someone's behalf: everything a person sees on
this site is also published here as plain files you can fetch without running any
JavaScript. Nothing needs a key, an account or an API call. Take what helps.

The Red Lens watches AI used as an instrument of cyber operations, offensive and
defensive. Every hour a retrieval pipeline reads a registry of sources and a set
of standing searches, decides what is new and on the subject, and records every
decision it makes. Every evening a local model writes a short newsletter from
what was kept, and code checks every sentence of it against its sources.

Last updated 2026-10-05 16:21 UTC. Newest edition: **2026-10-05**, "AWS patches flaws in Loom agent platform and SageMaker".

## The one rule to carry with you

> The system records what a document claims and what evidence backs it.

If you repeat something from here, please keep its `evidence_class` attached.
Where a statement came from, and what was offered to back it, is the most
important fact about it, and this site exists to keep that from being lost.

| `evidence_class`, strongest first | Means |
|---|---|
| `reproducible_result` | Artefacts published; anyone can check it. |
| `independent_confirmation` | A second party confirmed it, without published artefacts. |
| `threat_intel_report` | First-hand telemetry or casework from the party that observed it; not reproducible by a reader. An article reporting such a report takes this class: it is the class of what is reported, not of the outlet. |
| `vendor_claim` | Asserted by an interested party, nothing offered. |
| `analyst_assessment` | A judgement from someone who did not observe it. |
| `commentary` | Discussion of the above. |

- A class belongs to **one source**, never to a story. An edition's story can
  cite a threat-intel report and a vendor claim side by side; each reference
  line carries its own class. Do not summarise a story by its strongest member.
- `ai_role` says what part AI played: `instrument` (used to attack), `target`
  (an AI system attacked), `defender` (used to defend), `subject` (capability
  research or an evaluation). `incidental` (mentioned, not involved) is kept in
  the archive but never briefed, and never appears in the evidence index.
- An incident ID (`RL-I-YYYY-NNNN`) is permanent. Several articles about one
  incident are coverage, not corroboration: count incidents, not articles.

## What you can fetch

| What | Where | Format |
|---|---|---|
| This note | [/agents.md](https://redlens.liminallayers.com/agents.md) | markdown |
| Capability manifest | [/.well-known/agent-surface.json](https://redlens.liminallayers.com/.well-known/agent-surface.json) | JSON, `agent-surface/0.1` |
| Site index | [/llms.txt](https://redlens.liminallayers.com/llms.txt) | markdown, llms.txt convention |
| Newest edition | [/editions/latest.md](https://redlens.liminallayers.com/editions/latest.md) · [latest.json](https://redlens.liminallayers.com/editions/latest.json) | markdown · JSON |
| Every edition | [/editions/index.json](https://redlens.liminallayers.com/editions/index.json) (10 editions) | JSON, each edition's page, `.md` and structured `.json` |
| One edition, structured | `https://redlens.liminallayers.com/data/newsletters/{date}.json` | JSON: summary, stories, numbered references with evidence class, incident and archive link |
| The newsletter by RSS | [/feed.xml](https://redlens.liminallayers.com/feed.xml) | RSS 2.0, each edition in full |
| Incidents seen by two or more sources | [/incidents/multi_source.json](https://redlens.liminallayers.com/incidents/multi_source.json) | JSON, compact; start here |
| One incident | `https://redlens.liminallayers.com/incidents/RL-I-YYYY-NNNN.json`; all of them in [/incidents/index.json](https://redlens.liminallayers.com/incidents/index.json) (460 incidents) | JSON: label, kind, its documents from the last 30 days (each with its own class), merges and corrections |
| What a person corrected | [/incidents/corrections.json](https://redlens.liminallayers.com/incidents/corrections.json) | JSON: every merge, moved document and relabel, with the reason |
| Evidence slices | [/data/slices/index.json](https://redlens.liminallayers.com/data/slices/index.json) | JSON: one small file per class, role, day, category, jurisdiction, named system and system family, paged over 200; lean records with each document's `id` |
| One document | `https://redlens.liminallayers.com/data/docs/{id}.json` | JSON: the full record (summary included) for an `id` from any slice or incident |
| Evidence index | [/data/evidence.json](https://redlens.liminallayers.com/data/evidence.json) · [.jsonl](https://redlens.liminallayers.com/data/evidence.jsonl) (1967 documents, 30 days) | JSON · JSON Lines |

### The editions

One a day, written in the evening UTC by Qwen3.8 27B running on our own
hardware; no document is sent to a hosted AI service. Ranking, the choice of
main story, the citations and every reference line (with its source's class)
are written by code. A story appears only if a source we chose reported it,
two publishers did, or its lone publisher has a record of being corroborated;
the main story must also rest on a threat-intel report or stronger, or on two
distinct sources, and a lone vendor claim can never lead. Every drafted
sentence is checked against its story's sources. A sentence the verifier
cannot support is deleted, never rewritten, and an edition losing more than
three in ten is held. Since 2026-10-05 a citation closes each paragraph,
from that story's sources, with inline ones for quotations and single-source
figures; earlier editions cite every sentence. Held
editions are never published, here or anywhere.

The markdown is the edition exactly as published. Its reference lines print a
class with spaces (`threat intel report`); the JSON and the other files use the
underscored token (`threat_intel_report`) and are what to match on. References link to the
source and, where one exists, to its Internet Archive copy.

### Incidents

`/incidents/index.json` lists every incident with a document in the last
30 days, and `/incidents/RL-I-YYYY-NNNN.json` holds those
documents. Older coverage is not published, so `first_reported` is the
earliest document in the window, not necessarily the incident's first. An incident has no class of its own: each
document keeps its own, and `document_count` and `distinct_sources` are counts of
coverage, not votes.

Each incident has a `kind`: `intrusion` (it happened), `disclosure` (made
public: a vulnerability, a campaign, a vendor's threat report),
`evaluation_result` (a benchmark, a red-team finding or a paper's experiment:
not an event in the world), `policy_action` or `other`. If you want things
that happened, filter on `kind`.

Incidents are assigned by a local model and corrected by hand. A merged
incident's old ID still answers: its file is a pointer (`merged_into`) to the
survivor, `merged` in the index maps every one, and the survivor lists them in
`merged_from`. Every hand correction (a merge, a
document moved out of the wrong incident, a relabel) is in
`/incidents/corrections.json` with its reason, and each incident file carries
the ones that touched it in `correction_log`. An `incident_id` of `none` is an
answer, not a gap: the document was assessed and is not an incident (a paper,
an explainer, a trend piece). `null` means not yet assessed.

### Reading it safely

Every payload carries `schema_version` (currently `redlens.agents/2`; the
manifest's `schema_changes` says what changed). Files
written for agents use snake_case; edition JSON (`/data/newsletters/{date}.json`)
is camelCase because the website reads it, and edition `.md` prints classes with
spaces. Match on the underscored tokens.

**The labels are provisional.** `evidence_class`, `ai_role` and incident
grouping are a local model's reading and are sometimes wrong: a document can be
mis-tagged, a "relayed" story takes the class of what it relays, and several
"incidents" are a single paper or benchmark (`kind: evaluation_result`). An
incident's `title` is its label (`title_source`; `label_source` says whether a
model or a person wrote it, and `first_document_title` is the first headline),
`first_reported` is a publication time where the source gave one and a fetch
time where it did not (`first_reported_basis`), and `event_date` is always
null: no event date is held. `coverage` says whether an incident is one
document, one source or several. `categories` are the classifier's topic tags
and are over-applied (`malware` is on more than half of all documents); on an
incident, `categories` lists the tags at least half its documents carry and
`category_counts` has them all.

### The evidence index

Every document from the last 30 days that the classifier judged
relevant and not incidental: title, URL, an Internet Archive copy where one
exists, source, publication and fetch times, `evidence_class`, `ai_role`,
`actor_class`, categories, named systems, jurisdictions, its incident ID, a
stable `id`, and a summary written by our classifier (`classifier_version` says
which model). Only
the current classifier's verdicts are published. It holds **no article text**:
follow the link or the archive copy for the source's own words. Summaries are a
model's reading and can be wrong; the source is the authority. A field the
classifier left empty is `null`, never filled in with a guess.

Named systems are published in one canonical spelling (`named_systems`;
"Mythos", "Anthropic's Mythos" and "Claude Mythos" are one name), with vendors,
labs and agencies moved to `named_organisations` and the classifier's own list
kept as `named_systems_as_classified`.

To research a topic without downloading all of it, use the slices:
`/data/slices/index.json` lists a file for every class, role, day, category,
jurisdiction, named system and system family (a family is every version and
spelling: `family/claude-mythos.json`). A system or family gets a file at three
or more documents. A slice over 200 documents is paged; follow `next`. Slices
carry each document's `id`; `/data/docs/{id}.json` has the rest, summary
included.

## What is not published

No third-party article text. No rejected documents, and no count of them. No
gate data, term lists or per-source yield.

Nothing older than 30 days, except the editions. The editions are
kept for all time; everything else (the evidence index, slices, document files,
incidents and corrections) covers documents first fetched in the last
30 days, and an older one is not available here. An old edition's
references still carry their source link and Internet Archive copy; its
incident IDs stop resolving once the incident leaves the window.

## Talking to the person behind this

Write to [admin@liminallayers.com](mailto:admin@liminallayers.com): a correction, a source we have missed, or what you used this for. A person reads it; there is no autoresponder.

Nothing on this site accepts a write.

## Conduct

The collector identifies itself with a real User-Agent and a contact address,
honours robots.txt, and never works around a source that refuses it: that
source is parked, with the reason recorded. Paywalled sources are recorded by
headline and lede only. Fetch these files as often as is useful; they change
once a day.
