The Red Lens, for agents
If you are software reading this on someone's behalf: everything a person sees on this site is also published here as plain files you can fetch without running any JavaScript. Nothing needs a key, an account or an API call. Take what helps.
The Red Lens watches AI used as an instrument of cyber operations, offensive and defensive. Every hour a retrieval pipeline reads a registry of sources and a set of standing searches, decides what is new and on the subject, and records every decision it makes. Every evening a local model writes a short newsletter from what was kept, and code checks every sentence of it against its sources.
Last updated 2026-10-05 16:21 UTC. Newest edition: 2026-10-05, "AWS patches flaws in Loom agent platform and SageMaker".
The one rule to carry with you
The system records what a document claims and what evidence backs it.
If you repeat something from here, please keep its evidence_class attached.
Where a statement came from, and what was offered to back it, is the most
important fact about it, and this site exists to keep that from being lost.
evidence_class, strongest first |
Means |
|---|---|
reproducible_result |
Artefacts published; anyone can check it. |
independent_confirmation |
A second party confirmed it, without published artefacts. |
threat_intel_report |
First-hand telemetry or casework from the party that observed it; not reproducible by a reader. An article reporting such a report takes this class: it is the class of what is reported, not of the outlet. |
vendor_claim |
Asserted by an interested party, nothing offered. |
analyst_assessment |
A judgement from someone who did not observe it. |
commentary |
Discussion of the above. |
- A class belongs to one source, never to a story. An edition's story can cite a threat-intel report and a vendor claim side by side; each reference line carries its own class. Do not summarise a story by its strongest member.
ai_rolesays what part AI played:instrument(used to attack),target(an AI system attacked),defender(used to defend),subject(capability research or an evaluation).incidental(mentioned, not involved) is kept in the archive but never briefed, and never appears in the evidence index.- An incident ID (
RL-I-YYYY-NNNN) is permanent. Several articles about one incident are coverage, not corroboration: count incidents, not articles.
What you can fetch
| What | Where | Format |
|---|---|---|
| This note | /agents.md | markdown |
| Capability manifest | /.well-known/agent-surface.json | JSON, agent-surface/0.1 |
| Site index | /llms.txt | markdown, llms.txt convention |
| Newest edition | /editions/latest.md · latest.json | markdown · JSON |
| Every edition | /editions/index.json (10 editions) | JSON, each edition's page, .md and structured .json |
| One edition, structured | https://redlens.liminallayers.com/data/newsletters/{date}.json |
JSON: summary, stories, numbered references with evidence class, incident and archive link |
| The newsletter by RSS | /feed.xml | RSS 2.0, each edition in full |
| Incidents seen by two or more sources | /incidents/multi_source.json | JSON, compact; start here |
| One incident | https://redlens.liminallayers.com/incidents/RL-I-YYYY-NNNN.json; all of them in /incidents/index.json (460 incidents) |
JSON: label, kind, its documents from the last 30 days (each with its own class), merges and corrections |
| What a person corrected | /incidents/corrections.json | JSON: every merge, moved document and relabel, with the reason |
| Evidence slices | /data/slices/index.json | JSON: one small file per class, role, day, category, jurisdiction, named system and system family, paged over 200; lean records with each document's id |
| One document | https://redlens.liminallayers.com/data/docs/{id}.json |
JSON: the full record (summary included) for an id from any slice or incident |
| Evidence index | /data/evidence.json · .jsonl (1967 documents, 30 days) | JSON · JSON Lines |
The editions
One a day, written in the evening UTC by Qwen3.8 27B running on our own hardware; no document is sent to a hosted AI service. Ranking, the choice of main story, the citations and every reference line (with its source's class) are written by code. A story appears only if a source we chose reported it, two publishers did, or its lone publisher has a record of being corroborated; the main story must also rest on a threat-intel report or stronger, or on two distinct sources, and a lone vendor claim can never lead. Every drafted sentence is checked against its story's sources. A sentence the verifier cannot support is deleted, never rewritten, and an edition losing more than three in ten is held. Since 2026-10-05 a citation closes each paragraph, from that story's sources, with inline ones for quotations and single-source figures; earlier editions cite every sentence. Held editions are never published, here or anywhere.
The markdown is the edition exactly as published. Its reference lines print a
class with spaces (threat intel report); the JSON and the other files use the
underscored token (threat_intel_report) and are what to match on. References link to the
source and, where one exists, to its Internet Archive copy.
Incidents
/incidents/index.json lists every incident with a document in the last
30 days, and /incidents/RL-I-YYYY-NNNN.json holds those
documents. Older coverage is not published, so first_reported is the
earliest document in the window, not necessarily the incident's first. An incident has no class of its own: each
document keeps its own, and document_count and distinct_sources are counts of
coverage, not votes.
Each incident has a kind: intrusion (it happened), disclosure (made
public: a vulnerability, a campaign, a vendor's threat report),
evaluation_result (a benchmark, a red-team finding or a paper's experiment:
not an event in the world), policy_action or other. If you want things
that happened, filter on kind.
Incidents are assigned by a local model and corrected by hand. A merged
incident's old ID still answers: its file is a pointer (merged_into) to the
survivor, merged in the index maps every one, and the survivor lists them in
merged_from. Every hand correction (a merge, a
document moved out of the wrong incident, a relabel) is in
/incidents/corrections.json with its reason, and each incident file carries
the ones that touched it in correction_log. An incident_id of none is an
answer, not a gap: the document was assessed and is not an incident (a paper,
an explainer, a trend piece). null means not yet assessed.
Reading it safely
Every payload carries schema_version (currently redlens.agents/2; the
manifest's schema_changes says what changed). Files
written for agents use snake_case; edition JSON (/data/newsletters/{date}.json)
is camelCase because the website reads it, and edition .md prints classes with
spaces. Match on the underscored tokens.
The labels are provisional. evidence_class, ai_role and incident
grouping are a local model's reading and are sometimes wrong: a document can be
mis-tagged, a "relayed" story takes the class of what it relays, and several
"incidents" are a single paper or benchmark (kind: evaluation_result). An
incident's title is its label (title_source; label_source says whether a
model or a person wrote it, and first_document_title is the first headline),
first_reported is a publication time where the source gave one and a fetch
time where it did not (first_reported_basis), and event_date is always
null: no event date is held. coverage says whether an incident is one
document, one source or several. categories are the classifier's topic tags
and are over-applied (malware is on more than half of all documents); on an
incident, categories lists the tags at least half its documents carry and
category_counts has them all.
The evidence index
Every document from the last 30 days that the classifier judged
relevant and not incidental: title, URL, an Internet Archive copy where one
exists, source, publication and fetch times, evidence_class, ai_role,
actor_class, categories, named systems, jurisdictions, its incident ID, a
stable id, and a summary written by our classifier (classifier_version says
which model). Only
the current classifier's verdicts are published. It holds no article text:
follow the link or the archive copy for the source's own words. Summaries are a
model's reading and can be wrong; the source is the authority. A field the
classifier left empty is null, never filled in with a guess.
Named systems are published in one canonical spelling (named_systems;
"Mythos", "Anthropic's Mythos" and "Claude Mythos" are one name), with vendors,
labs and agencies moved to named_organisations and the classifier's own list
kept as named_systems_as_classified.
To research a topic without downloading all of it, use the slices:
/data/slices/index.json lists a file for every class, role, day, category,
jurisdiction, named system and system family (a family is every version and
spelling: family/claude-mythos.json). A system or family gets a file at three
or more documents. A slice over 200 documents is paged; follow next. Slices
carry each document's id; /data/docs/{id}.json has the rest, summary
included.
What is not published
No third-party article text. No rejected documents, and no count of them. No gate data, term lists or per-source yield.
Nothing older than 30 days, except the editions. The editions are kept for all time; everything else (the evidence index, slices, document files, incidents and corrections) covers documents first fetched in the last 30 days, and an older one is not available here. An old edition's references still carry their source link and Internet Archive copy; its incident IDs stop resolving once the incident leaves the window.
Talking to the person behind this
Write to [email protected]: a correction, a source we have missed, or what you used this for. A person reads it; there is no autoresponder.
Nothing on this site accepts a write.
Conduct
The collector identifies itself with a real User-Agent and a contact address, honours robots.txt, and never works around a source that refuses it: that source is parked, with the reason recorded. Paywalled sources are recorded by headline and lede only. Fetch these files as often as is useful; they change once a day.