Foundry Security Spec - An open specification for agentic AI security evaluation

Cisco has released Foundry, an open specification for building agentic AI security evaluation systems, distilling lessons from their internal operations. The spec defines eight core agent roles (Orchestrator, Indexer, Cartographer, Detector, Triager, Validator, Reporter, Coverage Guide) plus five optional extensions, a finding lifecycle, and a coordination substrate. It includes a constitution with eleven inviolable principles and ~130 functional requirements. Crucially, Foundry is designed to consume CodeGuard detection rules and operationalize a "detection-to-prevention flywheel" where missed findings generate new rules that improve both future evaluations and developer prevention via LLM coding assistants. The spec is infrastructure-neutral, deliberately lacks code, and is meant to be clarified and adapted to each organization's stack via a spec-kit workflow. It is not a turnkey scanner but a proven blueprint for building a self-improving security evaluation system. 

https://github.com/CiscoDevNet/foundry-security-spec

Comments

Popular posts from this blog

Prompt Engineering Demands Rigorous Evaluation

SecObserve: Simplified Vulnerability and License Management for CI/CD Pipelines

Secure Vibe Coding Guide: Best Practices for Writing Secure Code