Gather evidence
Use account settings, access lists, and release procedures. Leave answers unknown when you cannot verify them.
OPEN BUILD AND AGENT ASSURANCE FRAMEWORK
Know who can change, build, and release your software. Start with a checklist, identify the gaps, then put practical checks around your pipeline.
34 predefined questions. Runs in your browser.
Your answers are not sent to a server.
OBAAF combines a security checklist, workflow checks, and guidance for build pipelines and AI agents.
The questionnaire helps a team assess its practices. The checker inspects GitHub Actions workflow files, code ownership coverage, and recognized agent instruction files. Other tools and templates support proposal and release verification.
The checker does not scan application source code for vulnerabilities. A passing check is not a security certification. The wider framework is still a draft.
A project lead can start the assessment. Bring the people who manage accounts, builds, and releases into the conversation.
Open the questionnaireUse account settings, access lists, and release procedures. Leave answers unknown when you cannot verify them.
Your answers produce a tier and a ranked list of open items. Every item at a tier and below must be satisfied.
Start with practical fixes. An engineer or specialist handles installation and pipeline changes when you reach them.
The assessment scores supplied answers; it does not verify evidence. The checklist focuses on game studios and software releases. Review applicability for other teams.
A limited demonstration on a Netflix clone shows why application checks and configuration checks serve different purposes.
A MOVABLE VERSION LABEL
uses: actions/checkout@v6.0.0A version tag can move to different code. OBAAF flags this action because it is not pinned to an exact revision.
Inspect the failed audit ↗Finding: OBAAF-GHA-008 · Medium severity
Pinning selects exact code; it does not prove that code is safe. Both reports include one documented exception for the trusted auditor's private-access key, expiring January 9, 2027. This was not a full framework or studio validation.
For permitted local evaluation, use a checkout with Python 3.10 or later. Review the current licensing status before adopting or redistributing the draft:
python -m pip install -e .
obaaf check path/to/project --fail-on mediumReview findings locally, pilot CI, then make the agreed audit status required before merging. Private access needs credentials kept away from untrusted PR code. A public package is not yet available.
OBAAF does not currently offer a managed onboarding service. Review the current licensing terms before production adoption or redistribution.
The eight agent controls describe a proposed architecture. Installing the checker does not automatically enforce them all.
Label inputs by trust and preserve the exact snapshot an agent reads.
Public content must not give an agent access to secrets or protected changes.
Use narrowly scoped credentials for each invocation, separate from human accounts.
A separate process checks and applies proposals after the required approval.
Review instructions and load them from the protected base branch.
Pin tool dependencies to immutable revisions and check provenance where available.
Use fresh environments and control shared state and outbound connections.
Bind inputs, authority, outputs, and approvals to verifiable run records.
Commands, fictional answers, and scoring explained.
PLANWork through the tiers with your team.
EVIDENCEThe commits, runs, and limits behind the example.
DESIGNThe detailed requirements and implementation gaps.
Local tools, assessment scoring, templates, and the recorded workflow demonstration are available as a public draft. An independent studio pilot and broader platform validation remain pending. Agent egress is not enforced by default, and the inference proxy is not built.
Read the current licensing status ↗The repository is public. No reuse license is granted yet; intended license grants remain a separate maintainer decision.