Inclusion rules
- The source identifies an AI agent, agentic product, or agent-connected tool.
- The source describes a consequential action, security failure, governance bypass, or controlled demonstration.
- The record can point to at least one public source URL and a stable tracker URL.
- The write-up distinguishes what the source reports from Permission Protocol's control analysis.