Verifiable Engineering Evidence

Proven Engineering, Verifiable Results.

We build runtime verification and security auditing tooling for AI agent production systems. Every claim on this page is backed by data you can independently verify — no fabricated numbers, no borrowed credit.

24 Detection Rules
20,000 Public Traces
13 LLM Providers
33 Models Covered
80,000 Total Trace Assets

Evidence, With Sources

Each result below links to its primary source. Figures are taken from the artifacts themselves, not from estimates.

Detection Engine

24 Runtime Detection Rules

A bytecode-verified set of vulnerability detection patterns for AI agent frameworks, covering RCE, SSRF, credential exposure, prompt injection, and schema drift.

Source: bounty_rules.cpython-312.pyc, decompiled.
Patterns: VULN_PATTERNS list — 24 items.
SDK: correctover-ccs on PyPI
Open Dataset

20,000 Public API Traces

A release of 20,000 real production agent execution traces published for independent verification. Covers 13 LLM providers and 33 models.

File: Correctover-CCS-20K-Verification-Subset.jsonl
Lines: 20,000 (wc -l confirmed)
Download: GitHub Release
Dataset Coverage

13 Providers / 33 Models

Distinct LLM providers and models represented in the public trace dataset, counted from the dataset fields.

Providers: openai, github_models, cohere, anthropic, azure, deepseek, meta, qwen, mistral, together, groq, perplexity, fireworks
Method: field-level count across the 20,000-line file
Data Assets

80,000 Total Trace Assets

The full trace asset inventory behind the CCS program, held in the internal asset archive.

Breakdown: 20,000 public + 30,000 reserved + 30,000 reserved
Source: internal asset archive
Academic Record

CCS Framework Paper — Published DOI

A public specification of the CCS runtime verification framework for agent systems, registered with a resolvable DOI.

DOI: 10.5281/zenodo.21271910
Author: Correctover Research Group
Status: DataCite-registered, resolvable

Research Coverage

Our detection rules provide rule-level coverage for known vulnerability classes in the AI agent ecosystem. Coverage of a published CVE means our engine detects the underlying pattern — it does not mean Correctover reported that CVE.

Rule Coverage

CrewAI

CVE-2026-2287 · Docker sandbox RCE

Rule coverage for sandbox-escape and command-injection patterns in containerized agent execution.

Rule Coverage

LiteLLM

CVE-2026-30623 · MCP RCE

Rule coverage for remote command execution patterns in MCP tool invocation paths.

Rule Coverage

MCP Ecosystem

Tool authorization · path traversal · prompt injection · SSRF

Rule coverage for protocol-level patterns across MCP servers: readOnlyHint bypasses, path traversal, credential exposure, and SSRF.

Attribution: CVE-2026-2287 (CrewAI) and CVE-2026-30623 (LiteLLM) were reported, fixed, and credited to their respective researchers and maintainers. Correctover's CCS rules cover the underlying vulnerability patterns in our detection engine. We do not claim credit for CVEs we did not report.

Disclosure Submissions

Vulnerabilities we have reported to coordinated disclosure programs. Status reflects our submission state, not the program's final disposition.

2026-07

HackerOne — Cloudflare MCP report

In-flight report regarding a Cloudflare MCP integration issue.

Report #3904830

2026-07

Microsoft MSRC — markitdown

Three reports delivered to the Microsoft Security Response Center for the open-source markitdown project.

3 items delivered

Status note: Submissions marked "Submitted" are in the disclosure pipeline. Acceptance and confirmation status belongs to the respective platforms and programs.

Put this engineering to work on your stack.

Start with a free snapshot audit of your AI agent infrastructure. No commitment, no code access required.