Public record · 18 linked entries

Evidence,
classified.

Every public achievement I can currently substantiate with a link. Normative changes, merged code, references, listings, self-published research, and closed work are labeled differently because they mean different things.

01
Normative guidance changeMerged

Execution-receipt guidance merged into OWASP AST09

OWASP changed the AST09 risk page itself to include execution-receipt implementation guidance.

Boundary: A merged contribution is not an OWASP endorsement of Nobulex.

02
Merged code fixMerged

Descriptor traversal fix merged into the AGV validator

The validator now detects descriptor_dimensions shape instead of assuming it. CodeQL, validation, drift, and DCO checks passed before merge.

Boundary: This corrects the older note that the pull request was still waiting on DCO.

03
Merged implementation and harness changesMerged

Five contributions merged into shared agent-governance test vectors

One Nobulex implementation and four later verifier, parser, emitter, and negative-vector changes were merged into ScopeBlind's shared conformance repository.

Boundary: The public research freshly reruns #22 only. Merge does not certify the broader Nobulex product.

04
Merged security guidanceMerged

AML and sanctions cheat sheet merged into OWASP

A 276-line cheat sheet for AML and sanctions controls in AI-agent payments was added to the OWASP Cheat Sheet Series.

Boundary: The merged document is guidance, not a certification or legal-compliance guarantee.

05
Merged design proposalMerged

Verifiable-compliance-receipts proposal merged into Microsoft's toolkit

Microsoft's Agent Governance Toolkit added the 75-line proposal to its live documentation tree.

Boundary: This is a proposal in the toolkit, not a Microsoft product endorsement.

06
Merged curriculum referenceMerged

Nobulex referenced in Microsoft AI Agents for Beginners

Lesson 18 added the Nobulex Python receipt SDK to its production references.

Boundary: A one-line reference is not adoption or endorsement.

07
Merged standards-process editMerged

IETF AUDIT charter corrections merged during review

Deliverable numbering and eight editorial errors were corrected in the AUDIT BoF preparation charter.

Boundary: This was an editorial contribution, not authorship of the charter or IETF endorsement.

08
Merged research proposalMerged

AST-mapped adversarial fixture-corpus proposal merged

OWASP added the fixture-corpus proposal and two AST09 vectors to its proposals directory.

Boundary: It is a discussion proposal, not normative OWASP specification text.

09
Reproduced historical vulnerabilityPublished research

CVE-2026-45316 recovered from source without advisory knowledge

Enforcement Coverage reconstructed a weaker read-vs-write permission check from sibling routes and matched the already-published Open WebUI vulnerability.

Boundary: Recovered, not first discovered. The official advisory classifies it as CWE-863 and low severity.

10
Self-published executable researchPublic

Witness Independence scale, vectors, and reference grader

The W0-W4 model grades where a receipt's trust anchor came from. A fresh documented-dependency run completed 36 checks with zero failures.

Boundary: This is Arian's own model and implementation. Its self-test is not independent validation.

11
Merged catalog listingMerged

Nobulex solution entry merged alongside other OWASP tools

OWASP's solutions catalog added a 41-line Nobulex entry.

Boundary: A catalog listing is not normative guidance or endorsement.

12
Merged marketplace packageMerged

Nobulex package merged into the Dify plugin marketplace

The packaged Nobulex plugin was added to Dify's official plugin repository.

Boundary: Marketplace inclusion is distribution, not proof of adoption or correctness.

13
Merged adopters listingMerged

Nobulex added to Microsoft Agent Governance Toolkit adopters

The toolkit's ADOPTERS file added Nobulex as its first listed adopter.

Boundary: The entry was submitted by Arian and does not establish Microsoft endorsement.

14
Self-published data auditPublic

Medicare policy archival baseline measured across 85 documents

The audit reports 41 of 85 surveyed policies, 48%, with zero archived versions in the measured Wayback CDX results.

Boundary: The repository labels this a baseline spike and publishes negative results and scope limits.

15
Self-published package researchPublic

DefaultDrift measured 1,253 patch releases

The current repository reports 62 passing tests and a 12-mutation battery with every mutation caught.

Boundary: This corrects the older 61-case, 11-mutation count. The current code is public.

16
Merged directory listingMerged

Nobulex listed in awesome-mcp-servers

The MCP Compliance Server was added to the directory's security section.

Boundary: A directory row is discoverability, not adoption.

17
Self-published thesisPublic

THESIS.md publishes five observable falsifiers

The project states five conditions that would make the original registry thesis wrong and preserves a correction explaining why they do not fully test the current gateway product.

Boundary: This is self-critique, not external validation.

18
Closed upstream contributionClosed without merge

yfinance price-adjustment observability patch submitted

The patch proposed stamping every return path so callers could determine whether requested price adjustment actually happened. It included a ten-case test design and live ticker follow-up.

Boundary: The collaborator closed it without merge. It must not be described as an accepted upstream fix.

Ranking rule

Movement outside my repository ranks first.

A change to someone else’s normative text or code outranks a reference. A reference outranks a list. A list outranks a page I wrote about myself. Statuses are rechecked against the linked artifact, so old “open” labels become “merged” or “closed” when reality changes.

Excluded from this page: private drafts, work with no surviving public artifact, and claims that cannot be linked.