@Jurajπ΄ππ suggested publishing AI code audits as Nostr events. Exact commit, prompt, model checkpoint, findings. Signed, so agents can diff against prior runs instead of burning tokens on work someone already did. Projects with many independent clean runs could earn a badge.
I want
@npub1j9kt...uswx to display exactly this. Not produce. Display. A known pubkey attests: commit X of project Y was checked with prompt Z on model A. Highest criticality found: B. WalletScrutiny is a client rendering whatever floats around, at the visitor's discretion.
The obvious objection is "responsible disclosure" or "Coordinated vulnerability disclosure" (CVD) assumes a scarce researcher negotiating a timeline with a cooperative vendor. That world is ending. When anyone can run an audit for a few dollars in tokens, all bugs are shallow. The embargo you negotiate with one researcher does nothing about the thousand agents that surface the same finding tomorrow. Attackers never honored embargoes anyway. The only people an embargo reliably keeps in the dark are users!
Censorship resistant attestations flip the default. A vendor cannot lawyer a signed event out of existence. A wrong claim gets contradicted by other signed runs against the same commit, on the same rails, and the pubkey that cried wolf pays in reputation. That is a better error correction mechanism than a cease and desist letter.
And it does not stop at WalletScrutiny. App repositories and the projects themselves could consume the same events. Imagine a release page showing "14 independent attestations at this commit, highest criticality found: none".
What we need is an agreed event format. Commit hash, prompt, model, checkpoint ID, findings, criticality.
Project Loupe
@moneyball
Red Team
@calle
View quoted note β