Skip to content

[v3.1.0] Release showcase β€” what's new and what's nextΒ #931

Description

v3.1.0 is live! πŸŽ‰

Release notes | CHANGELOG

This is our biggest feature release since the v3.0.0 Microsoft-signed public preview. Here's a visual tour of what shipped.


πŸ’» Unified agt CLI (#924)

Single command-line entry point replacing 12+ separate tools. Plugin discovery, doctor diagnostics, global --json flag for CI/CD.

πŸ“Š Governance Dashboard (#925)

Real-time Streamlit-based dashboard showing:

  • Agent fleet health (active/degraded/offline)
  • Trust score distribution across your agent fleet
  • Policy compliance rates with SLO tracking
  • Recent audit events timeline

πŸ”„ Agent Lifecycle Management (#923)

8-state lifecycle model:
Provisioning β†’ Active β†’ Suspended β†’ Rotating β†’ Degraded β†’ Quarantined β†’ Decommissioning β†’ Decommissioned

Includes automatic credential rotation, orphan detection, and full audit trail at every transition.

πŸ” Shadow AI Discovery (#921)

Finds unregistered agents hiding in your infrastructure:

  • GitHub scanner β€” repos with agent-related topics/keywords
  • Process scanner β€” running agent processes on hosts
  • Config scanner β€” agent config files on disk
  • Risk scoring: each discovered agent gets a risk assessment

πŸ”’ Quantum-Safe ML-DSA-65 (#927)

Post-quantum cryptography ready today:

  • ML-DSA-65 (FIPS 204) for signatures
  • Runs alongside existing Ed25519
  • Seamless β€” agents automatically use the strongest available algorithm
  • Because Q-day preparation starts now, not in 2030

πŸ›‘οΈ OWASP ASI 2026 Taxonomy

Migrated from the draft OWASP Agentic Top 10 to the finalized ASI 2026 taxonomy with a complete reference architecture mapping. Still 10/10 coverage.

πŸ§ͺ PromptDefenseEvaluator (#854)

12-vector prompt injection audit covering:
Direct injection, indirect injection, jailbreaks, role manipulation, encoding attacks, multilingual attacks, and more.


By the numbers

Metric Value
Tests 9,500+
OWASP coverage 10/10
Policy eval latency < 0.1ms
Policy violation rate 0.00%
Framework integrations 20+
SDK languages 5 (Python, TS, .NET, Rust, Go)
Prompt-based safety violation rate 26.67% (AGT: 0%)

What's next

We're already working on the next wave:

  • Plugin ecosystem β€” mesh, sre, runtime packages registering with agt CLI
  • agt dashboard β€” terminal-native TUI (no browser needed)
  • Agent-to-agent delegation chains β€” governed delegation with trust decay
  • GA readiness β€” moving from Public Preview toward General Availability

⭐ If AGT is useful to your team, consider giving us a star! It helps others discover the project.

Feedback, feature requests, and contributions welcome. πŸ‘‡

Activity

  1. imran-siddique commented on Apr 13, 2026

    @imran-siddique
    CollaboratorAuthor

    Post-launch update β€” what shipped in the last 48 hours

    Since the v3.1.0 showcase, we've merged 14 additional PRs addressing market gaps, public criticism, and community contributions:

    New Capabilities

    PR Feature Tests
    #937 Data-Layer ABAC β€” classification-aware policies (PII/PHI/PCI detection, geography restrictions) 28
    #933 Developer Experience β€” 60-sec quickstart, AWS/GCP deployment guides, progressive complexity tutorial, YAML policy generator 21
    #956 AGT Lite β€” zero-config governance in 3 lines (from agent_os.lite import govern) + fixed broken quickstart 16
    #955 Reversibility Checker β€” pre-execution reversibility assessment with compensation plans 19
    #955 Trust Score Calibration Guide β€” weights, decay functions, threshold recommendations

    Security Hardening

    PR Fixes
    #944 9 CWE fixes in new packages (symlink escape, path traversal, race conditions, auth bypass)
    #945 7 fixes in existing code (XSS, curl|bash, CORS wildcard, PII in exceptions, policy fallback warning)

    Documentation & Quality

    PR What
    #941 Normalized all 20 tutorials to consistent format (metadata, What You'll Learn, Next Steps)
    #929 README cleanup β€” all 13 packages now documented

    Community PRs Merged

    PR Contributor What
    #908 Adam Lin (@eeee2345) (Cisco ATR) 15 ATR detection rules + sync script for 108 rules (closes #901)
    #948 kevinkaylie ADR 0005 β€” Liveness attestation for TrustHandshake
    #949 Harsh-Cyber (@harshnair75567-cloud) LotL prevention policy
    #899 Aymen Hmaidi (@aymenhmaidiwastaken) MCP Security blog post (closes #848)

    Production Policy Library

    Shipped 5 battle-ready policy sets in examples/policies/production/:

    • minimal.yaml (startups) β†’ enterprise.yaml β†’ healthcare.yaml (HIPAA) β†’ financial.yaml (SOX/PCI) β†’ strict.yaml (defense/ITAR)

    By the numbers (updated)

    Metric At launch Now
    Tests 9,500+ 9,700+
    PRs merged (total) 343 357+
    Production policy sets 0 5
    ATR detection patterns 38 86+ (community) + 15 (PolicyEvaluator)
    Tutorials normalized ~10 consistent All 30 consistent
    Security findings fixed β€” 27 of 31
  2. imran-siddique commented on Apr 16, 2026

    @imran-siddique
    CollaboratorAuthor

    v3.1.0 has been released β€” closing this showcase issue. See RELEASE_NOTES_v3.1.0.md for the full changelog.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions