PUBLIC DRAFT Version 0.1. Explore the framework, assess your practices, and start a pilot.
OBAAFFIELD GUIDE / 0.1

OPEN BUILD AND AGENT ASSURANCE FRAMEWORK

A clearer path to
safer software builds.

Know who can change, build, and release your software. Start with a checklist, identify the gaps, then put practical checks around your pipeline.

34 predefined questions. Runs in your browser.
Your answers are not sent to a server.

What does OBAAF do?

OBAAF combines a security checklist, workflow checks, and guidance for build pipelines and AI agents.

The questionnaire helps a team assess its practices. The checker inspects GitHub Actions workflow files, code ownership coverage, and recognized agent instruction files. Other tools and templates support proposal and release verification.

Know the scope

The checker does not scan application source code for vulnerabilities. A passing check is not a security certification. The wider framework is still a draft.

No terminal needed
for the first step.

A project lead can start the assessment. Bring the people who manage accounts, builds, and releases into the conversation.

Open the questionnaire
01

Gather evidence

Use account settings, access lists, and release procedures. Leave answers unknown when you cannot verify them.

02

Find your next improvement

Your answers produce a tier and a ranked list of open items. Every item at a tier and below must be satisfied.

03

Assign an owner

Start with practical fixes. An engineer or specialist handles installation and pipeline changes when you reach them.

TIER 1AccountedKnow who and what can publish.
TIER 2ControlledSeparate trusted release work.
TIER 3VerifiedProduce and check build evidence.
TIER 4AssuredAdd independent verification.

The assessment scores supplied answers; it does not verify evidence. The checklist focuses on game studios and software releases. Review applicability for other teams.

The build passed.
The workflow needed a fix.

A limited demonstration on a Netflix clone shows why application checks and configuration checks serve different purposes.

A MOVABLE VERSION LABEL

uses: actions/checkout@v6.0.0

A version tag can move to different code. OBAAF flags this action because it is not pinned to an exact revision.

Inspect the failed audit ↗
Application type check + buildPASS
OBAAF configuration auditFAIL
Merge gateBLOCKED

Finding: OBAAF-GHA-008 · Medium severity

Pinning selects exact code; it does not prove that code is safe. Both reports include one documented exception for the trusted auditor's private-access key, expiring January 9, 2027. This was not a full framework or studio validation.

A first project.
A manageable plan.

Organize the work around people.

  1. Complete the self-assessment with your team.
  2. Choose a few achievable improvements and assign owners.
  3. Ask an engineer to pilot the checker on one repository.
  4. Agree which findings should block merges and how exceptions are reviewed.
  5. Reassess after 90 days, using updated evidence.

OBAAF does not currently offer a managed onboarding service. Review the current licensing terms before production adoption or redistribution.

Keep agent authority
within clear boundaries.

The eight agent controls describe a proposed architecture. Installing the checker does not automatically enforce them all.

R1 Record where inputs come from

Label inputs by trust and preserve the exact snapshot an agent reads.

R2 Match permissions to input trust

Public content must not give an agent access to secrets or protected changes.

R3 Give each run a temporary identity

Use narrowly scoped credentials for each invocation, separate from human accounts.

R4 Separate proposals from changes

A separate process checks and applies proposals after the required approval.

R5 Protect agent instruction files

Review instructions and load them from the protected base branch.

R6 Verify tools and models

Pin tool dependencies to immutable revisions and check provenance where available.

R7 Isolate runs and restrict network access

Use fresh environments and control shared state and outbound connections.

R8 Keep signed records of agent runs

Bind inputs, authority, outputs, and approvals to verifiable run records.

Your reference shelf.

What is ready today?

Local tools, assessment scoring, templates, and the recorded workflow demonstration are available as a public draft. An independent studio pilot and broader platform validation remain pending. Agent egress is not enforced by default, and the inference proxy is not built.

Read the current licensing status ↗

The repository is public. No reuse license is granted yet; intended license grants remain a separate maintainer decision.