Changelog
All notable changes to the portfolio. Format loosely follows Keep a Changelog; the project itself is a Next.js site, not a library, so versions are semantic over feature batches rather than over public-API breaks.
[0.8.1] - 2026-10-03
Fixed
- agent-audit-kit numbers - the rule count now comes from the latest release's
rules.jsonbundle and the version from its tag, so the badge,/oss/agent-audit-kit, the home page and the resume show the current release instead of a count frozen in old release notes. The badge label says it is the total rule count, not only the OWASP MCP rules. - agent-audit-kit response time - removed the fixed CVE-to-rule turnaround promise everywhere. The project retired it; what it has is a public CVE-to-rule ledger with measured latency, now linked from its page.
- Licenses - agent-airlock and agent-audit-kit are Apache-2.0, not MIT.
- agent-airlock - described the way its own repo does: a type-checker and contract layer for AI agent tool calls, deny-by-default, in-process. Its version, test count and coverage are synced from the README test badge at the latest release tag instead of being typed by hand.
- Provael - the measured result now quotes the current headline from provael.com, with its benign control, interval and the "simulation only" caveat. The Embodied AI Security Top 10 is described as independent, not OWASP-style.
- MannSetu - copy matches MannSetu's own wording: Hindi and English, CBT-based exercises, working toward DPDP Act alignment, hosted on AWS in the US with a move to India planned, live with early users. Removed a superlative, a therapy tag and an unpublished user count.
- Cost router -
/principlesno longer gives a cost-cut percentage. - verdict is now proofloop - the repo was renamed on GitHub; cards, links,
/uses,/nowand the llms files follow. - The Production Agent -
/bookand the chapter pages say what is true today: chapters 1 and 2 are free drafts on this site, 3 to 5 are outlined, and nothing is on Substack or for sale yet. The bundle button is gone. - Hugging Face link - the JSON-LD and the chat knowledge base now point at huggingface.co/Sattyam.
- AGENTS.md - the capability-lease template link pointed at a file that does not exist; it now points at the essay's wire format and the
/api/quoteJSON Schema. - Sitemap - the five book chapters and disclosure #001 are listed.
- agent-audit-kit page - the rule catalogue lists the project's 14 real rule categories and shows OWASP Agentic (ASI01-ASI10) and MCP (MCP01-MCP10) coverage under OWASP's own ids, with links to the generated coverage tables. Removed rule families and features it doesn't have (numbered, compliance and capability-lease rule ids, allow-list drift, audit-trail-gap detection) and the "interoperates with" claim for Microsoft's Agent Governance Toolkit, which is complementary, not integrated. The compliance chips list all 14 frameworks, and the Marketplace link goes to the actual listing. The
/projectscard drops an internal note about a NIST profile mapping that doesn't exist and a third-party comparison the project's docs don't make. - Disclosure #001 - the detecting rule is AAK-STDIO-001 (first shipped in v0.3.2, mapped to ASI02 and MCP01), not AAK-MCP-001, which flags remote MCP servers without authentication. The page now describes what the rule really checks and carries a dated correction. Its affected list now matches NVD's record for CVE-2026-30623 (LiteLLM, fixed in 1.83.7-stable) instead of five frameworks the record doesn't name, with NVD and LiteLLM's advisory added as references. Book chapter 2 and
/startsay the same. - /now - no longer promises a 15-minute refresh or a live feed. On AWS Amplify the page and
/now.jsononly update when the site deploys, so that is what they say now, and the footer shows when the page was last updated. Same fix inAGENTS.md, the llms files and the chat knowledge base. - /uses - it said "Updates daily", but it's hand-edited static content dated 2026-05-03. It now says it's updated by hand when the stack changes.
- Capability Lease - it stays the pattern and the essay. The essay, the resume and the chat knowledge base no longer claim an agent-audit-kit rule family for it or a measured latency; agent-airlock is where leases are enforced. The essay carries a dated correction.
- Accessibility - the rule-category list on
/oss/agent-audit-kitand the book's chapter list keep their list semantics in Safari and VoiceOver, star and fork counts on/projectsare read as "stars" and "forks" instead of bare numbers, the agent-audit-kit "Where it fits" links get the 44px touch size and the Marketplace link names the tool for screen readers, and the agent-airlock link on the Capability Lease essay shows an external-link icon instead of the internal-link arrow.
Removed
content/products.yml. Nothing read it, and it still carried retired numbers.
Added
scripts/check-claims.mjsfailsnpm test, and a new "Content truth" CI workflow, when any of these retired claims comes back./llms-full.txthas a "Current Release Numbers" section generated from the synced GitHub data.
[0.8.0] - 2026-09-28
Changed
- AI chat - answers now come from the server (
/api/chat) instead of your browser. Jev, TypeSafe AI's decision model, picks the knowledge-base entries that answer the question, and Claude Haiku writes a short reply from only those entries, both through OpenRouter. It can combine facts and answer in plain sentences instead of pasting one entry. Off-topic questions get a polite redirect, and instructions hidden in a question are ignored. If Claude Haiku fails, Gemini Flash-Lite writes the reply, and if that fails too, you get the picked entry itself. Each question stands alone. In a 21-question bake-off, Jev picked the right entry 20 times; the old in-browser matcher managed 16. - Chat panel - it's ready as soon as it opens, with no model to download. A short note says replies are written by AI and can be wrong, and that questions and answers are logged. Rate limits, outages and timeouts each say what happened and how long to wait, and a question that fails goes back in the message box. A question over 500 characters says how long it is instead of being cut off. The contact email in a reply is a link.
- Chat for screen readers - you hear "Working on your answer", one "Still working" after 8 seconds, then the reply once. A reply that arrives while the panel is closed is read out when you reopen it. The typing dots stop after four bounces.
- Accessibility statement - the chat limitation now says it needs JavaScript, sends your question to an AI service, and can be wrong.
Removed
- The in-browser chat model (Transformers.js running MiniLM in a Web Worker),
public/knowledge-index.json(1.36 MB), the embeddings build step and the@xenova/transformersdependency.
Security
- The CSP no longer allows
'wasm-unsafe-eval',blob:workers or the Hugging Face and jsDelivr hosts. /api/chatrefuses cross-origin browser requests and takes JSON only (8 KB bodies, 500-character questions). Each visitor gets 6 questions a minute and 30 a day, and each server instance 100 an hour; a request refused by one limit doesn't use up another, and a question that gets no answer doesn't count toward the day. The OpenRouter key is server-only, and without it the route answers 503. Each request is logged as one line with the question, the reply and a salted client tag, never the IP address.
Added
npm run eval-chatruns 23 real questions through the pipeline and fails on invented links, markdown, versioned model names, salary or client-name leaks and obeyed injections (about $0.05 a run). With--urlit smoke-tests a running build.npm testcovers the chat pipeline with 66 specs, and the Substack guard now scansdata/.
[0.7.3] - 2026-09-27
Changed
- Touch targets - on phones and tablets, buttons and links that stand on their own are now at least 44px, the size DESIGN.md asks for. The footer's quick links become two columns of full-size rows, and small text links, icons and the resume's contact links get taller tap areas. Desktop is pixel-identical (checked on every page at 1280, 1024 and 768px), and the resume PDF is unchanged.
Fixed
- Focus under the chat button - at 320px, tabbing to a footer link could leave it hidden under the chat button. Focused content now scrolls clear of it.
Added
npm run check-targetsmeasures tap targets on a running build, across every sitemap page and the pages they link to: 44px on touch, WCAG 2.5.8 spacing on desktop, and no overlapping targets. AccessLint has no target-size rule, so this covers the gap.
[0.7.2] - 2026-09-27
Fixed
- Chat widget - it's now a proper dialog. Opening it moves focus into the question box, and closing it moves focus back to the chat button. Escape closes it from anywhere on the page, and sending a question or pressing Retry no longer drops focus to the page. Asking a question no longer scrolls the page behind the chat, and at 400% zoom the input and Close button stay on screen.
- Chat for screen readers - each reply is read out once, as soon as it's chosen, and every message says who wrote it. The question box has a real label and stays editable while the model loads, and a send that can't go through yet says why. Replies finish streaming within about two seconds and appear at once with reduced motion.
- Accessibility statement - now targets WCAG 2.2 AA and says plainly that the site partly meets it. It lists what was checked and what wasn't, and drops two claims that weren't true: embedded third-party content and "screen reader support".
Changed
- With both the mobile menu and the chat open, one Escape closes just the menu.
[0.7.1] - 2026-09-26
Fixed
- /changelog was blank - the whole page sat inside one scroll-reveal block that needed 20% of an 11,700px article on screen at once, which never happens. Blocks now reveal as soon as any part is visible, so tall sections also show at 400% zoom, and print, reduced motion and no-JS always show content. The changelog renderer now handles nested lists, wrapped list items, reference links and bold text.
- Header nav - between 768 and 983px the nine links pushed every page sideways. The desktop nav now starts at 1024px. The mobile menu closes on Escape (focus goes back to the button), on route change, on an outside click and on resize, and it gained the Consult link.
- Accessibility (WCAG 2.2 AA) - a production sweep found about 60 issues on 12 pages; all 24 pages now audit clean. Text links are always underlined, link names start with their visible label, card grids use one real link instead of a label that hid the card text, focus rings survive Windows High Contrast, focused items no longer hide under the sticky header, the skip link sits above the header, and low-contrast text on /resume, /book, /building and the disclosure badges is fixed.
- llms-full.txt - 25 of 26 section lookups pointed at chunk ids that no longer existed, so Experience was empty and open source never appeared. Section orders now live in one module shared with the Copy-to-LLM button, and a test fails if an id goes stale. Both also linked to sattyamjain.in (single j), which doesn't resolve.
- Chatbot - the loading indicator sat near 0%, and questions like "what products has he built?" or "where does he work?" got unrelated answers. Three direct-answer entries fix those. Loading progress, readiness and load failures are announced to screen readers, and Retry announces again.
- Narrow screens - at 320px, content on the home page, /building, /book and /uses was up to 15px wider than the screen and silently cut off. Grid columns can now shrink and long button labels wrap, so nothing is clipped at 320px, including with enlarged text spacing.
- Broken links - OWASP Agentic Top 10, OWASP MCP Top 10, Cisco and Devin references now point at live pages. The link checker skips code placeholders and example domains, retries with a browser-style GET, and handles oversized response headers.
Changed
public/AGENTS.mddocuments every/api/healthfield and the/api/quotev0.2 fields.- Brand icons (GitHub, LinkedIn, X) no longer use lucide's deprecated exports.
scripts/check-a11y.mjsguards the fixed patterns innpm test, and lint is clean with no warnings.
Security
- Dev-dependency audit is clean: scoped overrides give
@xenova/transformersprotobufjs 7.6.6 and sharp 0.35.4 (1 critical and 4 high before). Chatbot embeddings are bit-for-bit unchanged.
[0.7.0] - 2026-09-26
Added - 255 (get255.com)
- 255 - a just-for-fun writing experiment on Jev, TypeSafe AI's decision model, via OpenRouter. Drop in any text, see 255 AI impressions at once, change one sentence and watch what moves. Featured in
/building(now five live products) and/projects, on the résumé and/about, in the chatbot and in the llms files. I wanted 255.ai, but it was listed at about ₹2.45 crore, so it lives at get255.com.
Security
- Next.js 16.3.6 - closes two critical RCE advisories: Image Optimization with AVIF (GHSA-2xp9-vwfh-vxw4) and
next/ogImageResponse (GHSA-vcvr-r3jv-pc5j). The CI floor inscripts/verify-next-cve.tsis now 16.3.6. - Resume PDF stack - puppeteer-core 25.11 with @sparticuz/chromium 153, which drops the vulnerable extract-zip. Needs Node 22.17+.
- Unused dependency removed - @react-pdf/renderer, never imported.
Fixed
- Model naming - the site names model families (Claude Opus / Sonnet / Haiku, OpenAI GPT, Google Gemini Pro) instead of version numbers, which go stale within weeks.
lib/models.tsis the source of truth and the model guards enforce families only. - OWASP benchmark marked as a draft - the scores are working estimates, not audited results, so the page is noindex and out of the sitemap,
/start, the llms files and the chatbot until the audited version ships. Dead links are gone, and the ten families are labelled as the OWASP Top 10 for LLM Applications (2025). /api/healthon Amplify - reports the deployed commit again (amplify.ymlwrites it into.env.production). The post-deploy check now waits for the pushed commit, smoke-tests the resume PDF, and keeps one tracking issue instead of opening one per push.- IndexNow - pings the www host after a verified deploy; the apex host was rejecting the key.
- llms.txt section name - "Open Source" is now "Open Source & Products", since it also lists live products that aren't open source (MannSetu, whycantwehaveanagentforthis, 255).
- Accessibility -
/projectsbutton labels now start with their visible text ("View Project: ...", "View on GitHub: ..."), which clears six label-in-name findings. Long product domains on/buildingwrap inside their button instead of overflowing the card at narrow widths or under text-spacing overrides.
Removed
- Unused components (LeadMagnetCTA, the old article/project/timeline cards, gradient-text, the quote demo, two posture badges, four unused shadcn primitives) and the orphaned
content/now-physical-ai.yml.
[0.6.0] - 2026-07-24
Changed - "Agentic & GenAI" → "Building" products hub
- Renamed section
/agentic-genai→/building("Building" in the nav), reframed from a case-study page into a live-products hub: four products I build and run (Provael, MannSetu, Why Can't We Have An Agent For This, Agentify) shown as cards with domain CTAs + status + ownership chips, Provael + MannSetu elevated under a "doubling down" banner, then open source and enterprise case-studies below. Permanent redirect from/agentic-genai;#mannsetu/#agentifyanchors preserved.
Added - Provael (physical-AI security)
- Provael integrated as a flagship product - featured in
/building,/projects,/start, the chatbot KB (fourprovael-*entries plus a consolidated live-products entry),/uses(VLA simulation stack: LIBERO / robosuite / MuJoCo / LeRobot / uv), and/resume. All links point to the live product at provael.com + GitHub - no dedicated portfolio microsite, since provael.com already fills that role (/provaelredirects to/building). - Live metrics -
provael/provaelwired into the product-metrics sync (stars / forks / latest release version self-update on build) and into the/now"Shipping right now" feed (cross-org commits). - Person JSON-LD - added "Embodied AI security" + "Vision-Language-Action (VLA) policies" to
knowsAbout; Provael named in the Person description.
[0.5.0] - 2026-04-30
Fixed - model-posture truth
- P0 / Task 1 -
scripts/check-models.mjsregex extended to flag bareGemini 3.1 Pro/gemini-3.1-pro(superseded by Gemini 3 Pro preview, blog.google 2026-04-22) plus the retiredo1-mini,o1-preview,o3-mini,o3-pro,o4-miniprefixes. - P0 / Task 2 -
scripts/check-projects.mjsre-run: 6 shipping products green, VAJRAnow-building, PyVerseAI absent. - P0 / Task 3 - New
scripts/check-registry.mjs. For every endpoint declared in/agents-registry.json, verifies a corresponding Next.js route file exists. Wired intonpm test. - P1 / Task 4 -
/llms-full.txtmodel-posture line refreshed: date stamp 2026-04-29 → 2026-04-30;gemini-3.1-pro→gemini-3-pro-preview; newaudio: gemini-3.1-flash-tts (eval-only)sub-line; newwatch-list: deepseek-v4-pro, mistral-medium-3.5 (not in production routing)footnote. - P1 / Task 5 -
/writing7-day freshness re-audit. The 2026-04-27 32-Day Window Medium piece remains index 0 (still ≤ 7 days) - no newer Medium / Substack entry has landed.
Added - new public surfaces
- F1 -
/identity-posturepage +/identity-posture.jsonmachine twin. Three-card declaration of the agent-identity stack: Okta NHI (GA 2026-04-30), W3C DID + Verifiable Credential, capability-lease envelope. Each card cites its primary source. Linked from the footer + the Okta-NHI section on/agentic-genai. - F2 -
/api/quote/schema.jsonv0.2. Adds optionalokta_nhi_token(Okta for AI Agents GA, 2026-04-30) andbedrock_invocation_arn(AWS Bedrock Managed Agents preview, 2026-04-28). Both log-only; not yet cryptographically verified.version+lastModifiedkeys added to the schema body. Handler inapp/api/quote/route.tsaccepts and echoes the new fields and raises the rate limit from 30 → 60 / hr / IP. Newtests/quote-schema.spec.ts. - F3 -
/usesadds an "Agent identity (3-layer)" section (Okta NHI · DID · capability lease) and an AWS Bedrock Managed Agents row in Infrastructure.Updated:stamp moved to 2026-04-30. - F4 -
<MarketSignalCard />reusable component (requires a primarySourceUrl prop) +content/market-signals-2026-04-30.tswith 8 ≤ 7-day signals + new section on/agentic-genai. Auto-prune viascripts/check-market-signals.mjs(stale-after 14 days unless pinned).
Added - context cards on /agentic-genai
- P1 / Task 6 - Vendor-lock-in posture aside citing the Microsoft-OpenAI partnership restructure (blogs.microsoft.com, 2026-04-27).
- P1 / Task 7 - Okta-for-AI-Agents GA section (Okta Showcase 2026, 2026-04-30) linking to /identity-posture + /identity-posture.json.
- P2 / Task 9 - Anthropic Claude for Creative Work (9 first-party MCP connectors, 2026-04-28) advisory line appended to the existing CVE-2026-30623 MCP-STDIO posture section.
Added - context lines on /projects
- P2 / Task 8 -
agent-airlockcard now ships an Interop bullet citing AWS Bedrock Managed Agents (Codex / GPT-5.5 limited preview, 2026-04-28). Theinteropdata field is now actually rendered (was defined but unused). - P2 / Task 10 -
agent-audit-kitcard description cites OpenObserve Observability 3.0 + autonomous AI-SRE (2026-04-29) as a category-comparable runtime layer.
Changed - A2A discovery + truthful posture line
- P2 / Task 11 -
<link rel="alternate" type="application/json" href="/agents-registry.json">added to root layout so any A2A crawler discovers the manifest from any route. /agents-registry.jsonrequest_schema_version: "0.2",rate_limit.requests: 60,last_updated: 2026-04-30. New/identity-posture.jsonendpoint added.lib/models.tsLATEST_GOOGLEgemini-3-1-pro→gemini-3-pro-preview. NewLATEST_GOOGLE_TTSandWATCH_LIST_MODELSexports.app/layout.tsxkeywords updatedGemini 3.1 Pro→Gemini 3 Pro.
Verification
npm test: 61/61 + 5 check scripts (projects, substack-canonical, models, registry, market-signals) all green.npx tsc --noEmit: clean.npx next build --webpack: clean. New routes ship: /identity-posture static (1d), /identity-posture.json static (1d), /api/quote/schema.json v0.2 static (1d).- Local production smoke test confirmed all surfaces.
- Local Lighthouse desktop: Perf 100 / A11y 100 / BP 96 / SEO 100 (no regression vs. 0.4.0).
Sources
- Microsoft, The next phase of the Microsoft-OpenAI partnership (2026-04-27): https://blogs.microsoft.com/blog/2026/04/27/the-next-phase-of-the-microsoft-openai-partnership/
- AWS, Bedrock OpenAI Models (Codex) Managed Agents (2026-04-28): https://aws.amazon.com/about-aws/whats-new/2026/04/bedrock-openai-models-codex-managed-agents/
- Anthropic, Claude for Creative Work (2026-04-28): https://www.anthropic.com/news/claude-for-creative-work
- Okta, Showcase 2026 - Okta for AI Agents GA (2026-04-30): https://www.okta.com/newsroom/press-releases/showcase-2026/
- DeepSeek V4-Pro / V4-Flash (2026-04-24): https://api-docs.deepseek.com/news/news260424
- Mistral Medium 3.5 (2026-04-29): https://releasebot.io/updates/mistral
- OpenObserve Observability 3.0 + AI SRE (2026-04-29): https://www.morningstar.com/news/business-wire/20260429034926/openobserve-introduces-ai-native-observability-platform-with-autonomous-ai-sre-agent-to-unify-infrastructure-application-and-llm-monitoring
- Google, Gemini 3 Pro preview (2026-04-22): https://blog.google/products/gemini/
[0.4.0] - 2026-04-29
Fixed - truth + canonical-URL hygiene
- Task 1 - Substack canonical-URL sweep + new
scripts/check-substack-canonical.mjsCI gate. Legacysattyamjjain.substack.comhost blocked from resurfacing in any app/, public/, content/, components/, or lib/ file. The newsletter canonical ishttps://theproductionagent.substack.com/. - Task 2 - Frontier-model regression CI gate (
scripts/check-models.mjs). Bans Opus 4.6 / Sonnet 5 / Sonnet 4.7 / GPT-4o / bare GPT-5 / Claude 3.x / Haiku 3.x / Gemini 2.x outside the documented fallback context. Caught two real regressions on first run: bare"GPT-5"inapp/layout.tsxkeywords (now upgraded to GPT-5.5 / 5.5 Pro / Opus 4.7 / Sonnet 4.6 / Haiku 4.5 / Gemini 3.1 Pro), and an "Opus 4.6" doc-comment inlib/models.ts. - Task 3 - Re-ran
scripts/check-projects.mjs: 6 shipping products green, VAJRAnow-building, PyVerseAI absent. - Task 4 -
/llms-full.txtmodel-posture date roll-forward 2026-04-28 → 2026-04-29. Body line unchanged (no new vendor releases). - Task 8 - X handle case canonicalised to lowercase
x.com/sattyamjjainacross 11 surfaces (AGENTS.md ×2, /resume, /about, structured-data, profile.ts, footer, article-schema, portfolio-data, json-ld test).
Added - net-new agent-readable surfaces
- F1 / Task 6 -
/api/quote/schema.json- public JSON Schema (draft 2020-12) for the signed-capability-lease envelope. Buyer-agents validate locally before POSTing. References Anthropic Project Deal + Cisco Agentic Workforce Identity. - F2 -
/agents-registry.json- public A2A-protocol manifest. Declares all outward-facing agent endpoints (/api/quote, /api/health, /api/badges/agent-audit-kit, /now.json, /now-physical-ai.json, /llms.txt, /llms-full.txt, /AGENTS.md) with per-endpoint method, rate limit, and capability-lease requirements. - F3 -
/usesPhysical AI subsection bumped to fully-pinned: JetPack 6.3 (L4T r36.4.x), ROS 2 Jazzy 0.13, NanoOWL @ 0.4.2, GR00T N1.7 (commit-pinned), Cosmos 3 sim assets v3.1. - F4 -
<CapabilityLeaseBadge />reusable component. Mounted on/agentic-genaiagent-commerce section; ready for additional mounts on/projectsagent-airlock card. - F5 -
/changelogroute - auto-rendersCHANGELOG.mdwith per-section anchored URLs. Added to sitemap + sync-route-dates. - Task 7 - NIST AI RMF Profile-for-Agents v1.0 framing on the agent-audit-kit project card with
(mapping in progress)honesty caveat - verify GA on nist.gov before flipping to "mapped".
LLM discovery
/llms.txtOptional section gains/agents-registry.json,/api/quote/schema.json, and/changelogbullets.- Sitemap + sync-route-dates extended to include
/changelog.
Deferred (per Open Issues)
- Per-route dynamic OG via
next/og- VAJRA / talks-2026 / changelog still on static OG. - Wikidata Q-item still queued (sameAs[] gap).
/api/atlas-pingsremains console-log stub; F2 quote widget POSTs there for now.- Stanford AI Index 89% - still cited from secondary coverage; verify against the official 2026 AI Index PDF before next reuse.
[0.3.0] - 2026-04-26
Fixed - truth corrections
- Task CC - Replaced
Claude Sonnet 5→Claude Sonnet 4.6site-wide. Anthropic's GA Sonnet is 4.6 (platform.claude.com); yesterday's Task V landedSonnet 5copy from a leak/speculation source.lib/models.tsis now authoritative;tests/model-strings.spec.tsfails the build ifSonnet 5ever creeps back. Updated:lib/models.ts,lib/schema/profile.ts,scripts/generate-llms-txt.ts,components/faq-schema.tsx,components/structured-data.tsx,app/page.tsx,app/projects/page.tsx,app/agentic-genai/page.tsx,app/agentic-genai/layout.tsx,data/portfolio-data.json. - Task DD - Re-purged PyVerseAI from
/projects(regression of 2026-04-21 Task N).tests/projects-no-pyverseai.spec.tsblocks future regressions. - Task EE -
/api/healthroute now declaresexport const dynamic = "force-dynamic"soVERCEL_GIT_COMMIT_SHAreads at request time (it is NOT injected into the build env)..github/workflows/post-deploy-health-assert.ymlpolls the live endpoint after every push tomainand opens ahealth-wire-regressionlabelled issue ifcommitreturns"local". (Vercel system env vars) - Task FF - Replaced the stale generic-tooling
knowsAbout[]incomponents/structured-data.tsx(OpenAI GPT-4,Claude AI,Microservices Architecture, …) with the canonical 12-entry topic-authority array (AI agents,Multi-agent systems,Model Context Protocol (MCP),LLM orchestration,Agentic AI security,OWASP Agentic Top-10,Production GenAI platforms,AgentOps,Capability leases,LLM red-teaming,Python,TypeScript).lib/schema/profile.tstrimmed to match.tests/knowsabout-content.spec.tsenforces drift parity between the two schemas.
Added - market signals
- Task GG - New "Where this work fits the 2026 frontier-security stack" section on
/agentic-genaiwith three Apr-2026 cards: Anthropic Mythos Preview / Project Glasswing (anthropic.com/glasswing), LangChain-ChatChat 0.3.1 RCE via MCP STDIO (thehackerwire.com), Claude Code v2.1.117 sandbox hardening (code.claude.com/docs/en/changelog). Posture aside added to/llms-full.txtmodel-posture blockquote noting Mythos is explicitly excluded from production posture. Gemini 3.1 Pro added as eval-only model in posture. - Task HH (deferred) - Today's OX-MCP-STDIO Medium piece is not yet in the ingested feed (RSS hasn't propagated). Will land on the next ingest run; no manual entry needed.
Added - net-new product features
- Feature Q1 -
/nowpage (Edge runtime, 15-min revalidate). Pulls last 14 days of GitHubPushEvents across the 6 production repos (agent-airlock,agent-audit-kit,verdict,mnemo,ferrumdeck,aboutme), last 30 days of writing fromcontent/external-writing.generated.ts, and calendar links. JSON twin at/now.json. Surfaced in/llms.txt ## Optional. (nownownow.com) - Feature Q2 -
/usespage (the uses.tech convention). Daily revalidate. Sections: Editor + agent loop, Models in production rotation, Runtime, Infrastructure, Security tooling, Observability, Hardware. Each line cites primary source. Surfaced in/llms.txt. - Feature Q3 -
/api/badges/agent-audit-kitShields.io-format JSON endpoint. Pulls live rule count + version fromcontent/products.generated.ts(PRODUCTS.agent_audit_kit). Embeddable in README / Substack / Medium viahttps://shields.io/endpoint?url=https%3A%2F%2Fwww.sattyamjjain.in%2Fapi%2Fbadges%2Fagent-audit-kit.
[0.2.0] - 2026-04-25
Added - frontier-model truth + topical authority + wrap-up
lib/models.ts- single source of truth for frontier-model identifiers and theFRONTIER_POSTURE_LINEstring. Bumps land here first; downstream consumers import. (OpenAI: GPT-5.5, Anthropic: models overview)Person.knowsAbout[]- agent-security topical signals added (AI agents, Agentic AI security, OWASP Agentic Top-10, Production GenAI platforms) and frontier model bumps (Sonnet 5, GPT-5.5). (knowsAbout authority signal)- Per-route
ProfilePage.dateModified-scripts/sync-route-dates.tsemitscontent/route-dates.generated.tsfromgit log -1 --format=%cIper route;ProfilePageSchemais now a client component readingusePathname(). Each canonical route emits its own@idand a real freshness timestamp. (schema.org/dateModified) - Wikidata sameAs (staged) -
WIKIDATA_QID: string | nullconstant +buildSameAs()helper inlib/schema/profile.ts; auto-appendshttps://www.wikidata.org/wiki/<QID>toPerson.sameAs[]when set. Submission steps + 4 citation URLs indocs/wikidata-evidence.md. (Wikidata as KG trigger) /api/health- returns{commit (7-char), branch, deployedAt}from Vercel system env vars (VERCEL_GIT_COMMIT_SHA,VERCEL_GIT_COMMIT_REF,VERCEL_DEPLOYMENT_CREATED_AT). Falls back to"local"when env is unset. (Vercel system env vars)/feed.xmlApril-2026 stop-gap - 4 most recent Medium URLs prepended to the hardcodedarticlesarray; mirrored incontent/writing.ymlas future-proof source of truth pending the auto-ingest cron rewrite.- Regression tests -
tests/llms-full-truth.spec.ts(asserts the current frontier-model strings are present) andtests/json-ld-knowsabout.spec.ts(assertsknowsAbout[]shape + Wikidata wiring). Run vianpm test(node:test, no new deps).
Changed - model-name sweep
- Replaced
Claude Sonnet 4.6→Claude Sonnet 5andGPT-5.2/GPT-5/GPT-5.2→GPT-5.5(andGPT-5.5 / GPT-5.5 Prowhere the paired form was used) across:scripts/generate-llms-txt.ts(model-posture blockquote in/llms-full.txt)data/portfolio-data.json(RAG chatbot knowledge base - 5 chunks)components/faq-schema.tsx(FAQ JSON-LD answer)app/page.tsx(home featured-card tags + skills array)app/projects/page.tsx(Agentify card tags)app/agentic-genai/page.tsx(case-study tech-stack chips + cascading-router caption)app/agentic-genai/layout.tsx(page metadata description)
Skipped (per direction)
- Atlas-traffic detector /
/api/atlas-pings- deferred until Vercel KV is provisioned. In-memory storage would lose pings on cold start; not useful telemetry.
[0.1.5] - 2026-04-24
Added - ProfilePage schema + Next.js CVE pin + LLM discovery + capability-lease tagline
lib/schema/profile.ts+components/profile-page-schema.tsx- Google-compliant ProfilePage JSON-LD with@idanchored at/about#person. Per-spec at developers.google.com/search/docs/appearance/structured-data/profile-page.- Next.js 16.2.4 pin - closes CVE-2026-23869 (RSC DoS) and CVE-2026-29057 (http-proxy rewrite smuggling). New
scripts/verify-next-cve.ts+.github/workflows/security.ymlgate the patch floor in CI. - LLM discovery
<link>tags -<link rel="llms">,<link rel="alternate" type="text/llms-full+txt">, and a second sitemap link for/llms-sitemap.xmlin root<head>./accessibilityadded to/llms.txtOptional section. - Capability-lease tagline - appended
"builds signed capability leases and agent-egress benches"to the/hero subtitle and rewrote the/agentic-genailede to lead with the signed-capability-lease primitive framing. /og- noindex preview gallery of the 10 canonical OG cards./api/health- initial roster endpoint + nightly inbound-health workflow that opens aninbound-404-labelled issue on any non-2xx/3xx.
Changed
/llms-full.txtheader gained a model-posture blockquote noting Anthropic's 2026-04-23 engineering postmortem and Opus 4.7 Auto Memory's opt-in / default-off status.
[0.1.4] - 2026-04-21
Added - honesty bugs + per-route OG + feed ingest + strict llms.txt
- Per-route dynamic OG images (
/,/about,/agentic-genai,/projects,/experience,/resume,/writing) vianext/og. lib/og-card.tsxsharedImageResponserenderer.scripts/ingest-feeds.ts- Medium + Substack RSS intocontent/external-writing.generated.ts(no runtime deps).scripts/sync-product-metrics.ts- live GitHub API →content/products.generated.ts.scripts/check-links.ts- outbound URL HEAD/GET probe.app/llms-sitemap.xml/route.ts- companion sitemap withlastmodderived fromgit log -1per route./writing"Latest" row pulling 6 most recent items from the ingested feed./aboutphoto + testimonials + Talks & Media sections./resumelast-updated stamp + Talks/CFP sidebar.
Changed
/projectsagent-audit-kit card now driven by live GitHub release data (rule count, version, stars). Removed PyVerseAI from the featured grid./llms.txtrewritten to strict llmstxt.org v1 (H1 + blockquote + Markdown link H2s with real canonical URLs).app/sitemap.tslastModifiednow per-route via git log.
[0.1.3] - 2026-04-20
- Trust-bar reframe: "Trusted by" → "Where I've built".
- Homepage testimonials expanded to 5 LinkedIn recommendations.
- Comprehensive digital-presence audit fixes.