Skip to content
View slabbdev's full-sized avatar
🎯
Alone in the Dart
🎯
Alone in the Dart

Block or report slabbdev

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
slabbdev/README.md

🐏 Sam LABBE

I build black boxes for systems nobody can fully trust — right now, that means AI agents.

The exploit lives in the gap between what your AI reads and what it's allowed to do. The cover-up lives in the gap between what it did and what its logs say. I build for the second gap.

🧳 NoireBox — the flight data recorder for AI agents

An agent does something it shouldn't. Three weeks later, someone asks "what exactly did it do?" — and the only witness is a log written by the suspect.

NoireBox fixes that: a hash-chained, Ed25519-signed journal of agent decisions and outputs, anchored by third-party RFC 3161 timestamping, exported as attestations anyone can verify. Tamper with the journal and verification explodes. On purpose.

┌─ ⬛ FLIGHT DATA RECORDER — STATUS ────────────────────
│  journal      hash-chained · Ed25519-signed
│  anchoring    RFC 3161 · third-party TSA
│  exports      signed attestations · MIT
│  interfaces   MCP server · Plugins · API · dashboard
│  pilot        solo, from the Vosges mountains 🇫🇷
└────────────────────────────────────────────────────────

PyPI · Docker · Verify in CI · Docs

The honesty bit

Tamper-evidence is not truth-at-write: NoireBox proves records weren't altered — it can't vouch that a record was accurate when it was sealed. That boundary is written down in the threat model, on purpose. Trust a product that tells you what it can't do.

🛩️ Also in the hangar

  • zerojour — security-advisories agent built for the DEV × Sanity Challenge: head-to-head model duels on structured content, scored eval runs. Every demo frame is a real capture.
  • pluginforge — quality-first factory for e-commerce payment plugins: one spec, one conformance suite, AI-agent generation under strict gates.
  • mineral-starter-kit — batteries-included starter for the Mineral Dart framework.

🧰 Stack & scars

Python · TypeScript · Dart · a long PHP past (Laravel, Symfony — I don't flinch at legacy anymore).

📡 Elsewhere

slabb.dev · X · ☕ buymeacoffee.com/samlabbe


Every claim on this page ships with receipts.

Pinned Loading

  1. noirebox/noirebox noirebox/noirebox Public

    The flight data recorder for AI agents — hash-chained, Ed25519-signed journal with RFC 3161 anchoring and third-party-verifiable exports. One TSA seal covers a whole fleet. MIT

    Python 1 2

  2. zerojour zerojour Public

    A security-advisories agent built for the DEV x Sanity Challenge — head-to-head model duels on structured content, scored eval runs, Sanity CMS integration. Every demo frame is a real capture.

    TypeScript 1

  3. noirebox/noirebox-verify noirebox/noirebox-verify Public

    Verify a NoireBox export journal in CI — fails the job on tampering. MIT

    1

  4. mineral-starter-kit mineral-starter-kit Public

    Starter kit for the Dart Mineral framework — a batteries-included foundation to bootstrap your next application.

    Dart

  5. pluginforge pluginforge Public

    Quality-first factory for e-commerce payment plugins: one spec, one conformance suite, AI-agent generation under strict gates

    PHP 1