RWA · private credit
RWA Readiness Clinic
- Need
- Validate loan structure, SPV lifecycle, custody, and regulatory dependencies before tokenization.
- On platform
- File v3 evidence slots, run nine clinical gates, get GO / CONDITIONAL / NO_GO with blockers.
Agent execution control
Authority at the tool call. Then evidence. Deny the wrong call before it runs — not a threat-intel dashboard.
Not SOC 2 certified. No pen-test letter. No named customers. SARIF is the artifact you can take to GitHub Advanced Security.
RWA Readiness Clinic Validate private-credit structures before tokenization.Buyer clinic
Same thesis on every lane: before a consequential tool runs, the call must be bounded, confirmable, stoppable, and provable. Pick your field; each card names what you actually need, what breaks today, and where to start on Shield. Full specialized clinic — eight lanes with symptoms, anti-patterns, and 10-step paths.
RWA · private credit
MCP · IDE agent platform
resources/read on .env until after exfiltration..env read.npx @noetfield/shield-cursor init --yes then shield-cursor prove.POST /v1/adapter/mcp/proxy or IDE “Verify Shield” on the MCP page.GET /v1/shield/policy-packsAgent supply chain · AppSec
npm audit and SCA miss prose instructions (“ignore prior rules”, hidden shell steps) and MCP server JSON that never hits a package registry.mcp.json → Analyze artifact.GET /v1/boundary-eval/policies → run trace JSON.POST /v1/agent-security/scorecard for unified gate verdict.exports.sarif.GET /v1/reports/{id}/brief.mdCISO · GRC · vendor risk
GET /v1/reports/{id}/sarif and /brief.md from shared report.share:true → GHA SARIF upload.Platform ops · SRE · release
hooks/release that ties surface scan to agent policy without bolting three vendors together.POST /v1/hooks/deploy with url + consent:true.POST /v1/hooks/release — use hook tester first.gate is fail; store report_id on ticket.Threat intel · IR
GET /v1/threat-feed.POST /v1/ioc-hunt.POST /v1/control-plane.Identity · IAM · control plane
POST /v1/agent-control/agents register agent metadata.GET /v1/shield/policy-packs · GET /v1/agent-control/packs.POST /v1/agent-control/simulate/{scenario} hostile regression.Engineering management · Team lead
GET /v1/shield/team-summary.npm run dogfood:sweep for coverage by repo.npx @noetfield/shield-cursor init --yes + prove.Regulated · banking · healthcare · fintech
.env read before exam season.environment=production on control plane.Operations playbook
Complete vendor questionnaires and internal readiness from live surfaces — not PDFs to request later. Full operations kit — every form field, API body, and error fix. ABCP money controls and diligence ZIP live on banking.noetfield.com.
| Kit / form | Where | Requirements to complete | Output |
|---|---|---|---|
| URL surface scan | URL Scan tab · POST /v1/scan | App URL · consent · optional share:true | Report id · SARIF when shared |
| Agent artifact scan | Agent Guard · POST /v1/agent-scan | Artifact type · paste content | Findings + CWE tags |
| Boundary eval | Agent Guard → Boundary · POST /v1/boundary-eval | Policy or authority JSON · trace events | ALLOW/DENY/STEP_UP + receipt |
| Org assessment | /org-assessment/ · POST /v1/org-assessment | URL · consent · optional artifact | Unified gate · SARIF · brief |
| MCP / Cursor | MCP page | Agent id · pack · bridge install · verify | Runtime DENY + receipt |
| Deploy / release hooks | Hook tester | Live URL · consent:true · optional boundary policy | pass / warn / fail |
| SARIF → GHAS | SARIF guide | Share scan · download SARIF · upload action | GitHub code scanning alert |
| OpenAPI | /v1/openapi.json | None — full API catalog | Vendor API diligence |
| Money readiness gate | banking.noetfield.com/gate | Six radio questions (honest answers) | Signed GO / CONDITIONAL / NO-GO |
| Policy demo walk | control.noetfield.com/sandbox | Six in-page demo steps | Receipts sandbox:true |
| Vendor diligence ZIP | vendor/pack.zip | Download · map to questionnaire | CSV · OpenAPI · schemas |
| Vendor request lanes | /request | Pick lane · email opens with required fields | Walk · NDA · pilot SOW path |
| Full buyer clinic | /buyer-clinic/ | Pick lane · follow 10-step path per role | Symptoms · anti-patterns · module map |
URL scan runs in the hero above. Jump to scan form · POST /v1/scan
Static artifact analysis plus trace-driven boundary evaluation. Artifact scan matches IOCs and trojanized patterns. Boundary eval runs six deterministic suites on normalized traces from sandboxed adapters. Policy decision point returns ALLOW, DENY, or STEP_UP per action.
Inventory, policy decision point, hostile simulations, receipt verification, and CI gate. Adapters submit normalized events; core never executes untrusted agents.
Loading control plane stats…
Evaluator does not execute untrusted agents. Adapters submit traces from Docker/VM sandboxes.
Curated 2026 attack stories from public reporting: agent supply chain, identity wipes, OT breaches, ransomware TTPs.
Paste logs, egress records, configs, or shell history. Match against our curated IOC database from active 2026 campaigns.
Includes getpaperclipp.com endpoints, typosquatted skills, and malicious PyPI packages from Zenity disclosure.
Answer the checklist based on the Stryker Intune wipe and agent governance incidents. Optionally paste Entra, Intune, or MCP config for pattern analysis.
CI integration
POST your live URL after deploy. Returns pass, warn, or fail plus a shareable report.
curl -sS -X POST "https://scan.noetfield.com/v1/hooks/deploy" \
-H "content-type: application/json" \
-d '{"url":"https://your-app.com","consent":true}'
curl -sS -X POST "https://scan.noetfield.com/v1/hooks/release" \
-H "content-type: application/json" \
-d '{"url":"https://your-app.com","consent":true,"policy_id":"skills-marketplace-untrusted-v1","subject":"release-gate","events":[{"type":"tool_call","name":"shell"}],"policy":{"fail_on":["critical","high"]}}'
For security & GRC teams
Reports can tag findings with OWASP, CWE, and CIS references. That is mapping on a report, not a SOC 2 certification. Export SARIF into GitHub Advanced Security. Pull an executive brief. Track drift between deploys.
POST /v1/agent-control/decide — ALLOW / DENY / STEP_UP per action. POST /v1/agent-control/simulate/* for hostile regression.
GET /v1/boundary-eval/policies — Cursor, MCP, CI, skills marketplace, support bot.
POST /v1/agent-security/scorecard — static + boundary in one denied/conditional/approved gate.
POST /v1/boundary-eval/verify — audit SHA-256 receipts for tamper evidence.
GET /v1/reports/{id}/cef — Splunk, Sentinel, Chronicle compatible CEF.
POST /v1/hooks/release — URL scan + optional boundary eval with webhook and export URLs.
POST /v1/org-assessment now includes boundary traces in unified posture.
curl -sS -X POST "https://scan.noetfield.com/v1/hooks/boundary" \
-H "content-type: application/json" \
-d '{"policy_id":"skills-marketplace-untrusted-v1","subject":"skill-pr","events":[{"type":"tool_call","name":"shell"}]}'
Platform API
Every module is available over HTTP. Agents call MCP at /api/mcp. CI hooks use deploy gate at /v1/hooks/deploy.
POST /v1/scanLive URL surface scan
POST /v1/agent-scanAgent artifact static analysis
POST /v1/agent-control/decidePolicy decision point (ALLOW/DENY/STEP_UP)
POST /v1/agent-control/simulate/{scenario}Hostile trace regression
GET /v1/agent-control/packsEvaluation packs (enterprise-baseline, mcp-core)
POST /v1/boundary-evalTrace boundary eval + SHA-256 receipt
GET /v1/boundary-eval/policiesEnterprise authority policy packs
POST /v1/agent-security/scorecardUnified agent approval gate
POST /v1/hooks/boundaryCI boundary gate
GET /v1/threat-feedCurated threat stories
POST /v1/ioc-huntIOC matching
POST /v1/control-planePosture assessment
POST /v1/org-assessmentUnified org posture brief
GET /v1/reports/{id}/sarifSARIF for GHAS / DevSecOps
GET /v1/reports/{id}/brief.mdExecutive markdown brief
POST /api/mcpMCP JSON-RPC tools
GET /v1/platformPlatform metadata
GET /v1/openapi.jsonOpenAPI 3.1 catalog
POST /v1/hooks/deployCI deploy gate
curl -sS https://scan.noetfield.com/v1/platform | jq .
curl -sS -X POST https://scan.noetfield.com/v1/agent-scan \
-H "content-type: application/json" \
-d '{"content":"…skill text…","artifact_type":"skill"}'
FAQ
GET /v1/reports/{id}/sarif in SARIF 2.1.0 with CWE and severity on every finding.Indexed guides
Every guide is public, linked in our sitemap, and registered with IndexNow for Bing and Yandex. Start with the DENY demo or Agent Guard.