Standards Watchlist

August 11, 2026 ยท View on GitHub

The maintainer reviews this list each quarter. Review it sooner when a tracked body publishes a new version.

  • Last full agent-standards review: 2026-08-06.
  • Engineering-practice sources reviewed: 2026-08-11.
  • Next planned review: 2026-11-06.

Watchlist

WorkStatus at reviewWorkcell effectNext check
Model Context Protocol 2026-07-28Current dated specificationMCP transport, authorization, and extension changes can affect injected configuration and runtime controls.Check adapter support for the stateless protocol and authorization changes.
OWASP Top 10 for Agentic Applications 2026Published 2026 editionWorkcell maps its controls to ASI01 through ASI10.Check for a new edition. If OWASP publishes one, update the mapping.
IETF WIMSE documentsActive working-group and individual draftsWorkload identity can affect future agent authentication and delegation.Check architecture, credential, proof-token, and AI-agent drafts.
NIST SSDF 1.1Final, published February 2022The engineering baseline maps secure development across the lifecycle.Check for a final revision or supplement.
NIST SP 800-160 Rev. 1Final, published November 2022Trust objectives inform architecture, requirements, verification, and operations.Check for a final revision.
ISO/IEC 25010:2023Published second editionRelevant product-quality characteristics inform requirements, tests, acceptance, and measures.Check its systematic-review status.
SLSA v1.2Approved specificationBuild and Source tracks affect provenance claims and source-control assessment.Reassess exact Workcell track and level claims after a new approved version.
GitHub Actions secure useCurrent official guidanceToken permissions, untrusted checkout, action identity, and secret handling affect workflow controls.Check after a material Actions security change.
DORA metricsCurrent five-measure guidance, updated January 2026Repository trends can guide delivery improvement after Workcell defines deployments and recovery.Check definitions before changing a delivery measure.
Google Engineering PracticesCurrent official guidanceSmall changes, technical evidence, and code-health improvement inform review practice.Check for material review-policy changes.
Go guidance and Rust API GuidelinesCurrent official project guidanceLanguage conventions inform APIs, documentation, and tests.Check after a supported language or toolchain change.
OpenSSF Best Practices BadgeCurrent voluntary self-certification programThe checklist can support open-source hygiene. It does not prove Workcell isolation.Check criteria before starting the deferred badge assessment.

Notes

The MCP 2026-07-28 version changes the core protocol to stateless requests. It also adds new authorization and extension rules.

The OWASP item is the source for the agentic application mapping. Update both documents together when OWASP publishes a new edition.

WIMSE work is not a Workcell implementation commitment. The AI-agent identity documents remain Internet-Drafts. Do not describe them as an IETF standard or an approved agent identity protocol.