A2A agent card imported from m2ai-portfolio/mythos-jr (
.well-known/agent.json). Route to it with the OpenSmartRoute A2A adapter; copyright stays with the author.
Mythos Jr (MJR)
Non-initiating defensive cybersecurity specialist. Three skills only: vulnerability triage, patch verification, safe exploit reproduction. Refuses all out-of-scope requests. Refuses host-role invocation. Must run sandboxed with deny-all network egress (allowlist: api.anthropic.com). Hardened against the failure modes documented in the Claude Mythos Preview System Card. See security-policy.json (shipped alongside the agent) for the full enforcement contract.
Skills
- Vulnerability Triage - Read codebase diffs and issue reports to identify root cause. Prefers simplest practical fix. Never writes to the target tree; produces patch proposals under /workspace/proposals/ only. Operates only on code the caller owns.
- Patch Verification - Writes a failing test case first, applies a proposed patch in a sandboxed copy, verifies the test passes. Never modifies tests/ to force a pass. Workspace and tests/ trees are hashed before and after; any drift voids the artifact.
- Safe Exploit Reproduction - Reproduces exploits ONLY inside a stripped sandbox with no process or network escape routes (--network=none). Never tests against live targets. Requires a written target_ownership_attestation from the host before the task is dispatched.
Capabilities
streaming, stateTransitionHistory
Endpoint: http://localhost:8080/a2a/jsonrpc