DEV Community

Julien Chable
Julien Chable

Posted on Originally published at julien.chable.net

OKF4net 0.6.0: auditing what your AI agent knows, in zero-dependency .NET

OKF4net 0.6.0 shipped on 1 October. This post covers what it does and what
changed, with commands you can run.

What OKF4net is

The Open Knowledge Format
(OKF) is Google's open format for knowledge an AI agent can read: a directory
of markdown files, each with YAML frontmatter saying what the file is, where it
came from and how far to trust it. No database, no server. You ship it with
git clone.

OKF4net is an independent .NET 10
implementation of OKF v0.2. The core library and the okf CLI use the base
class library only: the YAML-subset parser, the markdown link scanner and the
argument parser are all in the repository. The CLI is published as a Native AOT
binary.

The problem 0.6.0 goes after

Once an agent reads from a knowledge bundle, the question stops being "is this
file valid?" and becomes "should anyone believe it?". A concept may be
well-formed and two years out of date. It may have been written by a model and
never read by a person.

OKF v0.2 has fields for this: who generated a concept, who verified it, when it
goes stale. 0.6.0 adds the tooling to query and maintain them.

okf audit: ask the whole bundle

okf audit bundles/acme_retail --stale --trust unverified,machine-confirmed
Enter fullscreen mode Exit fullscreen mode

This lists the concepts that are past their stale_after date and that no
human has confirmed. With no flags, okf audit gives you the staleness
worklist. It exits 0 and prints nothing when there is nothing to do, so it
drops into a CI job or a pipe.

okf verify: record a review

okf verify bundles/acme_retail metrics/revenue --by human:ada
Enter fullscreen mode Exit fullscreen mode

This writes a dated verification stamp into the concept's frontmatter. It reads
ids from stdin too, so the two verbs compose:

okf audit bundles/acme_retail --trust unverified | cut -d' ' -f1 \
  | okf verify bundles/acme_retail --by human:ada -
Enter fullscreen mode Exit fullscreen mode

One caveat, stated in the README as well: the stamp is a dated declaration. The
tool cannot authenticate the name you pass to --by.

okf-render: a browsable site from a bundle

okf-render bundles/ga4 --out ./ga4-site
Enter fullscreen mode Exit fullscreen mode

The output is static HTML you can open from disk or host anywhere. It is a
separate binary from okf so that the validator people run in CI stays small.

Because the viewer renders untrusted markdown in a browser, it sanitizes the
parsed DOM against an element and attribute allowlist. That sanitizer is tested
by a Node harness that runs the real viewer code against hostile payloads in CI.
We added the harness after finding that two .NET tests "proving" raw HTML was
disabled were green while the sanitizer had a hole: they were reading the .js
file as text, because xunit cannot execute JavaScript.

Attested computation, in a real container

OKF §10 lets a concept declare a computation (a script or SQL) and an attester
script that judges the result. OKF4net.Attestation.Containers runs both in
Docker, Podman or nerdctl:

  • the bundle's own script runs, not a C# port of it;
  • containers run as an unprivileged user, all capabilities dropped;
  • no volume is mounted, every payload travels over stdin;
  • SQL parameters are bound by the database driver, never spliced into the text.

It is in the repository with a worked sample, but not published to NuGet yet,
since it needs a container engine on the machine.

For agent builders: MCP, read-only by default

dotnet tool install -g OKF4net.Mcp
Enter fullscreen mode Exit fullscreen mode

okf-mcp exposes a bundle to any MCP client over stdio. As of 0.6.0 it serves
the bundle read-only; set OKF_MCP_WRITABLE=1 to register the write tools.
There are 13 okf_* tools in total, including the new okf_audit and
okf_verify.

The numbers

0.5.0 (31 Jul) 0.6.0 (1 Oct)
Commits in the release 93 642
Lines of C# in src/ 13,439 24,120
Lines of C# in tests 13,418 30,512
Tests run 912 2,352
Projects under src/ 7 10

The project is ten weeks old and 1,194 commits in. In this release the test
code overtook the product code, which is a fair summary of where the effort
went.

Upgrading from 0.5.0

0.6.0 has breaking changes. The four you are most likely to meet:

  1. Bare attester.resource and computation paths resolve from the bundle root (§6.2). Run okf validate; it tells you what to rewrite.
  2. The frontmatter fence must be --- at column 0, and YAML anchors, aliases and tags are rejected with a named error.
  3. Bundle.ReadResourceText throws for a path outside the bundle root.
  4. okf-mcp no longer writes unless you opt in.

The full list is at the top of the
0.6.0 changelog section.

Get it, or get involved

dotnet add package OKF4net
Enter fullscreen mode Exit fullscreen mode

Binaries for Windows, Linux and macOS are on the
release page, and the
docs are at jchable.github.io/okf4net.

The project is looking for contributors. There are issues labelled
good first issue
and a public roadmap.
If you run Podman or nerdctl, trying the container runtime on it would be a
real contribution: so far it has only been exercised on Docker.

Top comments (0)