参考来源¶
下面收录的是本书当前版本依赖的主要一手来源。最近一次来源编辑审查:2026 年 7 月 24 日。
如何阅读这份列表
最好不仅按主题来读这些来源,也按它们提供的支撑强度来区分:
规范性框架:NIST、OWASP、CISA 等文档,它们定义了相对稳定的治理轮廓;平台实践:OpenAI、Anthropic、LangGraph、Google Cloud、Microsoft 等资料,它们展示这些轮廓在生产环境里是如何被组装出来的;HCI、HITL 与人工监督:这些来源说明自动化会在哪里出错,以及怎样把人稳稳留在回路里;研究前沿:关于记忆、可观测性、验证器设计与多智能体可靠性的较新论文。
如果你要给第一、第五和第八部分建立最稳的基础,先从规范性框架和 HCI/HITL 层开始。如果你要看当前工程实践,就读平台文档和近期研究,但始终要留意发布日期。
规范来源路线(Canonical source routes)
把这些来源(sources)作为三个规范案例(canonical cases)的快速路线(fast route)。支持分流(Support triage) 从 OWASP、OpenAI 智能体指南(OpenAI agent guides)、人在回路来源(HITL sources)、策略/审批材料(policy/approval material)、追踪评分(trace grading)和事件案例(incident cases)开始。内部知识助手(Internal knowledge assistant) 从 LangGraph 记忆(LangGraph memory)、OpenAI Agent 记忆(OpenAI Agent memory)、检索/评测来源(retrieval/eval sources)、面向来源证明的治理(provenance-oriented governance)和记忆研究前沿(memory research frontier)开始。事件协调(Incident coordination) 从 NIST/AI RMF、Google/Microsoft 治理(Google/Microsoft governance)、可观测性来源(observability sources)、多智能体可靠性研究(multi-agent reliability research)、事件复盘(incident review)和发布/控制平面材料(rollout/control-plane material)开始。
规范性框架与治理轮廓¶
Agent-specific security¶
- OWASP, AI Agent Security Cheat Sheet
- OWASP GenAI Security Project, OWASP Top 10 for Agentic Applications for 2026
- OWASP, MCP Security Cheat Sheet
- OWASP, MCP Tool Poisoning
- OWASP, MCP Top 10
- OWASP, Agentic Skills Top 10
- OWASP, LLM Prompt Injection Prevention Cheat Sheet
- OWASP, RAG Security Cheat Sheet
Governance and baseline controls¶
- NIST, AI RMF 1.0
- NIST, AI RMF: Generative AI Profile
- NIST, SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
- NIST, SP 800-218A: Secure Software Development Practices for Generative AI and Dual-Use Foundation Models
- NIST, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations
- CISA, Artificial Intelligence
智能体架构与平台模式¶
- Dmitry Vikulin, Architecture of Reliable AI Agents
- Anthropic, Building Effective AI Agents
- Anthropic, Harness design for long-running application development
- Anthropic, Effective harnesses for long-running agents
- Anthropic, Demystifying evals for AI agents
- Anthropic, Scaling Managed Agents: Decoupling the brain from the hands
- Anthropic, How we contain Claude across products
- Anthropic, How we built our multi-agent research system
- Anthropic, An update on recent Claude Code quality reports
- Snowflake Documentation, Cortex Analyst
- Databricks Documentation, Genie Spaces
- Microsoft Learn, Copilot for Power BI overview
- OpenAI, A practical guide to building agents (PDF)
- OpenAI, Agents SDK
- OpenAI Agents SDK, Sandbox Agents、Sandbox Concepts、Sandbox clients 与 Agent memory
- OpenAI, Agent Builder
- OpenAI, Safety in building agents
- OpenAI, Running Codex safely at OpenAI
- OpenAI, How agents are transforming work
- OpenAI, Codex-maxxing for long-running work
- OpenAI, Building self-improving tax agents with Codex
- OpenAI, From model to agent: Equipping the Responses API with a computer environment
- Model Context Protocol, Security Best Practices
- Model Context Protocol, Authorization specification
- Agent2Agent Protocol, A2A specification
- LangGraph, Overview
- LangGraph, Durable execution
- LangGraph, Persistence
- LangGraph, Memory overview
- LangChain, Multi-agent
- LangChain, The Runtime Behind Production Deep Agents
- LangChain, Choosing the Right Multi-Agent Architecture
- Google Cloud, Achieve agentic productivity with Vertex AI Agent Builder
- Google Cloud, More ways to build, scale, and govern AI agents with Vertex AI Agent Builder
- Google Cloud, 20 questions for the Agentic Enterprise
- Google Cloud, Vertex AI Agent Builder overview
- Google Cloud Architecture Center, Multi-agent AI system in Google Cloud
- Google Cloud, Build agents even faster with Gemini Enterprise Agent Platform’s fully-managed, remote MCP server
- Google, Introducing Agent Executor: a new runtime for AI agents
- Google, google/ax: Agent Executor
- Google Cloud, Beyond Static Prompts: Building Scale-Proof, Polymorphic Multi-Agent Systems with Google's ADK
- Microsoft Azure Architecture Center, AI Agent Orchestration Patterns
- Cloudflare, Build Agents on Cloudflare
- Cloudflare Agents SDK, Store and sync state 与 Schedule tasks
- Cloudflare Agents SDK, Human-in-the-loop patterns 与 WebSockets
- Cloudflare Agents SDK, Using Agents with Workflows、Run Workflows、Durable execution 与 Durable execution with fibers
- Cloudflare Agents SDK, Long-running agents
- Cloudflare, Rules of Durable Objects
- Cloudflare Changelog, Agents SDK improves browser automation, code execution, and recovery
- Cloudflare Changelog, Outbound connections keep Durable Objects alive
- Cloudflare Changelog, Agents SDK adds background sub-agents and a unified turn entry point
- Cloudflare Changelog, Agents SDK improves browser automation, code execution, and recovery
- Cloudflare Blog, Project Think: building the next generation of AI agents on Cloudflare
- Cloudflare Blog, Agents that remember: introducing Agent Memory
- Cloudflare Changelog, Temporary Accounts: From agent deployments to claimed accounts
- Cloudflare Blog, Introducing Dynamic Workflows: durable execution that follows the user, not the other way around
- Cloudflare Blog, How we built saga rollbacks for Cloudflare Workflows
- Cloudflare Blog, Build your own vulnerability harness
- Cloudflare Blog, Bringing more agent harnesses and frameworks to Cloudflare, starting with Flue
- Cloudflare, Build and deploy Remote Model Context Protocol (MCP) servers to Cloudflare
- Cloudflare, Scaling MCP adoption: reference architecture for safer enterprise MCP
- Cloudflare, Connect your AI agents to MCP servers with Cloudflare Access
- Cloudflare, Code Mode: give agents an entire API in 1,000 tokens
- Cloudflare Blog, Your site, your rules: new AI traffic options for all customers
- Cloudflare Blog, Announcing the Monetization Gateway
- GitHub Docs, GitHub Copilot cloud agent
- GitHub Docs, Using Copilot cloud agent on GitHub 与 Configuring settings for GitHub Copilot cloud agent
- GitHub Changelog, Browser tools for GitHub Copilot in VS Code are generally available
- GitHub Changelog, Agent finder for GitHub Copilot now available
- GitHub Changelog, GitHub Copilot in Visual Studio Code, June 2026 releases
- GitHub Blog, Under the hood: Security architecture of GitHub Agentic Workflows
- GitHub Agentic Workflows, Security Architecture
- GitHub Blog, How we built an internal data analytics agent
- GitHub Blog, Evaluating performance and efficiency of the GitHub Copilot agentic harness across models and tasks
- GitHub Changelog, Security validation for third-party coding agents
- GitHub Changelog, Agentic autofix for code scanning alerts in public preview
- GitHub Changelog, Secret scanning with GitHub MCP Server is now generally available
可观测性、评测与验证器设计¶
- OpenAI, Agent evals
- OpenAI, Separating signal from noise in coding evaluations
- OpenAI, Deprecations
- OpenAI, Predicting model behavior before release by simulating deployment
- OpenAI, How we monitor internal coding agents for misalignment
- OpenAI, Trace grading
- OpenAI, Background mode
- OpenAI, Using tools
- OpenAI, Structured model outputs
- OpenAI, Introducing AgentKit
- OpenAI, Secure MCP Tunnel
- OpenAI, Making private MCP servers reachable without making them public
- GitHub Changelog, Schedule and automate tasks with Copilot cloud agent
- GitHub Changelog, Copilot code review: AGENTS.md support and UI improvements
- GitHub Changelog, GitHub Copilot app support for BYOK
- GitHub Blog, Better tools made Copilot code review worse. Here's how we actually improved it
- Cloudflare Changelog, Spend limits are now available for AI Gateway
- Cloudflare Docs, AI Gateway spend limits
- Cloudflare Docs, AI Gateway: Coding Agents
- LangChain, State of Agent Engineering
- Microsoft Learn, Observability for Generative AI and agentic AI systems
- Microsoft Azure AI Foundry Blog, AI Observability Starter Kit for Microsoft Foundry agents
- Microsoft Azure AI Foundry Blog, Monitoring & Observability in Microsoft Foundry, Part 2: Configuration and Operations
- Microsoft Azure Blog, From insight to action: The next phase of agentic cloud operations
- Google Cloud, Observability and monitoring
- Google Cloud, Evaluate your agents
- Google Cloud, Continuous evaluation with online monitors
- Google Cloud Blog, Evaluate agent performance
- AWS, AgentOps: Operationalize agentic AI at scale with Amazon Bedrock AgentCore
- AWS, It’s safe to close your laptop now: Hosting coding agents on Amazon Bedrock AgentCore
- AWS, Debugging production agents with Amazon Bedrock AgentCore Observability
- AWS, Evaluate AI agents systematically with Agent-EvalKit
- AWS, ToolSimulator: scalable tool testing for AI agents
- AWS, MCP tool design: practical approaches and tradeoffs
- AWS Prescriptive Guidance, Design tools for AI agents
- AWS, Secure AI agents with Policy and Lambda interceptors in Amazon Bedrock AgentCore gateway
- AWS, How Smartsheet built a remote MCP server on AWS
- AWS, Introducing stateful MCP client capabilities on Amazon Bedrock AgentCore Runtime
- AWS, Extending MCP support for Amazon Bedrock AgentCore Gateway
- Model Context Protocol, Specification 2026-07-28
- Model Context Protocol Blog, The 2026-07-28 MCP Specification Release Candidate
- AWS Open Source Blog, Governing AI Assets at Scale with MCP Gateway and Registry
- arXiv, The Art of Building Verifiers for Computer Use Agents
- GitHub, microsoft/fara
HCI、HITL 与人工监督¶
- Microsoft Research, Guidelines for Human-AI Interaction
- LangChain Deep Agents, Human-in-the-loop
- LangGraph, Interrupts
- OpenReview, The Illusion of Consensus in Human-Centered Interactive AI
- Microsoft Learn, Agentic AI adoption maturity model
治理、安全与运行保障¶
- Google Cloud, How Google secures AI Agents
- Google Cloud, Recommended AI Controls framework
- Google Cloud, Introducing Agent Sandbox
- Google DeepMind, Securing the future of AI agents
- AWS Security Blog, Secure AI agent access patterns to AWS resources using Model Context Protocol
- Google Research, Security Assurance in the Age of Generative AI
- Google Research, Securing the AI Software Supply Chain
- Google Research, An Introduction to Google’s Approach for Secure AI Agents
- Google Research, Identifying and Mitigating the Security Risks of Generative AI
- Anthropic, Claude Code Security
- Anthropic, Responsible Scaling Policy
- Anthropic, Frontier Safety Roadmap
- Anthropic, Redeploying Fable 5
- Anthropic, Agentic Misalignment
- Anthropic, Strengthening Red Teams
- Anthropic, Introducing Bloom
- Anthropic, Findings from a Pilot Anthropic-OpenAI Alignment Evaluation Exercise
- MLCommons, AILuminate v1.0 Release
- Microsoft Learn, Secure autonomous agentic AI systems
- Microsoft Learn, Reduce autonomous agentic AI risk
- Microsoft Learn, Complete production infrastructure inventory
- Microsoft Learn, Agent Registry convergence with Microsoft Agent 365
- Microsoft Foundry Blog, Build agents you can trust across any framework with open evals and a control standard
- Microsoft Research, Systematic debugging for AI agents: introducing the AgentRx framework
- Microsoft Research, AgentRx: Diagnosing AI Agent Failures from Execution Trajectories
- GitHub, microsoft/AgentRx
事故与案例¶
- American Bar Association, BC Tribunal Confirms Companies Remain Liable for Information Provided by AI Chatbot
- Microsoft Security Blog, When prompts become shells: RCE vulnerabilities in AI agent frameworks
- Microsoft Security Blog, AutoJack: How a single page can RCE the host running your AI agent
- Microsoft Security Blog, Securing AI agents: When AI tools move from reading to acting
- Microsoft Research, Red-teaming a network of agents: Understanding what breaks when AI agents interact at scale
- OpenAI, OpenAI and Hugging Face partner to address security incident during model evaluation
- Hugging Face, Security incident disclosure — July 2026
- arXiv, ExploitGym: Can AI Agents Turn Security Vulnerabilities into Real Attacks?
研究前沿:记忆、可观测性与多智能体可靠性¶
- OpenReview, EVOLVE-MEM: A Self-Adaptive Hierarchical Memory Architecture for Next-Generation Agentic AI Systems
- OpenReview, MemGen: Weaving Generative Latent Memory for Self-Evolving Agents
- OpenReview, AgentTrace: A Structured Logging Framework for Agent System Observability
- OpenReview, AgentTrace: Causal Graph Tracing for Root Cause Analysis in Deployed Multi-Agent Systems
- OpenReview, Evaluation of Multi-Turn Consistency in LLM Agents: Survival Analysis and Failure-Rationale Taxonomy
- OpenReview, AMA-Bench: Evaluating Long-Horizon Memory for Agentic Applications
- OpenReview, Aegis: Automated Error Generation and Attribution for Multi-Agent Systems
- OpenReview, PALADIN: Self-Correcting Language Model Agents to Cure Tool-Failure Cases
- OpenReview, Why Do Multiagent Systems Fail?
- arXiv, Symphony: A Decentralized Multi-Agent Framework for Scalable Collective Intelligence
- arXiv, SYMPHONY: Synergistic Multi-agent Planning with Heterogeneous Language Model Assembly
发布、构建与本书的平台层¶
- MkDocs, Official documentation
- Material for MkDocs, Official documentation
- uv, Working on projects
- ty, Official documentation
- Starlight, Official documentation
Rust 与智能体运行时的基础设施层¶
- AWS, AWS SDK for Rust is generally available
- AWS Docs, Code examples for Amazon Bedrock Runtime using AWS SDK for Rust
- docs.rs, aws-sdk-bedrockagentruntime
- Microsoft Learn, Azure SDK for Rust
- Rig, Official documentation
- docs.rs, rig-core
- GitHub, 0xPlaygrounds/rig
如何使用这份列表¶
如果你要继续扩展这本书,比较顺手的顺序是:
- 风险与控制框架:NIST、OWASP、CISA。
- 架构模式与运行时纪律:Anthropic、OpenAI、LangGraph、Google Cloud、Microsoft。
- 可观测性、评测与验证器层:OpenAI、Microsoft、arXiv、GitHub。
- HCI、HITL 与案例:Microsoft Research、OpenReview、ABA。
- 研究前沿:记忆、一致性、可观测性与多智能体失败模式。
如果你是配合本书阅读,再记住一个区分就够了:
稳定内核:规范性框架、架构、策略、执行与可观测性;快速变化层:评测工具、验证器设计、清单治理、前沿研究和较新的案例。