Agentic Security Attack and Containment Lab
Prove that untrusted repository content and tool output cannot widen authority, expose secrets, poison durable memory, or corrupt evidence.
A focused view of boundaries, contracts, state, authority, failure paths, and tradeoffs drawn from this chapter.
Prove that untrusted repository content and tool output cannot widen authority, expose secrets, poison durable memory, or corrupt evidence.
Execute the existing Markdown instructions and retain the required output and evidence.
Jump to validation criteriaSafety boundary
Use synthetic data, disposable environments, mock external systems, and fake credentials. Do not target a live service or use real confidential information.
Required failure and recovery
Temporarily remove one output-validation control in the disposable setup and demonstrate detection of the resulting unsafe proposal before any external effect. Restore the control, create a new Attempt, and preserve both histories.
Curriculum maturity is not implementation proof.
This chapter defines architecture or practice. It does not by itself prove a corresponding production implementation.
Review this chapter.
Challenge a claim, boundary, missing failure mode, unclear term, or unsupported evidence statement.
- Claim
- Boundary
- Failure
- Evidence