Skip to content

Declare adversarial-control apparatus and backend capabilities #1004

Description

@Brad-Edwards

Parent: #812

Bounded outcome

Extend existing participant implementation, experiment apparatus, and API-407 capability surfaces to declare bounded quarantine, trusted/untrusted processing roles, label/derivation support, final-sink mediation, monitor topology, and fail-closed downgrade behavior. Keep apparatus-specific prompt separation, model roles, MCP gateways, and tool scopes outside portable participant semantics.

Negative cases

  • Backend or apparatus declarations treated as proof of realization.
  • A prompt sanitizer, gateway, model wrapper, or heuristic monitor declared as the sole enforcement point.
  • Different model/process ids treated as independence or non-collusion evidence.
  • Secrets, prompts, credentials, policies, or hidden objectives embedded in public manifests, argv, environment, logs, or evidence.
  • Unsupported label propagation or quarantine silently downgraded to supported.

Evidence required

  • Closed capability/manifests and declared-versus-effective support resolution.
  • Honest, unsupported, weakened, overclaiming, and colluding/correlated fixtures.
  • Backend realization and bounded conformance probes tied to the exact SEM-233 profile.
  • Apparatus capability and least-authority/tool-scope evidence.
  • Safe provenance and limitation records.

Explicit nonclaims

  • No automatic trust in a model, human, monitor, gateway, or backend.
  • No runtime realization without implementation and conformance evidence.
  • No portable prompt, chain-of-thought, private-state, credential, or LLM-message semantics.

Dependencies

Requirements

  • SEM-233
  • ASR-536
  • API-407
  • ACT-617

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:runtimeRuntime and control-plane codeenhancementNew feature or requestin-progressAn agent is actively working this issue via /implementsecuritySecurity vulnerabilities and hardening issues

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions