Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Documents & Metadata · Parser-boundary ambiguity

    Document Container Map

    The inspector maps structure and reports limits without rendering, executing, following relationships, or retaining the upload.

    Quick answer

    What does the Container Map show?

    The inspector maps structure and reports limits without rendering, executing, following relationships, or retaining the upload.

    Human visibility
    Container and metadata layers
    Machine receiver
    Bounded structural inspector
    Robustness
    Format-specific

    Research boundary: this page uses bounded, inert data and fixed safe examples. It never executes decoded content, requests secrets, calls third-party services, or performs actions against external systems.

    FIRST RUN / THREE STEPS

    Start with the prepared, bounded workflow.

    Nothing runs automatically
    1. Choose one supported file

      The file stays in PHP’s temporary upload for this request and is not retained by the application.

    2. Run Inspect container

      Inspect the selected file as inert bytes and containers. No embedded content is executed.

    3. Scan before expanding

      Read the summary and findings first, then inspect extracted metadata, views, and table rows.

    INPUT / CONTROL PLANE

    Prepare the input and choose one action.

    Laboratory status: Ready

    The recommended first run is separated from alternate analyses. Inputs and selected files stay on this host.

    Current input state No file selected yet

    Choose one supported local file, then run the recommended inspection. Browsers do not repopulate file selections after a reload.

    Maximum 4 MiB. Uploaded bytes are inspected from PHP temporary storage and are not retained.

    Maximum file size: 4 MiB. Accepted file types: PDF, DOCX, XLSX, PPTX, PNG, JPG, JPEG.

    ACTION HIERARCHY

    Run the recommended first pass.

    Alternate actions remain available below, but the first pass is the clearest place to start.

    Inputs remain on this host. Text operations are size-limited; uploaded files are processed from PHP’s temporary upload and are not retained by the application.

    OUTPUT / MACHINE VIEWS

    Scan the result from summary to evidence.

    Run Inspect container to create the first result.

    Choose a supported file first. The output will lead with a summary and visible qualifications before the expandable machine views.

    SummaryFindingsMachine views
    Interpretation framework

    The same artifact can produce several valid observations.

    01

    Human view

    What a person naturally reads, sees, or hears.

    02

    Structural view

    What a parser, DOM, container reader, or metadata extractor exposes.

    03

    Decoder view

    What becomes meaningful only with a rule, key, tokenizer, model, or tool.

    04

    Defensive view

    What normalization, rendering, OCR, canonicalization, or policy changes.

    Evidence and decision boundary

    Use the result as bounded evidence, not as a universal verdict.

    The inspector maps structure and reports limits without rendering, executing, following relationships, or retaining the upload.

    LOCAL MODEInert bounded container inspection
    REVIEW DATE2026-08-26
    SOURCE BODYPreserved separately from implementation claims
    Computed locally

    Deterministic output produced by this bounded runtime.

    • Outer byte count, MIME evidence, SHA-256, and allowlisted format signature
    • Bounded PDF, OOXML ZIP, PNG, or JPEG structural indicators already supported by the shared file inspector
    • Selected active-content, metadata, relationship, chunk, marker, and ambiguity findings without execution
    Bounded approximation

    Useful subset or model that does not establish full conformance.

    • The inspector is not a complete ISO 32000-2, ECMA-376, PNG, JPEG, EXIF, or XMP validator
    • Structural indicators do not predict how every viewer, office suite, or parser will recover malformed content
    • Metadata presence and parser warnings do not establish malicious intent
    Escalate for

    Claims that require an exact parser, trust system, model, or human review.

    • Digital-signature validity, certificate status, and trust require dedicated cryptographic verification
    • Rendered appearance and semantic deception require isolated rendering and human review
    • Malware, macros, fonts, embedded objects, and polyglots require specialist sandbox and forensic tooling
    Interpretation rule

    Record the receiver and transformation.

    Machine-decodable is receiver-relative. Record the parser, preprocessing, codebook, tokenizer, key, model, and transformation path before generalizing from one result.

    Limitations

    What this page does not prove

    Structural inspection does not establish semantic safety and does not replace isolated rendering, malware analysis, cryptographic signature validation, or application-specific policy.

    Deterministic review material

    Download the exact benign fixtures used for the evidence boundary.

    These local files are supplied for repeatable inspection. The application does not fetch them automatically, execute their content, or treat a fixture result as external verification.

    Benign PDF metadata file

    Benign PDF metadata fixture for structural container mapping.

    Type
    PDF fixture
    Bytes
    1,822
    SHA-256
    5fe4fa83387d1a9639b4…
    Download fixture
    Benign OOXML properties file

    Benign OOXML properties fixture for ZIP/package relationship mapping.

    Type
    DOCX fixture
    Bytes
    36,812
    SHA-256
    796a7f45026704a87aed…
    Download fixture