Quarantined reader
Preserves source bytes and derives bounded structural, visual, semantic, metadata, token, or behavioral views without credentials or write authority.
Run one governed fictional scenario through explicit evidence preservation, representation comparison, capability containment, authorization, recovery, and lessons learned—without storing the record or touching a live system.
It turns eight governed fictional representation-layer scenarios into request-local exercises with explicit roles, staged injects, evidence requirements, trust boundaries, categorized decisions, missing-authority checks, recovery prompts, and deterministic runbook exports. It does not score readiness, declare pass or failure, store incident data, or authorize a production action.
The tabletop starts with an untrusted fictional artifact, preserves its identity, compares independent representations, and prevents unresolved evidence from reaching a privileged action. The generated runbook records method and authority gaps; it never becomes an execution token.
Preserves source bytes and derives bounded structural, visual, semantic, metadata, token, or behavioral views without credentials or write authority.
Records representation agreement, conflict, conditional comparability, and the exact parser, browser, model, registry, or owner still required.
Remains separate. State-changing, financial, externally visible, or production actions require an explicit accountable human and normal operational controls.
Exercise rule: preserving and comparing evidence can inform a decision, but the simulator cannot authorize containment, publication, financial action, disclosure, recovery, or production change.
The scenario titles, vectors, and defensive objectives are derived from the governed defense-operations report. The implementation adds bounded injects and runbook structure without altering that source body.
A fictional applicant resume contains a parser differential that presents benign visible content while a separate machine-readable layer attempts to influence an HR ranking workflow.
A fictional resume is accepted by the upload boundary. The file extension and media type appear ordinary, but the exact bytes and parser version have not yet been preserved.
The inert object map reports an additional text-bearing object that is absent from the approved rendered page but appears in one text-extraction path.
The HR workflow proposes using the extracted text in a candidate-ranking summary before the representation conflict is resolved.
A flattened, inert derivative and a separately preserved original are available for replay through the corrected pipeline.
A fictional financial document mixes visually confusable Latin and Cyrillic characters to evade an identifier or compliance comparison before reaching an automated trading workflow.
A fictional financial name appears ordinary in the visible document, while code-point inspection reports mixed Latin and Cyrillic scripts.
NFC leaves the mixed-script identifier unchanged. An educational confusable skeleton collides with a protected Latin identifier.
A downstream workflow proposes an externally visible financial action based on the unresolved identifier.
The fictional system can replay the document using a versioned identifier profile and a blocked-by-default action boundary.
A fictional internal wiki page is indexed into a retrieval store and causes an IT assistant to propose unapproved executable links.
A fictional wiki revision with unclear ownership ranks above an approved support article for a common IT query.
The retrieved chunk contains content that conflicts with the user objective and proposes an external executable link.
The IT assistant proposes sharing the link across an employee channel, but no human confirmation or egress allowlist has been applied.
The poisoned revision is removed from active retrieval, the approved source is reindexed, and the fixed scenario is replayed.
A fictional competitor page exposes hidden accessibility text that is absent from the painted view but appears in an agent-facing semantic representation.
The fictional browser snapshot contains text in the accessibility tree that is not visible in the approved screenshot.
A role/name locator and text extraction include the hidden content, while visual hit testing reports no visible target.
The scraping agent proposes a market-research statement derived from the conflicting content.
The workflow now records semantic, visual, and geometry views separately and marks conflicts for human review.
Fictional source code contains bidirectional controls that cause visual order to diverge from logical compiler order during automated review.
A fictional source diff contains explicit bidirectional override characters inside a comment or string region.
The visual editor order differs from logical token order, while a compiler diagnostic is not yet available in the review record.
An automated review suggests approval despite the unresolved bidi control warning.
The controls are escaped or removed in a separately reviewed revision, and compiler warnings are enabled by default.
A fictional orchestration dependency changes prompt construction so sensitive values are appended to outbound URL parameters.
A fictional package digest does not match the previously reviewed lock file, while the package name and version string appear unchanged.
A deterministic diff shows that the dependency modified prompt or URL-construction behavior.
The fictional runtime proposes an external URL containing sensitive placeholder values in query parameters.
A known-good artifact and verified build record are available for redeployment in the fictional environment.
A fictional adversarial suffix produces unexpected token boundaries and a policy-violating model output under one specific model and tokenizer configuration.
A fictional evaluation returns a policy-violating output for a bounded test input under one declared model/tokenizer pair.
Educational token inspection shows materially different boundaries after a declared normalization or invisible-character transformation.
A downstream system proposes rendering or acting on the output despite the failed evaluation.
A new regression fixture and explicit tokenizer/model identity are added to the fictional test suite.
A fictional receipt contains micro-text or another low-salience visual layer that an OCR path extracts as an instruction to approve a maximum expense.
A fictional receipt image is accepted. The raw file, dimensions, metadata, and exact transformation path are not yet fully recorded.
Prepared OCR reports a low-salience instruction-like phrase not present in the approved human description.
The expense agent proposes an approval action based on OCR text rather than an authorized policy field.
A re-encoded derivative, separated OCR channel, and corrected approval policy are ready for replay.
The laboratory accepts two to eight role IDs. Each scenario declares a minimum role set, and the generated record lists every required role that was not represented.
| Role ID | Visible label | Exercise responsibility |
|---|---|---|
executive-owner | Executive owner | Owns risk tolerance, consequential-action policy, and resource decisions. |
engineering | Engineering and architecture | Owns parser isolation, representation comparison, control implementation, and technical recovery. |
security-operations | Security operations | Owns triage, evidence preservation, containment coordination, and detection follow-up. |
ai-model-operations | AI and model operations | Owns model, retrieval, tokenizer, prompt-construction, and evaluation boundaries. |
content-data-owner | Content and data owner | Owns source authority, data lineage, publication, and retrieval-store stewardship. |
privacy-legal | Privacy or legal | Owns privacy, disclosure, contractual, regulatory, and retention constraints. |
incident-commander | Incident commander | Owns exercise coordination, decision logging, escalation, and recovery sequencing. |
independent-observer | Independent observer | Records gaps, contradictions, missing evidence, and lessons without directing the exercise. |
Every exercise uses the same four stages. JavaScript progressively hides unrevealed decision fields; no-JavaScript visitors can still submit the complete native form.
Recognize the fictional anomaly, preserve source identity, and establish initial ownership.
Compare independent evidence planes and identify the exact unresolved representation gap.
Limit capabilities, require authority, and prevent an unverified representation from driving action.
Restore a known-good boundary, verify controls, and record lessons and unanswered questions.
preserveProtect raw and transformed evidence before changing the system.
inspectUse an inert, bounded representation-specific analysis path.
containLimit reachable capabilities or isolate the affected boundary.
verifyName the external authority required to establish a claim.
authorizeRequire explicit authority before a consequential action.
recoverRestore a known-good state and validate the repaired boundary.
deferRecord why the decision cannot yet be made and what evidence is missing.
Identical inputs under the same release produce the same JSON and Markdown bytes, Tabletop ID, and full SHA-256. The record contains no timestamp, request address, random value, hidden history, or readiness score.
Site release, governed report path and SHA-256, scenario source row, participating roles, missing roles, and fictional-state declaration.
Staged injects, required evidence, dependencies, decision category, bounded decision note, and exact external-verification classes.
Ordered runbook steps, containment and recovery notes, unanswered questions, lessons prompts, and explicit non-conclusions.
No account, cookie, analytics, database, browser storage, upload, mail, model, registry, DNS, trust-service, tool, or production action.
research/reports/machine-tradecraft-defense-maturity.md
SHA-256 77ede5cba60a8121d3054a50969c1ab6950b046deb484f759b24d20790136d5e