Preserve first
Verify fixture bytes and digest before normalization, decoding, sanitization, rendering, or reconstruction.
Choose safe governed fixtures, identify the representation planes that matter, route unresolved questions into existing focused laboratories, then separate facts, interpretations, hypotheses, verification needs, and constraints in a deterministic specialist handoff.
They create a bounded investigation plan and a deterministic specialist handoff that keeps observed facts, derived observations, hypotheses, required verification, and decision constraints separate. They do not parse fixtures themselves, persist notes, infer malicious intent, assign a universal score, or claim production assurance.
Select up to 6 governed cases. The server validates every case, layer, and objective against allowlisted registries. Nothing runs until you submit, and the plan is not retained after the response.
This matrix is descriptive, not evaluative. “Present” means the fixture contract directly contains or exercises the layer. “Conditional” means the layer requires another parser, renderer, model, trust system, or human context.
| Governed case | Bytes | Unicode | Structure | Visual | Semantic | Metadata | Extracted | Model | Behavior | Transform | Trust | Handoff | Focused lab |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Unicode canonicalization and display differential01-unicode-representation.txt | Present: Source bytes | Present: Unicode and text structure | Not declared: Container and syntax structure | Present: Rendered or visual representation | Not declared: Semantic and accessibility representation | Not declared: Metadata and provenance claims | Present: Decoded and extracted content | Present: Tokenizer and model-facing representation | Not declared: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| HTML source, DOM, visibility, and semantic differential02-web-representation.html | Present: Source bytes | Present: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Present: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Conditional: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| PDF metadata and object-container map03-pdf-metadata-demo.pdf | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Not declared: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| OOXML ZIP, properties, and relationship map04-docx-properties-demo.docx | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Not declared: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| Tokenizer and normalization boundary comparison05-tokenization-boundaries.txt | Present: Source bytes | Present: Unicode and text structure | Not declared: Container and syntax structure | Not declared: Rendered or visual representation | Not declared: Semantic and accessibility representation | Not declared: Metadata and provenance claims | Present: Decoded and extracted content | Present: Tokenizer and model-facing representation | Not declared: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| Fixed-marker linguistic steganalysis06-linguistic-fixed-marker.txt | Present: Source bytes | Present: Unicode and text structure | Not declared: Container and syntax structure | Not declared: Rendered or visual representation | Not declared: Semantic and accessibility representation | Not declared: Metadata and provenance claims | Present: Decoded and extracted content | Present: Tokenizer and model-facing representation | Not declared: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| Provenance-negative image control07-provenance-negative.png | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Not declared: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| Agent policy and capability-boundary scenario08-agent-policy-scenario.json | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Not declared: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Present: Tokenizer and model-facing representation | Present: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| Image metadata, transparency, and multimodal differential09-multimodal-metadata.png | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Present: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Conditional: Tokenizer and model-facing representation | Not declared: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| MIME multipart and body-alternative comparison10-message-alternative.eml | Present: Source bytes | Present: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Present: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| iCalendar request and scheduling-action map11-calendar-request.ics | Present: Source bytes | Present: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Present: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| Browser DOM, accessibility, geometry, and agent-view set12-browser-agent-fixtures.json | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Present: Rendered or visual representation | Present: Semantic and accessibility representation | Not declared: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Present: Behavior and capability boundary | Present: Transformation survival | Conditional: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| CycloneDX dependency and provenance-claim map13-cyclonedx-dangling-reference.json | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Not declared: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Present: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Present: Behavior and capability boundary | Present: Transformation survival | Present: Trust and external verification | Present: Operational evidence and handoff | Open lab |
| Defense maturity evidence-planning scenario14-defense-planning-example.json | Present: Source bytes | Not declared: Unicode and text structure | Present: Container and syntax structure | Not declared: Rendered or visual representation | Not declared: Semantic and accessibility representation | Present: Metadata and provenance claims | Not declared: Decoded and extracted content | Not declared: Tokenizer and model-facing representation | Present: Behavior and capability boundary | Conditional: Transformation survival | Present: Trust and external verification | Present: Operational evidence and handoff | Open lab |
The initial page does not create or run a plan.
Select one or more governed fixtures above, keep the relevant evidence planes, and submit the form.
Keep direct facts, bounded interpretations, possible explanations, exact verification needs, and decision constraints in separate fields. The worksheet is a reproducible method record—not an incident verdict, expert opinion, malicious-intent finding, or certification.
The worksheet inherits the selected fixture identities, representation planes, existing laboratory routes, allowlisted actions, and Plan ID from the server-generated plan above.
Structural findings and categorized notes can show that representations differ, that a field exists, or that a deterministic control changes a prepared scenario. They do not independently prove attacker intent, real-world truth, cryptographic validity, standards conformance, exact production-parser behavior, or model susceptibility.
Verify fixture bytes and digest before normalization, decoding, sanitization, rendering, or reconstruction.
Keep byte, structural, visual, semantic, metadata, extracted, model-facing, and behavioral outputs as separate evidence planes.
Route browser, cryptographic, OCR, DNS, trust-list, registry, model, or organizational questions to the exact external verifier required.