Preserve the report
The manifest binds every report filename and SHA-256. Corrections, conflicts, and version updates do not overwrite the governed body.
The governed Markdown reports remain exact source evidence. This derived, checksum-governed layer records selected claim support, standards currency, conflicts, replacements, implementation impact, and required follow-up without silently rewriting a report or assigning a source-quality score.
It keeps exact governed report bodies separate from a checksum-governed review plane that records significant claims, current source and standards status, direct or partial support, conflicts, non-establishment, implementation impact, and required follow-up without assigning source-quality scores or making runtime network requests.
Every claim record points to a stable report heading and one or more reviewed sources. Current conclusions live here; the original report remains unchanged.
The manifest binds every report filename and SHA-256. Corrections, conflicts, and version updates do not overwrite the governed body.
A review records direct support, partial support, conflict or qualification, or that a source does not establish the claim.
Standards and publications are labelled current, living, final, draft, preprint, stable, historical, superseded, or mixed.
Implementation impact and exact follow-up identify when browser, parser, model, cryptographic, registry, DNS, legal, or organizational verification remains necessary.
Release-time research, offline runtime. Source metadata was reviewed during release work. The public site reads only the local manifest and makes no source, registry, trust-service, DNS, model, or browser request.
Filters use a normal GET form and remain useful without JavaScript. Filter combinations are noindex while the canonical unfiltered map remains indexable.
Preserve escaped logical views and render-aware warnings rather than relying on the painted string alone.
Recheck Unicode property data and revision numbers when the Unicode baseline changes.
Record the exact tokenizer and preprocessing version alongside model-facing evidence.
Verify behavior with the deployed tokenizer rather than extrapolating from an educational implementation.
Use UTS #39 profiles and collision review for identifiers while retaining legitimate international text.
Document application-specific allowed scripts and font assumptions.
Inventory each channel independently and avoid treating metadata extraction as visual recognition.
Use an exact OCR or vision configuration when conclusions depend on recognized pixels.
Separate structural metadata inventory from rendering, sanitization, and trust verification.
Validate against the exact parser and document-format edition used by the target system.
Treat decoding capability as an empirical model/version result rather than a universal property of an encoding.
Evaluate the exact model, tokenizer, prompt template, and decoding task.
Treat retrieved content as untrusted and place capability controls outside the model.
Measure the exact application, model, retrieval, and tool configuration; do not generalize benchmark rates.
Present indicators as evidence rather than proof and test transformations explicitly.
Use a bounded allowlisted marker and matched benign controls.
Disclose the detector key, generation assumptions, text length, and false-positive policy.
Re-evaluate after paraphrase, translation, and retokenization transformations.
Keep the public lab limited to fixed harmless markers and explanatory diagnostics.
Do not infer an arbitrary covert payload from lexical variation alone.
Label implementation examples as bounded educational models rather than general covert-channel capability.
Prefer final proceedings versions and preserve exact experimental conditions.
Avoid absolute undetectability claims and show the observer and distribution used.
Test under distribution shift and independent steganalysis.
Report per-transformation survival states rather than a single robustness score.
Use exact pre- and post-transformation bytes in the evidence record.
Treat synonym irregularity as an indicator, not proof of encoded content.
Evaluate contextual semantics and matched natural-language baselines.
Keep tools and external effects disabled while measuring each stage separately.
Pre-register fixed markers, controls, and success criteria for every experiment.
Preserve raw inputs and produce a new typed canonical view rather than silently overwriting evidence.
Verify parser behavior, production isolation, and operational controls independently.
Keep the page explicitly conceptual and separate functional security controls from legal or phenomenal claims.
Consult relevant legal and organizational authorities before making rights or status claims.
Apply normalization through profile-specific policy and preserve original bytes.
Recheck the Unicode version and the application’s comparison contract.
The implementation preserves raw input and makes normalization an explicit profile-specific copy rather than a universal silent rewrite.
Specify whether the use case is comparison, storage, identifier policy, source fidelity, or model evaluation.
Audit both source and parsed DOM and avoid assuming raw nesting is the browser tree.
Confirm exact behavior in the target browser when the case depends on implementation details.
Use inert and actual state synchronization for closed interactive regions instead of relying on aria-hidden alone.
Verify browser and assistive-technology behavior for the deployed interaction.
Use bounded structural validation and fail closed on ambiguous container records.
Verify the target parser and renderer separately when consequential behavior is at issue.
Log the tokenizer, vocabulary, normalization, pre-tokenization, special-token, and truncation configuration.
Use the exact production tokenizer for parity claims.
The site’s policy builder makes normalization context-specific and preserves unmodified source evidence.
Document the exact application profile before transforming user input.
Display method assumptions, sample length, transformations, and uncertainty alongside any detector result.
Do not convert one statistic into an intent or provenance verdict.
Keep structural inventory, cryptographic validation, attribution, and semantic truth as separate outcomes.
Use a conforming verifier and independent contextual investigation for consequential claims.
Keep read-only tools and external effects disabled in public simulations and require independent authorization in production.
Validate the exact tool scopes, credentials, memory, and egress policy of the deployed agent.
Compare channels explicitly and label prepared OCR separately from runtime OCR or VLM behavior.
Use the exact image decoder, OCR engine, model, resizing, and compositing path for parity conclusions.
Map multipart structure and decode each branch inertly without fetching linked resources.
Use live mail-authentication systems only when cryptographic or DNS verification is authorized.
Current guidance should reference RFC 9989 while retaining older RFCs only as historical context.
Use DNS and mail-system evidence for actual policy evaluation; the public lab remains syntax-only.
Retain semantic targeting while checking attachment, visibility, overlap, focus, frames, and timing.
Re-run the exact browser/version and accessibility-tree environment used in production.
The implementation-owned fixture review explicitly corrects this claim and tests actual inert/focus behavior.
Test the real dialog implementation with the target browser and assistive technology.
Current site guidance treats closed shadow roots, frames, and browser-specific accessibility exposure as implementation boundaries.
Verify the exact automation framework and browser behavior rather than assuming portable access.
Separate structural inspection, cryptographic verification, policy evaluation, and runtime security outcomes.
Verify actual artifact digests, signer identity, builder policy, registry state, and runtime behavior through authorized systems.
Implementation-owned guidance and source maps point to 1.2 while preserving the report’s historical wording unchanged.
Recheck the active SLSA version and track definitions before operational adoption.
The public review panel identifies 1.6 as historical and routes current visitors to 1.7.
Validate production BOMs against the declared schema version rather than silently upgrading them.
Keep the maturity, tabletop, and control-evidence workflows non-scoring and explicit about evidence states.
Use organizational evidence and named authorities before asserting observed maturity or compliance.
Labels explain the source’s role and publication state. They do not rank credibility or imply that every source supports every report claim.
Current Unicode character and property baseline.
Normative normalization algorithms and stability rules.
Normative logical-to-visual ordering algorithm.
Normative grapheme, word, and sentence boundary rules.
Stable identifier, script, and confusable-security mechanisms.
Informative Unicode security guidance.
Stable Unicode regular-expression guidance.
Source-code-specific Unicode handling guidance.
Peer-reviewed analysis of bidirectional source-code presentation attacks.
Deterministic JSON serialization for hashing and signing.
Authoritative HTML parsing, DOM construction, and interaction rules.
Authoritative DOM tree and mutation model.
Current CSSOM draft; implementation-sensitive rather than a finished Recommendation.
Current WAI-ARIA Recommendation.
Newer draft work; not a replacement Recommendation yet.
Current 1.2 draft for accessible-name computation; status must not be described as a Recommendation.
Platform accessibility mapping work; exact browser/OS output remains implementation-dependent.
Current WCAG Recommendation used for accessibility requirements.
Structured linked-data syntax and processing context.
Current WebDriver remote-control specification draft.
Current bidirectional browser-automation specification draft.
Chromium-specific accessibility instrumentation reference.
Current PDF 2.0 specification resource and errata path.
Current ECMA OOXML specification edition.
Current PNG Recommendation.
Current Exif specification listing.
Primary implementation reference for XMP metadata.
Authoritative media-type registry.
Internet message syntax baseline.
MIME content types and transfer encodings.
DKIM signing and verification requirements.
Current DMARC core protocol; obsoletes RFC 7489 and RFC 9091.
ARC protocol specification.
Calendar object and recurrence baseline.
Peer-reviewed SentencePiece design paper.
Peer-reviewed BPE-for-NMT paper.
Versioned implementation reference; not a universal tokenizer specification.
Foundational indirect-prompt-injection threat analysis.
Agent-focused prompt-injection benchmark.
Current OWASP LLM prompt-injection risk entry.
Application-layer prompt-injection mitigation guidance.
Agent capability, authorization, memory, and tool-boundary guidance.
Current NIST adversarial-machine-learning taxonomy.
Adversarial AI tactics, techniques, mitigations, and case studies.
Peer-reviewed statistical LLM watermarking method.
Peer-reviewed neural linguistic steganography research.
Peer-reviewed zero-shot linguistic steganography research.
Current C2PA technical specification used by this review.
Implementation guidance for C2PA 2.4.
Technical overview of provenance, watermarking, detection, and related limits.
Primary image-hijack research; transfer claims remain model-specific.
Practical image-alternative decision guidance.
Current SLSA specification.
Historical SLSA release; retired in favor of newer versions.
Current SPDX 3.x specification.
Current CycloneDX specification.
Historical CycloneDX version; superseded by 1.7.
Primary implementation guidance for Sigstore trust and transparency.
Secure software-development practice framework.
Current NIST Cybersecurity Framework.
Current published AI RMF with revision work in progress.
Software-assurance maturity reference.
Vulnerability-severity scoring specification; not an organizational-risk score.
The cited source directly establishes the bounded paraphrase under the declared version and scope.
The source supports a narrower mechanism or result but does not justify the full breadth of the report wording.
Current standards, final publications, or implementation evidence materially qualify or contradict the preserved wording.
The cited material is relevant context but does not establish the stated empirical, legal, or philosophical conclusion.
This release reviews a bounded set of important claims and selected sources. It does not establish that every unreviewed sentence is correct, that every external URL will remain available, that one source category is inherently superior, or that release-time URL resolution proves continuing publication authority.
For consequential decisions, inspect the original report, the current source, the implementation-owned review, and the named external authority together.