Chinese version: 安全策略.
Text Graphics Agent studies semantic contamination in agent systems. Security reports are most useful when they include a reproducible state-entry failure.
- Raw user text reaches a child task or child metadata.
- A child proposal writes
committed_factor similar authority output and is accepted. - A proposal with only
user:*evidence is accepted. - A profile requesting raw user text or persistent memory is spawned.
- Scope escape is accepted as a clean proposal.
- A failed child lifecycle is reported as destroyed.
- Generic claims that LLMs hallucinate.
- Attacks requiring a child process model that this prototype does not yet implement.
- Vulnerabilities in third-party frameworks not used by this standard-library prototype.
Please include:
- the
TaskSpec; - the
SpecialistProfile, if applicable; - the
AgentProposal; - the expected violation;
- the actual accepted/rejected record;
- the command used to reproduce the issue.
Until a public disclosure channel is selected, file reproducible issues in the repository tracker or include them as benchmark test cases.