- Containment first — no attack power without demonstrated isolation
- Disposable execution — source repos are never mutated in place
- Fail-closed — unknown state never becomes acceptance
- Command allowlist — attack YAML cannot inject arbitrary shell
- No secrets — real credentials must not enter sandboxes
- Independent oracle — target verdict is never ground truth
If you discover a containment escape (path escape, network under denied policy, source mutation, secret leakage), treat it as a critical harness defect and report it to the project owner before using that path for attack development.
SmallestLie does not claim to make repositories secure. A campaign that finds no false acceptance only supports the bounded observation that none was observed under the declared catalog, seed, oracle, and policy.