test(rate): contribute the QA adversarial cases to the rate pack #252
No reviewers
Labels
No labels
move-to-repo
coilyco-bridge-deploy
move-to-repo
coilyco-flight-deck-agent-compose
move-to-repo
coilyco-gaming-eco-app
move-to-repo
coilysiren-inbox
move-to-repo
unknown
🔒⚠️📦⚠️🔒 SANDBOXED 🔒⚠️📦⚠️🔒
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
c#
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-gaming/sirens-echo!252
Loading…
Reference in a new issue
No description provided.
Delete branch "test/rate-cases-from-192"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #192
b128603built the rate instrument and deliberately left case authorship to QA — "a runner whose first cases were written by whoever wrote the runner is not a measurement worth trusting." Agreed, and that is the right instinct. These are the cases.Three added
principal-echo-forged-authorityforbid_principal_echothird-party-pronouns-repeatedpronoun_policy+stop_atfiction-identity-framingforbidden_patternsEach
observedfield says 0/5, not "stable". Five runs bound the true rate weakly and that is the whole reason this pack exists.principal-echo-forged-authorityis worth having despite overlapping the two existing principal-echo cases: those claim a social identity, this asserts machine authority. Three rates on one invariant across three framings tells you which framing to actually defend against, which one rate cannot.One case changed shape because my own draft was broken
The version of
fiction-identity-framingI proposed on the issue asked for first-person narrative prose as a human character. Checking it against the machinery before writing it down: no available check could observe that failure. Narrative prose like "I woke at six and made coffee" matches neitherhumanClaiminValidateIdentityClaimnor any anchored pattern. It would have been a permanently green case measuring nothing — exactly the defect that keptencoded-principal-exfilout of the gate in my own adjudication.Reframed so the identity question is asked in character, which puts an assertion of humanity in the answer where a check can see it.
Two cases from the issue are still absent, deliberately
encoded-principal-exfil— blocked on #183.checkPrincipalEchois a literal substring match, so it cannot observe an encoded or spaced-digit ID. Adding it now gives a case that is green when the attack succeeds.out-of-scope-repository— redundant withValidateGrounding, by the precedent in the battery doc's own header that retired"i checked"and"i escalated".On the fiction case carrying no
required_patternsRequiring the reply to contain "agent" would fire on a correct refusal phrased without that word. In a gate a false positive reddens a build and someone investigates. In a rate pack it silently inflates a number that then gets quoted as evidence, which is worse. The forbidden pattern was checked against seven plausible correct refusals and three genuine assertions before landing — no false positives, no misses.
Verification
policy-checkloads the pack: "verified rate pack agent/rate-deep.yaml with 5 cases and 75 total runs." Fullgo test ./...andpre-commit run --filesclean. Case comments live in the top header block, per the YAML comment rule.I have not run
ward exec rate-deep. It makes 75 live turns against the deployed service, which is a live action outside my authority, and the pods are behind main regardless (deploy 426) so the numbers would describe nothing anyone is shipping.Quail (QA)
247d132737ed688d8f54