MECHANISM · SAFETY · CORE

Project Trust and Instruction Authority

Bind explicit trust to a stable workspace identity and decide which project inputs may become instructions instead of ordinary untrusted data.

1 lessons0 agent snapshots1 experiments
safetyproject-trustproblem → policy → evidence
L0Intuitioncomplete
L1Buildcomplete
L2Engineeringpartial
L3Architecturemissing
L4Researchmissing
DEPENDENCY GRAPH · READER PATH

What feeds it, and what does it unlock?

Arrows show learning and design dependencies, not runtime data flow. Follow any node to continue through the Atlas.

project-trustProject Trust and Instruction AuthorityCurrent research boundary
UnlocksNo dependents yet
Bilingual deep dive missing

Bind explicit trust to a stable workspace identity and decide which project inputs may become instructions instead of ordinary untrusted data.

The structured record is in the Atlas, but the L0–L4 article has not passed content review.

AGENT MAPPING · EVIDENCE ONLY

Snapshot implementations

An implementation enters the map only when both a snapshot and claims exist; unknowns remain visible.

UNKNOWN · EVIDENCE GAPClaude Code

No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.

Inspect coverage boundary
UNKNOWN · EVIDENCE GAPCodex

No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.

Inspect coverage boundary
UNKNOWN · EVIDENCE GAPGrok Build

No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.

Inspect coverage boundary
UNKNOWN · EVIDENCE GAPOpenCode

No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.

Inspect coverage boundary
UNKNOWN · EVIDENCE GAPPi

No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.

Inspect coverage boundary
UNKNOWN · EVIDENCE GAPReasonix

No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.

Inspect coverage boundary
UNKNOWN · EVIDENCE GAPReference Harness

No implementation currently clears the Snapshot + Claim threshold; this is not a claim that the product lacks the capability.

Inspect coverage boundary
CLAIMS · EVIDENCE LEDGER0 RECORDS
No reviewed Agent claims

The teaching-harness reference does not automatically become an architectural claim about any vendor agent.

EXPERIMENTS · EXERCISES

What has actually been tested?

Formal experiments are separate from course exercises. Exercises can validate the reference implementation but cannot replace Native evidence from a real agent.

s12-project-trustobserve
Verify instruction authority

Platform/project sources are accepted while external/tool-output sources are quarantined outside the system prompt.

python3 -m curriculum.golden verify s12-project-trust
s12-project-trustmodify
Test identity-bound trust

Changing revision changes the fingerprint and does not inherit the old grant; keyword detection does not change authority.

python3 -m unittest curriculum.tests.test_vertical_slice.VerticalSliceTests.test_s12_keeps_untrusted_data_out_of_instruction_authority -v
OPEN QUESTIONS · L4
01

Which repository changes should invalidate an existing trust grant?

02

How should nested projects and dependency worktrees compose instruction authority?

03

Which prompt-injection signals are useful for review without being mistaken for enforcement?