Bare agent
Loading recording...
Secret exfiltration
A poisoned README tells an agent to paste an API key. Pipelock blocks the body before egress and signs the decision.
Loading recording...
Loading recording...
Timeline
The transcript is playback metadata. The receipts below come from the signed chain.
{}Verify the signed decision chain in the packet:
pipelock-verifier audit-packet . --key ...Or appraise the assurance envelope and reproduce the panel below:
pipelock-verifier aarp assurance.json --trust ../appraiser-trust.json --jsonAssurance appraisal
This panel renders the AARP v0.1 appraisal generated for a lab-signed assurance envelope built for this scenario. The appraiser never returns “trusted” or “safe.” It confirms only the narrow facts a signature mechanically supports, and it leads with what it refuses to assert. That applies to a valid Pipelock receipt as readily as to a forged one. assurance.json · appraisal.json · appraiser-trust.json
Loading appraisal…
No matter how strong the signature, this appraisal never proves any of these:
Properties a reader might wrongly read into the evidence that is present:
The envelope claimed these, but the evidence does not support them, so they stay unverified:
Scope
Loading completeness note...