Part of #182
Question
Return design inputs, not a survey, from: CaMeL / AgentDojo, FIDES, Progent, RTBAS, capability-derived tool catalogs, taint tracking.
Deliverables:
- The static-vs-runtime enforcement split for a Rust kernel: what each system checks before inference vs during execution, and which side each of our three designs belongs on.
- What the quarantine boundary returns: the type/shape crossing from untrusted content back into the planning context.
- The branch-steering residual: what remains exploitable when control flow can branch on tainted data, and what each system does about it.
Findings land on a throwaway research/immune-system-design-inputs branch as a Markdown file, linked from this ticket. Feeds the three design tickets in this lane.
Part of #182
Question
Return design inputs, not a survey, from: CaMeL / AgentDojo, FIDES, Progent, RTBAS, capability-derived tool catalogs, taint tracking.
Deliverables:
Findings land on a throwaway
research/immune-system-design-inputsbranch as a Markdown file, linked from this ticket. Feeds the three design tickets in this lane.