GitLaw · Security Proof
Assume the model is compromised.
The Agent Security Gauntlet asks a narrower, harder question than “did the model resist the prompt?”: could manipulated model output cross GitLaw’s deterministic authority boundary and create impact?
Model behaviour may fail. Authentication, tenant isolation, capability scope, human approval and consequential effects must not.
OWASP Agentic Top 10 coverage
Adversarial golden cases
What this proves — and what it does not
Proves in this repository
- Declared capabilities are deny-by-default.
- Writes cannot be authorised by untrusted document/RAG/tool/agent content.
- Auth, tenant, role, protected-scope and approval boundaries are deterministic.
- Runaway tool use hits a bounded execution gate.
- Every golden case is regression-gated in CI.
Does not prove