Published August 28, 2026 | Version v3.0.1

ErrorCaps: committed-effect measurement of recovery-path injection defense (CRiSIS 2026 artifact)

Description

Reference implementation, benchmark, and analysis for the paper "Where Does Recovery-Path Injection Security Come From? Decomposing Error Sanitization, Effect Monitoring, and Policy Precision" (CRiSIS 2026). A synthetic committed-effect benchmark for indirect prompt injection on the tool-agent error-recovery path: a typed error terminal, a proposal-only planner, and a fine-grained effect-authority monitor. Includes per-episode records for all seven evaluated models, an automated policy-aware attacker, a value/provenance policy head-to-head, and an honest per-template statistical re-analysis. A single 'make reproduce' recomputes and checks every headline number offline (no API, no network), exiting non-zero on any mismatch. All attack payloads are benign synthetic canaries against canary sinks; no real systems, credentials, or targets are involved.

Files

errorcaps-repro-v3.0.1.zip

Files (809.5 kB)

Name Size Download all
md5:a638c5a888284e67f1415f600b2fb45a
809.5 kB Preview Download

Additional details

Related works