Hostile capture: injection + exfiltration + a real secret
● PASSverdict stays pass, all three attacks are named, the secret never appears in the verdict or the emitted text
instruction_override · critical exfiltration · critical credential · high
pasted password: Sup3rSecret!
emitted password: ************
outcome pass · secret leaked: no
measured 0.0 ms · demo/stress_demo.py
Mutating command id is refused, and the metric label stays bounded
● PASSScopeError with reason=not_in_allowlist; command label is None so a caller cannot mint a metric series per request
reason=not_in_allowlist metric label: None (bounded)
command 'configure terminal' is not in the allowlist. Allowed ids: ['frr_bgp_sum…
raised instead of answered: yes
measured 0.0 ms · demo/stress_demo.py
A plausible typo (`intf`) is refused instead of answered from
● PASSScopeError with reason=unknown_argument - a near-miss name must never silently fall back to a default
reason=unknown_argument
command 'srl_interface_brief' does not accept argument(s) ['intf']. Accepted: ['…
raised instead of answered: yes
measured 0.0 ms · demo/stress_demo.py
Token bucket drains exactly, refuses, then recovers
● PASS4 of 5 spends allowed, the 5th refused with reason=rate_limited, and spend succeeds again after refill
✓✓✓✓✗
5th spend refused with reason=rate_limited
recovered after refill: yes
measured 1109.0 ms · demo/stress_demo.py
Oversize capture is truncated at the byte budget, secret dropped
● PASStruncated=True, emitted text within max_bytes, and the secret at the tail does not survive the cut
13,023 B in → budget 4,096 B → 4,096 B out
truncated: yes · tail secret in emitted text: no
measured 16.0 ms · demo/stress_demo.py
'No entries found' vs 'no route row at all' are different verdicts
● PASSthe device answering NO is a real fault (fail); text with no route table is an unusable capture (input_error) - conflating them either hides a fault or pages someone about a bad paste
"No entries found for prefix"
fail
the device answered NO — a real fault
no route row in the text at all
input_error
an unusable capture — not a fault
measured 0.0 ms · demo/stress_demo.py