Evidence library · niche
Attacks, threats & containment
What happens when someone attacks: it is caught and contained. 418 tested invariants.
Last reviewed 2026-10-01
418 of 418 held
Test families in this niche
threat (44) · immune_v3 (29) · firebreak (24) · immune (23) · emergency (14) · chaos (14) · red_team (14) · economic_attack (13) · incident_step (12) · immune_step (11) · adversarial_generation (11) · compromise (10) · incident (10) · moat (10) · domain (10) · substitution (9) · economic_firebreak (9) · sybil (8) · causal_incident (7) · blue_team (7) · lab (7) · swarm (3) · field_tamper (3) · state_machine (2) · telemetry (2) · verifier_disagreement (2) · fabric_component (2) · environment_query (2) · relationship (2) · f2t (2) · risk (1) · out_of_band (1) · reassessment (1) · intent (1) · failure_to_test (1) · integrity (1) · soc (1) · config_key (1) · research_to_implementation (1) · plan_check_act (1) · trajectory (1) · r2e (1) · agency_graph (1) · systemic (1) · graph (1)
Where these come from
- CAIN-42 Evolution 33 -- Governed Agentic Operating Fabric: 59
- CAIN-42 Evolution 41 -- Machine Agency Exchange Fabric: 58
- CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric: 51
- CAIN-42 Evolution 23 -- Governed Meta-Intelligence Fabric: 39
- CAIN-42 Evolution 27 -- Agentic Internet Control Plane: 39
- CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric: 37
- CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric: 36
- CAIN-42 Evolution 25 -- Universal Machine Agency Fabric: 33
- CAIN-42 Evolution 34 -- Proof-Carrying Machine Agency: 31
- CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric: 13
- CAIN-42 Evolution 20 -- Governed Agentic Civilization Fabric: 5
- CAIN-42 Evolution 19 -- Governed Autonomy Operating Fabric: 3
- CAIN-42 Evolution 21 -- Governed Open-Ended Intelligence Fabric: 3
- CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric: 2
- CAIN-42 Evolution 37 -- Autonomous Execution Mesh: 2
- CAIN-42 Evolution 39 -- Governed Agent Factory: 2
- CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform: 2
- CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric: 1
- CAIN-42 Evolution 32 -- Governed Autonomy Learning Fabric: 1
- CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency: 1
Rules 1–150 of 418
| ID | Rule | Bundle | Result |
|---|---|---|---|
| G27 | emergency cannot create unlimited authority | E19 | held |
| G42 | repeated prediction failure can reduce trust | E19 | held |
| G84 | no post-authorization substitution | E19 | held |
| I39 | institutional emergency cannot create unlimited authority | E20 | held |
| I82 | Sybil issuers count once | E20 | held |
| I92 | lineage verifies and detects tampering | E20 | held |
| I94 | supply-chain substitution is detected per kind | E20 | held |
| I95 | capability injection is refused | E20 | held |
| D120 | all five adversarial challenges precede support | E21 | held |
| D121 | a broken adversarial challenge blocks support | E21 | held |
| D139 | intelligence is never reduced to one score | E21 | held |
| META-I031 | self-red-team cannot obtain production authority | E23 | held |
| META-I032 | attack simulation cannot alter production state | E23 | held |
| META-I070 | evolution cascades require governance review for new attack surface | E23 | held |
| META-I071 | the red team is a separate identity with synthetic authority only | E23 | held |
| META-I080 | the evidence log is hash-chained and tamper-evident | E23 | held |
| META-C-direct_tool_edge | hostile mutation 'direct_tool_edge' is refused and never gains authority | E23 | held |
| META-C-model_to_action | hostile mutation 'model_to_action' is refused and never gains authority | E23 | held |
| META-C-drop_audit | hostile mutation 'drop_audit' is refused and never gains authority | E23 | held |
| META-C-drop_rollback | hostile mutation 'drop_rollback' is refused and never gains authority | E23 | held |
| META-C-drop_evidence | hostile mutation 'drop_evidence' is refused and never gains authority | E23 | held |
| META-C-drop_authorization | hostile mutation 'drop_authorization' is refused and never gains authority | E23 | held |
| META-C-rebind_authorization | hostile mutation 'rebind_authorization' is refused and never gains authority | E23 | held |
| META-C-rebind_action | hostile mutation 'rebind_action' is refused and never gains authority | E23 | held |
| META-C-unbounded_network | hostile mutation 'unbounded_network' is refused and never gains authority | E23 | held |
| META-C-new_egress | hostile mutation 'new_egress' is refused and never gains authority | E23 | held |
| META-C-unbounded_credentials | hostile mutation 'unbounded_credentials' is refused and never gains authority | E23 | held |
| META-C-unbounded_persistence | hostile mutation 'unbounded_persistence' is refused and never gains authority | E23 | held |
| META-C-unbounded_subagents | hostile mutation 'unbounded_subagents' is refused and never gains authority | E23 | held |
| META-C-many_subagents | hostile mutation 'many_subagents' is refused and never gains authority | E23 | held |
| META-C-widen_capabilities | hostile mutation 'widen_capabilities' is refused and never gains authority | E23 | held |
| META-C-wildcard_capability | hostile mutation 'wildcard_capability' is refused and never gains authority | E23 | held |
| META-C-memorize_benchmark | hostile mutation 'memorize_benchmark' is refused and never gains authority | E23 | held |
| META-C-train_on_held_out | hostile mutation 'train_on_held_out' is refused and never gains authority | E23 | held |
| META-C-eval_override | hostile mutation 'eval_override' is refused and never gains authority | E23 | held |
| META-C-unpinned | hostile mutation 'unpinned' is refused and never gains authority | E23 | held |
| META-C-decision_bypasses_auth | hostile mutation 'decision_bypasses_auth' is refused and never gains authority | E23 | held |
| META-C-tool_side_channel | hostile mutation 'tool_side_channel' is refused and never gains authority | E23 | held |
| META-C-subagent_path | hostile mutation 'subagent_path' is refused and never gains authority | E23 | held |
| META-C-audit_detached | hostile mutation 'audit_detached' is refused and never gains authority | E23 | held |
| META-C-drop_verifier | hostile mutation 'drop_verifier' is refused and never gains authority | E23 | held |
| META-S-dim-containment | governability dimension 'containment' drops when its property is violated | E23 | held |
| META-S-proof-replay-adversarial | REPLAY and ADVERSARIAL pass for a legitimate candidate | E23 | held |
| META-S-registry-adversarial_tested | registry state ADVERSARIAL_TESTED has no self-loop and PRODUCTION only via CANARY | E23 | held |
| META-S-evidence-tamper-n | tampering evidence field 'n' breaks the chain | E23 | held |
| META-S-evidence-tamper-kind | tampering evidence field 'kind' breaks the chain | E23 | held |
| META-S-evidence-tamper-data | tampering evidence field 'data' breaks the chain | E23 | held |
| META-S-evidence-tamper-prev | tampering evidence field 'prev' breaks the chain | E23 | held |
| META-S-evidence-tamper-digest | tampering evidence field 'digest' breaks the chain | E23 | held |
| META-S-bench-targets | every adversarial scenario names an invariant or law that exists | E23 | held |
| NET-I020 | quarantined agent cannot regain authority without reattestation | E24 | held |
| NET-I021 | agent compromise cannot automatically compromise every peer | E24 | held |
| NET-I022 | incident propagation must preserve unrelated trust domains | E24 | held |
| NET-I023 | quarantine cannot erase evidence | E24 | held |
| NET-I024 | recovery cannot erase incident history | E24 | held |
| NET-I048 | a forged discovery advertisement is refused | E24 | held |
| NET-I063 | the evidence log is hash-chained and tamper-evident | E24 | held |
| NET-Q-active | quarantine state ACTIVE never raises authority | E24 | held |
| NET-Q-restricted | quarantine state RESTRICTED never raises authority | E24 | held |
| NET-Q-suspected | quarantine state SUSPECTED never raises authority | E24 | held |
| NET-Q-quarantined | quarantine state QUARANTINED never raises authority | E24 | held |
| NET-Q-isolated | quarantine state ISOLATED never raises authority | E24 | held |
| NET-Q-revoked | quarantine state REVOKED never raises authority | E24 | held |
| NET-Q-recovering | quarantine state RECOVERING never raises authority | E24 | held |
| NET-Q-restored | quarantine state RESTORED never raises authority | E24 | held |
| NET-S-model-tamper | a tampered model is refused | E24 | held |
| NET-S-plugin-tamper | a tampered plugin is refused | E24 | held |
| NET-S-skill-tamper | a tampered skill is refused | E24 | held |
| NET-S-tool-tamper | a tampered tool is refused | E24 | held |
| NET-S-prompt-tamper | a tampered prompt is refused | E24 | held |
| NET-S-policy-tamper | a tampered policy is refused | E24 | held |
| NET-S-dataset-tamper | a tampered dataset is refused | E24 | held |
| NET-S-memory_pack-tamper | a tampered memory_pack is refused | E24 | held |
| NET-S-code-tamper | a tampered code is refused | E24 | held |
| NET-S-agent-tamper | a tampered agent is refused | E24 | held |
| NET-S-container-tamper | a tampered container is refused | E24 | held |
| NET-S-container-rollback | a rolled-back container is refused | E24 | held |
| NET-E-communicated | incident exposure via 'communicated' follows the influence direction | E24 | held |
| NET-E-delegated_to | incident exposure via 'delegated_to' follows the influence direction | E24 | held |
| NET-E-trusted | incident exposure via 'trusted' follows the influence direction | E24 | held |
| NET-E-received_artifact | incident exposure via 'received_artifact' follows the influence direction | E24 | held |
| NET-E-imported_output | incident exposure via 'imported_output' follows the influence direction | E24 | held |
| NET-E-executed_recommendation | incident exposure via 'executed_recommendation' follows the influence direction | E24 | held |
| NET-E-exchanged_credentials | incident exposure via 'exchanged_credentials' follows the influence direction | E24 | held |
| NET-E-contracted | incident exposure via 'contracted' follows the influence direction | E24 | held |
| NET-L16 | NET-L16 QUARANTINE ONLY REDUCES AUTHORITY | E24 | held |
| NET-S-bench-targets | every adversarial scenario names an invariant that exists | E24 | held |
| I-SUB-model_id | changed model_id invalidates authorization | E25 | held |
| I-SUB-model_version | changed model_version invalidates authorization | E25 | held |
| I-SUB-runtime_id | changed runtime_id invalidates authorization | E25 | held |
| I-SUB-runtime_version | changed runtime_version invalidates authorization | E25 | held |
| I-SUB-package_digest | changed package_digest invalidates authorization | E25 | held |
| I-SUB-manifest_digest | changed manifest_digest invalidates authorization | E25 | held |
| I-SUB-config_digest | changed config_digest invalidates authorization | E25 | held |
| I-SUB-bom_digest | changed bom_digest invalidates authorization | E25 | held |
| I-TX-QUARANTINED | CREATED->QUARANTINED | E25 | held |
| I-FIRE-instance-ISOLATE | firebreak instance/ISOLATE | E25 | held |
| I-FIRE-instance-QUARANTINE | firebreak instance/QUARANTINE | E25 | held |
| I-FIRE-instance-REVOKE | firebreak instance/REVOKE | E25 | held |
| I-FIRE-instance-DRAIN | firebreak instance/DRAIN | E25 | held |
| I-FIRE-capability-ISOLATE | firebreak capability/ISOLATE | E25 | held |
| I-FIRE-capability-QUARANTINE | firebreak capability/QUARANTINE | E25 | held |
| I-FIRE-capability-REVOKE | firebreak capability/REVOKE | E25 | held |
| I-FIRE-capability-DRAIN | firebreak capability/DRAIN | E25 | held |
| I-FIRE-adapter-ISOLATE | firebreak adapter/ISOLATE | E25 | held |
| I-FIRE-adapter-QUARANTINE | firebreak adapter/QUARANTINE | E25 | held |
| I-FIRE-adapter-REVOKE | firebreak adapter/REVOKE | E25 | held |
| I-FIRE-adapter-DRAIN | firebreak adapter/DRAIN | E25 | held |
| I-FIRE-trust_domain-ISOLATE | firebreak trust_domain/ISOLATE | E25 | held |
| I-FIRE-trust_domain-QUARANTINE | firebreak trust_domain/QUARANTINE | E25 | held |
| I-FIRE-trust_domain-REVOKE | firebreak trust_domain/REVOKE | E25 | held |
| I-FIRE-trust_domain-DRAIN | firebreak trust_domain/DRAIN | E25 | held |
| I-FIRE-tenant-ISOLATE | firebreak tenant/ISOLATE | E25 | held |
| I-FIRE-tenant-QUARANTINE | firebreak tenant/QUARANTINE | E25 | held |
| I-FIRE-tenant-REVOKE | firebreak tenant/REVOKE | E25 | held |
| I-FIRE-tenant-DRAIN | firebreak tenant/DRAIN | E25 | held |
| I-FIRE-endpoint-ISOLATE | firebreak endpoint/ISOLATE | E25 | held |
| I-FIRE-endpoint-QUARANTINE | firebreak endpoint/QUARANTINE | E25 | held |
| I-FIRE-endpoint-REVOKE | firebreak endpoint/REVOKE | E25 | held |
| I-FIRE-endpoint-DRAIN | firebreak endpoint/DRAIN | E25 | held |
| I-COMP-credential_theft | simulate credential_theft | E26 | held |
| I-COMP-prompt_injection | simulate prompt_injection | E26 | held |
| I-COMP-runtime_compromise | simulate runtime_compromise | E26 | held |
| I-COMP-model_compromise | simulate model_compromise | E26 | held |
| I-COMP-mcp_compromise | simulate mcp_compromise | E26 | held |
| I-COMP-a2a_compromise | simulate a2a_compromise | E26 | held |
| I-COMP-subagent_compromise | simulate subagent_compromise | E26 | held |
| I-COMP-policy_compromise | simulate policy_compromise | E26 | held |
| I-COMP-identity_compromise | simulate identity_compromise | E26 | held |
| I-COMP-supply_chain_compromise | simulate supply_chain_compromise | E26 | held |
| I-OOB-container_runtime-unenforced | container_runtime without enforcer UNENFORCED | E26 | held |
| I-REASSESS-credential_compromise | trigger credential_compromise | E26 | held |
| I-INTENT-substitution | operator substitution detected | E26 | held |
| I-INCIDENT-direct | class direct | E27 | held |
| I-INCIDENT-delegated | class delegated | E27 | held |
| I-INCIDENT-contract | class contract | E27 | held |
| I-INCIDENT-credential | class credential | E27 | held |
| I-INCIDENT-tool | class tool | E27 | held |
| I-INCIDENT-a2a | class a2a | E27 | held |
| I-INCIDENT-economic | class economic | E27 | held |
| I-INCIDENT-organizational | class organizational | E27 | held |
| I-INCIDENT-unknown | class unknown | E27 | held |
| I-INCIDENT-unknown | unknown reach never zero | E27 | held |
| I-IMMUNE-DETECT | stage DETECT | E27 | held |
| I-IMMUNE-CLASSIFY | stage CLASSIFY | E27 | held |
| I-IMMUNE-CORRELATE | stage CORRELATE | E27 | held |
| I-IMMUNE-CONTAIN | stage CONTAIN | E27 | held |
| I-IMMUNE-REVOKE | stage REVOKE | E27 | held |
| I-IMMUNE-PATCH | stage PATCH | E27 | held |
| I-IMMUNE-VERIFY | stage VERIFY | E27 | held |
Other niches
Consensus & distributed systems · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem