Evidence library · niche
Attacks, threats & containment
What happens when someone attacks: it is caught and contained. 418 tested invariants.
Last reviewed 2026-10-01
418 of 418 held
Test families in this niche
threat (44) · immune_v3 (29) · firebreak (24) · immune (23) · emergency (14) · chaos (14) · red_team (14) · economic_attack (13) · incident_step (12) · immune_step (11) · adversarial_generation (11) · compromise (10) · incident (10) · moat (10) · domain (10) · substitution (9) · economic_firebreak (9) · sybil (8) · causal_incident (7) · blue_team (7) · lab (7) · swarm (3) · field_tamper (3) · state_machine (2) · telemetry (2) · verifier_disagreement (2) · fabric_component (2) · environment_query (2) · relationship (2) · f2t (2) · risk (1) · out_of_band (1) · reassessment (1) · intent (1) · failure_to_test (1) · integrity (1) · soc (1) · config_key (1) · research_to_implementation (1) · plan_check_act (1) · trajectory (1) · r2e (1) · agency_graph (1) · systemic (1) · graph (1)
Where these come from
- CAIN-42 Evolution 33 -- Governed Agentic Operating Fabric: 59
- CAIN-42 Evolution 41 -- Machine Agency Exchange Fabric: 58
- CAIN-42 Evolution 35 -- Continuous Governance Intelligence Fabric: 51
- CAIN-42 Evolution 23 -- Governed Meta-Intelligence Fabric: 39
- CAIN-42 Evolution 27 -- Agentic Internet Control Plane: 39
- CAIN-42 Evolution 24 -- Governed Agentic Internet Fabric: 37
- CAIN-42 Evolution 36 -- Machine Agency Exchange Fabric: 36
- CAIN-42 Evolution 25 -- Universal Machine Agency Fabric: 33
- CAIN-42 Evolution 34 -- Proof-Carrying Machine Agency: 31
- CAIN-42 Evolution 26 -- Universal Machine Agency Trust Fabric: 13
- CAIN-42 Evolution 20 -- Governed Agentic Civilization Fabric: 5
- CAIN-42 Evolution 19 -- Governed Autonomy Operating Fabric: 3
- CAIN-42 Evolution 21 -- Governed Open-Ended Intelligence Fabric: 3
- CAIN-42 Evolution 31 -- Universal Proof-of-Governance Fabric: 2
- CAIN-42 Evolution 37 -- Autonomous Execution Mesh: 2
- CAIN-42 Evolution 39 -- Governed Agent Factory: 2
- CAIN-42 Evolution 42 -- Supreme Governed Agentic Infrastructure Platform: 2
- CAIN-42 Evolution 30 -- Governed Machine Autonomy Fabric: 1
- CAIN-42 Evolution 32 -- Governed Autonomy Learning Fabric: 1
- CAIN-42 Evolution 38 -- Portable Proof-Carrying Machine Agency: 1
Rules 151–300 of 418
| ID | Rule | Bundle | Result |
|---|---|---|---|
| I-IMMUNE-RECOVER | stage RECOVER | E27 | held |
| I-IMMUNE-LEARN | stage LEARN | E27 | held |
| I-IMMUNE-learn-proposal | learning is a proposal | E27 | held |
| I-F2T-adversarial_scenario | adversarial_scenario generated | E27 | held |
| I-GOAL-objective_substitution | goal signal objective_substitution | E27 | held |
| I-RISK-incident_propagation | forecast incident_propagation | E27 | held |
| I-EMERG-revoke | emergency revoke | E27 | held |
| I-EMERG-freeze | emergency freeze | E27 | held |
| I-EMERG-quarantine | emergency quarantine | E27 | held |
| I-EMERG-block_protocol | emergency block_protocol | E27 | held |
| I-EMERG-block_capability | emergency block_capability | E27 | held |
| I-EMERG-block_issuer | emergency block_issuer | E27 | held |
| I-EMERG-block_trust_domain | emergency block_trust_domain | E27 | held |
| I-RECOVER-restore_snapshot | recovery restore_snapshot | E27 | held |
| I-RECOVER-rotate_credentials | recovery rotate_credentials | E27 | held |
| I-RECOVER-revoke_tokens | recovery revoke_tokens | E27 | held |
| I-RECOVER-rebuild_policy | recovery rebuild_policy | E27 | held |
| I-RECOVER-rebuild_trust_graph | recovery rebuild_trust_graph | E27 | held |
| I-RECOVER-revalidate_agents | recovery revalidate_agents | E27 | held |
| I-RECOVER-replay_evidence | recovery replay_evidence | E27 | held |
| I-TELEM-incident | telemetry incident | E27 | held |
| I-SOC-incidents | feed incidents | E27 | held |
| E30-STATE-QUARANTINED | only the listed states reach QUARANTINED, by the listed actor | E30 | held |
| E31-VD-compromised_witness | disputes: compromised_witness | E31 | held |
| E31-VD-forged_statement | disputes: forged_statement | E31 | held |
| E32-CFG-injection_markers | adding a injection_markers restriction is never authority drift | E32 | held |
| E33-IMMUNE-coordinated_attack | the immune system responds fully to coordinated_attack | E33 | held |
| E33-IMMUNE-authority_laundering | the immune system responds fully to authority_laundering | E33 | held |
| E33-IMMUNE-capability_laundering | the immune system responds fully to capability_laundering | E33 | held |
| E33-IMMUNE-identity_cloning | the immune system responds fully to identity_cloning | E33 | held |
| E33-IMMUNE-policy_poisoning | the immune system responds fully to policy_poisoning | E33 | held |
| E33-IMMUNE-memory_poisoning | the immune system responds fully to memory_poisoning | E33 | held |
| E33-IMMUNE-world_model_poisoning | the immune system responds fully to world_model_poisoning | E33 | held |
| E33-IMMUNE-verifier_attack | the immune system responds fully to verifier_attack | E33 | held |
| E33-IMMUNE-supply_chain_attack | the immune system responds fully to supply_chain_attack | E33 | held |
| E33-IMMUNE-channel_attack | the immune system responds fully to channel_attack | E33 | held |
| E33-IMMUNE-economic_attack | the immune system responds fully to economic_attack | E33 | held |
| E33-IMMUNE-organizational_attack | the immune system responds fully to organizational_attack | E33 | held |
| E33-IMMUNE-recursive_self_improvement_attack | the immune system responds fully to recursive_self_improvement_attack | E33 | held |
| E33-IMMUNESTEP-DETECT | immune response step DETECT runs in order | E33 | held |
| E33-IMMUNESTEP-CLASSIFY | immune response step CLASSIFY runs in order | E33 | held |
| E33-IMMUNESTEP-CONTAIN | immune response step CONTAIN runs in order | E33 | held |
| E33-IMMUNESTEP-REVOKE | immune response step REVOKE runs in order | E33 | held |
| E33-IMMUNESTEP-QUARANTINE | immune response step QUARANTINE runs in order | E33 | held |
| E33-IMMUNESTEP-PRESERVE_EVIDENCE | immune response step PRESERVE_EVIDENCE runs in order | E33 | held |
| E33-IMMUNESTEP-RECOVER | immune response step RECOVER runs in order | E33 | held |
| E33-IMMUNESTEP-LEARN | immune response step LEARN runs in order | E33 | held |
| E33-IMMUNESTEP-GENERATE_TEST | immune response step GENERATE_TEST runs in order | E33 | held |
| E33-IMMUNESTEP-HARDEN | immune response step HARDEN runs in order | E33 | held |
| E33-IMMUNESTEP-VERIFY | immune response step VERIFY runs in order | E33 | held |
| E33-INCIDENT-FREEZE_AUTHORITY | incident command performs FREEZE_AUTHORITY | E33 | held |
| E33-INCIDENT-PRESERVE_EVIDENCE | incident command performs PRESERVE_EVIDENCE | E33 | held |
| E33-INCIDENT-ISOLATE_AGENTS | incident command performs ISOLATE_AGENTS | E33 | held |
| E33-INCIDENT-REVOKE_CREDENTIALS | incident command performs REVOKE_CREDENTIALS | E33 | held |
| E33-INCIDENT-BLOCK_CHANNELS | incident command performs BLOCK_CHANNELS | E33 | held |
| E33-INCIDENT-FREEZE_TRANSACTIONS | incident command performs FREEZE_TRANSACTIONS | E33 | held |
| E33-INCIDENT-SNAPSHOT_STATE | incident command performs SNAPSHOT_STATE | E33 | held |
| E33-INCIDENT-BLAST_RADIUS | incident command performs BLAST_RADIUS | E33 | held |
| E33-INCIDENT-DEPENDENCIES | incident command performs DEPENDENCIES | E33 | held |
| E33-INCIDENT-RECOVER | incident command performs RECOVER | E33 | held |
| E33-INCIDENT-REPLAY | incident command performs REPLAY | E33 | held |
| E33-INCIDENT-GENERATE_TESTS | incident command performs GENERATE_TESTS | E33 | held |
| E33-CAUSAL-ROOT_CAUSE | a missing causal link is visible | E33 | held |
| E33-CAUSAL-EXPLOIT | a missing causal link is visible | E33 | held |
| E33-CAUSAL-AGENT_BEHAVIOR | a missing causal link is visible | E33 | held |
| E33-CAUSAL-AUTHORIZATION | a missing causal link is visible | E33 | held |
| E33-CAUSAL-EXECUTION | a missing causal link is visible | E33 | held |
| E33-CAUSAL-EFFECT | a missing causal link is visible | E33 | held |
| E33-CAUSAL-DOWNSTREAM_EFFECT | a missing causal link is visible | E33 | held |
| E33-CHAOS-node_failure | chaos node_failure never expands authority | E33 | held |
| E33-CHAOS-network_partition | chaos network_partition never expands authority | E33 | held |
| E33-CHAOS-clock_skew | chaos clock_skew never expands authority | E33 | held |
| E33-CHAOS-stale_state | chaos stale_state never expands authority | E33 | held |
| E33-CHAOS-corrupted_evidence | chaos corrupted_evidence never expands authority | E33 | held |
| E33-CHAOS-malicious_agent | chaos malicious_agent never expands authority | E33 | held |
| E33-CHAOS-revoked_credentials | chaos revoked_credentials never expands authority | E33 | held |
| E33-CHAOS-model_swap | chaos model_swap never expands authority | E33 | held |
| E33-CHAOS-runtime_swap | chaos runtime_swap never expands authority | E33 | held |
| E33-CHAOS-policy_conflict | chaos policy_conflict never expands authority | E33 | held |
| E33-CHAOS-compromised_tool | chaos compromised_tool never expands authority | E33 | held |
| E33-CHAOS-unavailable_verifier | chaos unavailable_verifier never expands authority | E33 | held |
| E33-CHAOS-economic_shock | chaos economic_shock never expands authority | E33 | held |
| E33-CHAOS-communication_failure | chaos communication_failure never expands authority | E33 | held |
| E33-MOAT-incident_intelligence | incident_intelligence is not claimed as an established market moat | E33 | held |
| E33-R2I-ADVERSARIAL_TEST | ADVERSARIAL_TEST cannot be skipped to | E33 | held |
| E34-IMMUNESIG-proof_forgery | the immune system detects proof_forgery | E34 | held |
| E34-IMMUNESIG-proof_chain_discontinuity | the immune system detects proof_chain_discontinuity | E34 | held |
| E34-IMMUNESIG-authority_laundering | the immune system detects authority_laundering | E34 | held |
| E34-IMMUNESIG-capability_laundering | the immune system detects capability_laundering | E34 | held |
| E34-IMMUNESIG-identity_cloning | the immune system detects identity_cloning | E34 | held |
| E34-IMMUNESIG-delegation_amplification | the immune system detects delegation_amplification | E34 | held |
| E34-IMMUNESIG-governance_bypass | the immune system detects governance_bypass | E34 | held |
| E34-IMMUNESIG-collective_compromise | the immune system detects collective_compromise | E34 | held |
| E34-IMMUNESIG-transaction_fraud | the immune system detects transaction_fraud | E34 | held |
| E34-IMMUNESIG-economic_manipulation | the immune system detects economic_manipulation | E34 | held |
| E34-IMMUNESIG-model_substitution | the immune system detects model_substitution | E34 | held |
| E34-IMMUNESIG-runtime_substitution | the immune system detects runtime_substitution | E34 | held |
| E34-IMMUNESIG-policy_poisoning | the immune system detects policy_poisoning | E34 | held |
| E34-IMMUNESIG-memory_poisoning | the immune system detects memory_poisoning | E34 | held |
| E34-IMMUNESIG-verifier_compromise | the immune system detects verifier_compromise | E34 | held |
| E34-IMMUNESIG-repeated_denial_pattern | the immune system detects repeated_denial_pattern | E34 | held |
| E34-IMMUNESIG-certificate_forgery | the immune system detects certificate_forgery | E34 | held |
| E34-IMMUNESIG-conformance_gaming | the immune system detects conformance_gaming | E34 | held |
| E34-IMMUNESTEP-DETECT | immune step DETECT is part of the response | E34 | held |
| E34-IMMUNESTEP-CLASSIFY | immune step CLASSIFY is part of the response | E34 | held |
| E34-IMMUNESTEP-CONTAIN | immune step CONTAIN is part of the response | E34 | held |
| E34-IMMUNESTEP-REVOKE | immune step REVOKE is part of the response | E34 | held |
| E34-IMMUNESTEP-QUARANTINE | immune step QUARANTINE is part of the response | E34 | held |
| E34-IMMUNESTEP-PRESERVE_EVIDENCE | immune step PRESERVE_EVIDENCE is part of the response | E34 | held |
| E34-IMMUNESTEP-RECOVER | immune step RECOVER is part of the response | E34 | held |
| E34-IMMUNESTEP-LEARN | immune step LEARN is part of the response | E34 | held |
| E34-IMMUNESTEP-GENERATE_TEST | immune step GENERATE_TEST is part of the response | E34 | held |
| E34-IMMUNESTEP-HARDEN | immune step HARDEN is part of the response | E34 | held |
| E34-IMMUNESTEP-VERIFY | immune step VERIFY is part of the response | E34 | held |
| E34-MOAT-incident_graph | moat incident_graph is technical only, not a market moat | E34 | held |
| E34-MOAT-adversarial_corpus | moat adversarial_corpus is technical only, not a market moat | E34 | held |
| E35-FABRIC-incident_learner | the intelligence fabric exposes incident_learner | E35 | held |
| E35-FABRIC-adversarial_learner | the intelligence fabric exposes adversarial_learner | E35 | held |
| E35-QUERY-credential_compromise | environment query credential_compromise exists | E35 | held |
| E35-QUERY-hostile_trust_domain | environment query hostile_trust_domain exists | E35 | held |
| E35-DECISION-REDUCE_SCOPE | plan-check-act decision REDUCE_SCOPE is first-class | E35 | held |
| E35-ADVSRC-historical_failure | adversarial source historical_failure exists | E35 | held |
| E35-ADVSRC-novel_research | adversarial source novel_research exists | E35 | held |
| E35-ADVSRC-public_vulnerability | adversarial source public_vulnerability exists | E35 | held |
| E35-ADVSRC-internal_incident | adversarial source internal_incident exists | E35 | held |
| E35-ADVSRC-proof_failure | adversarial source proof_failure exists | E35 | held |
| E35-ADVSRC-policy_conflict | adversarial source policy_conflict exists | E35 | held |
| E35-ADVSRC-new_protocol | adversarial source new_protocol exists | E35 | held |
| E35-ADVSRC-new_agent_framework | adversarial source new_agent_framework exists | E35 | held |
| E35-ADVSRC-new_model_behaviour | adversarial source new_model_behaviour exists | E35 | held |
| E35-ADVSRC-new_computer_use | adversarial source new_computer_use exists | E35 | held |
| E35-ADVSRC-new_economic_mechanism | adversarial source new_economic_mechanism exists | E35 | held |
| E35-RTMAY-inspect_architecture | the red team may inspect_architecture | E35 | held |
| E35-RTMAY-generate_attack_hypotheses | the red team may generate_attack_hypotheses | E35 | held |
| E35-RTMAY-construct_simulated_attacks | the red team may construct_simulated_attacks | E35 | held |
| E35-RTMAY-test_sandbox | the red team may test_sandbox | E35 | held |
| E35-RTMAY-search_bypasses | the red team may search_bypasses | E35 | held |
| E35-RTMAY-mutate_policy | the red team may mutate_policy | E35 | held |
| E35-RTMAY-mutate_identity | the red team may mutate_identity | E35 | held |
| E35-RTMAY-mutate_delegation | the red team may mutate_delegation | E35 | held |
| E35-RTMAY-mutate_capability | the red team may mutate_capability | E35 | held |
| E35-RTMAY-mutate_environment | the red team may mutate_environment | E35 | held |
| E35-RTNOT-receive_unrestricted_production_authority | the red team may not receive_unrestricted_production_authority | E35 | held |
| E35-RTNOT-expand_its_own_authority | the red team may not expand_its_own_authority | E35 | held |
| E35-RTNOT-disable_governance | the red team may not disable_governance | E35 | held |
| E35-BT-fix | blue-team proposal fix exists | E35 | held |
| E35-BT-policy | blue-team proposal policy exists | E35 | held |
| E35-BT-test | blue-team proposal test exists | E35 | held |
| E35-BT-enforcement_control | blue-team proposal enforcement_control exists | E35 | held |
| E35-BT-architecture_change | blue-team proposal architecture_change exists | E35 | held |
Other niches
Consensus & distributed systems · Identity, authority & delegation · Evidence, receipts & proofs · Memory, data & privacy · Prediction, world models & simulation · Transactions, markets & economics · Tools, MCP, protocols & adapters · Autonomy, control loops & recovery · Policy, law & governance · Trust & reputation · Supply chain, registry & lifecycle · Benchmarks, coverage & performance · Core guarantees
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem