{
 "_doc": "One result as verifycorelabs.com prints it: the headline, the problem and the buyer cut (never reworded) from the lab's plain-English account of the result, the one figure a buyer is shown and its limit, and the lab's current claim and limits verbatim, copied at the commit named in source. A field is left out, never reworded, when it uses a word this site keeps for its own process or names a file this site does not serve (not_reprinted).",
 "slug": "composition-certificates",
 "company": "OrbitalProof",
 "order": 9,
 "rank": 9,
 "served_receipt": "wireless-reliability/results/composition-certificates.json",
 "lab_file_older": false,
 "headline": [
  "In a test world the lab built",
  "the lab ran every sequence of up to three tool calls (2,379 runs on real files and a real database) and found three smallest combinations that leak the secret, each the secret-reading tool followed by an outlet and only one of them a pair"
 ],
 "qualification": [
  "ten tools an AI assistant might use, one of which exists to read secrets, one stored secret, outlets the lab designed, and a verdict that depends on three of the five trust assumptions the lab chose",
  "a check that looks at tools two at a time misses the other two, but ordinary tracking of data from the secret to an outlet (taint analysis) would catch all three"
 ],
 "why": [
  "A platform that approves assistant tools one at a time, or two at a time without following data through intermediate storage, can let a combination of three leak a stored secret"
 ],
 "buyer": [
  "AI agent-platform and runtime-security teams that decide which tool combinations an assistant may use."
 ],
 "figure": "2,379 executed sessions against real files and a real SQLite database",
 "figure_from": "claim",
 "limit": "An approval is single-use only in memory",
 "limit_from": "limits",
 "plain": "2,379 runs on real files and a real database",
 "quotes": {},
 "claim": "Ten individually safe agent tools; 2,379 executed sessions against real files and a real SQLite database, exhaustive to three calls; and the finding that **three ⊆-minimal dangerous compositions exist and only one of them is a pair**.",
 "limits": "An approval is single-use only in memory: it is consumed by the first transition it covers, so one approval plus three `net.post` calls now puts exactly one copy of the credential in the sink, but nothing persists that consumption, and an approval rebuilt from its JSON or shown to another process is unused again.",
 "not_reprinted": [],
 "prior_work": [
  {
   "title": "The lethal trifecta for AI agents: private data, untrusted content, and external communication",
   "by": "Simon Willison, simonwillison.net, 2025-06-16",
   "url": "https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/"
  },
  {
   "title": "Invariant Labs Exposes Novel Prompt Injection Attack Vulnerabilities, \"Toxic Flows,\" in Agentic Systems & MCP Servers",
   "by": "Luca Beurer-Kellner, Marco Milanta, Marc Fischer, Invariant Labs blog, 2025-07-29",
   "url": "https://invariantlabs.ai/blog/toxic-flow-analysis"
  },
  {
   "title": "On lightweight mobile phone application certification",
   "by": "William Enck, Machigar Ongtang, Patrick McDaniel, ACM CCS 2009 (Penn State research portal record)",
   "url": "https://pure.psu.edu/en/publications/on-lightweight-mobile-phone-application-certification/"
  }
 ],
 "source": {
  "claims_file": "registry/CLAIMS_CURRENT.jsonl",
  "claims_sha256": "81776df15a1498abec7228ea179c952d01c54e031ffd4144498a30660963074b",
  "ranking_file": "views/VALUE_RANKING.md",
  "ranking_sha256": "2e980e26178b34dc49ec1d365f966be292f57d7c636143fc62c12feab72ae470",
  "dossier_sha256": "ccfe9eda9029d569e7ea5cf7e2978d51bdb2ef79888779b8cfb7c3e965bb9a12",
  "commit": "25d755d2f06518b632c3658ae83f20312daac53e"
 }
}
