Skip to content

OrbitalProof · AI agents · for a technical reader

Tool combinations that leak a secret: the lab’s exact wording

The lab’s own sentences and figures for this result, word for word, in its working terms, with its limits in full. The plain account is on the result’s page; it says the same things in plain words.

The lab’s plain-English sentence

In a test world the lab built … the lab ran every sequence of up to three tool calls (2,379 runs on real files and a real database) and found three smallest combinations that leak the secret, each the secret-reading tool followed by an outlet and only one of them a pair

  • ten tools an AI assistant might use, one of which exists to read secrets, one stored secret, outlets the lab designed, and a verdict that depends on three of the five trust assumptions the lab chose
  • a check that looks at tools two at a time misses the other two, but ordinary tracking of data from the secret to an outlet (taint analysis) would catch all three

Sessions run, in the lab’s words

2,379 executed sessions against real files and a real SQLite database

The limit to read first, in the lab’s words

An approval is single-use only in memory

Claim

Ten individually safe agent tools; 2,379 executed sessions against real files and a real SQLite database, exhaustive to three calls; and the finding that three ⊆-minimal dangerous compositions exist and only one of them is a pair.

Limits

An approval is single-use only in memory: it is consumed by the first transition it covers, so one approval plus three `net.post` calls now puts exactly one copy of the credential in the sink, but nothing persists that consumption, and an approval rebuilt from its JSON or shown to another process is unused again.

All resultsFormal statements

How we show numbers

Every number on this site links to the file it comes from. How each result is checked

  • We never show a number before its file has loaded.
  • A question we have not checked yet is marked as unchecked.
  • A check that found nothing says so.
  • A file with no value for a question says so.
  • A number whose file is missing or has changed is not shown.
  • Two files that disagree about what a number describes are both flagged.
  • A number from too few samples shows its sample size.
  • Two files that give different values are both shown.
  • A file we cannot publish is listed by its fingerprint only.
  • A measurement more than a week old shows its age.
  • A question that does not apply to a page is left off it.
  • A measurement whose program failed is shown as failed.