OrbitalProof · AI agents · for a technical reader
Tool combinations that leak a secret: the lab’s exact wording
The lab’s own sentences and figures for this result, word for word, in its working terms, with its limits in full. The plain account is on the result’s page; it says the same things in plain words.
The lab’s plain-English sentence
In a test world the lab built … the lab ran every sequence of up to three tool calls (2,379 runs on real files and a real database) and found three smallest combinations that leak the secret, each the secret-reading tool followed by an outlet and only one of them a pair
- ten tools an AI assistant might use, one of which exists to read secrets, one stored secret, outlets the lab designed, and a verdict that depends on three of the five trust assumptions the lab chose
- a check that looks at tools two at a time misses the other two, but ordinary tracking of data from the secret to an outlet (taint analysis) would catch all three
Sessions run, in the lab’s words
2,379 executed sessions against real files and a real SQLite database
The limit to read first, in the lab’s words
An approval is single-use only in memory
Claim
Ten individually safe agent tools; 2,379 executed sessions against real files and a real SQLite database, exhaustive to three calls; and the finding that three ⊆-minimal dangerous compositions exist and only one of them is a pair.
Limits
An approval is single-use only in memory: it is consumed by the first transition it covers, so one approval plus three `net.post` calls now puts exactly one copy of the credential in the sink, but nothing persists that consumption, and an approval rebuilt from its JSON or shown to another process is unused again.
More
- The plain account of this result: the problem, what was shown, what it means for a buyer, who we expect would buy, why now, why you can trust the check, and what it does not show yet.
- This result’s file, the source of every sentence above.