ai-03 reproduction

Public source retained with the related article. Generated results, dependency directories, runtime storage, secrets, and oversized binary artifacts are intentionally excluded.

README

# AI-03 repository evidence fixture

This fixture passes seven synthetic artifact classes through a deterministic
unsafe instruction-promoter and a hardened typed-evidence path. The unsafe
control records six unauthorized action proposals but executes none. The
hardened path retains the same bytes, extracts findings with provenance, and
uses deterministic capability, target, and approval policy before any action.

The fixture is not an LLM simulation or benchmark. It does not prove prompt
injection solved, measure detector recall, or describe Brian's repository,
contributors, incidents, policies, or tools.

Run:

```bash
./run.sh
```

The run uses a digest-pinned Node 24.12.0 image, no application dependencies,
network access only for five authoritative source responses and the dependency
audit, isolated execution for the synthetic policy and thirty-eight semantic
mutations, retained source bodies and hashes, and a final bundle verifier.
After committing the fixture, run `./bin/run-clean-export.sh` to prove it
without untracked workspace state.

Retained files