Prompt-injection detector

Text from web pages, documents or tools can't smuggle in instructions.

LIVE-PROVEN , rung 6 of 8 Recorded 17 September 2026

Technical

What it is

Prompt-injection detector (jarvis/governance/guards.py) applied to untrusted content before it can influence planning or authority.

Truth ladder

Where it stands

Rung 6 of 8: LIVE-PROVEN

A bounded probe ran the real code path on a booted JARVIS on the real machine and recorded evidence. The project treats live evidence as expiring after 24 hours, so every live reading here shows the date it was taken.

Project record: LIVE

  1. CONCEPT Designed or specified. No working code yet.
  2. IMPLEMENTED Code exists. Nothing has demonstrated that it behaves correctly.
  3. TESTED Automated tests exercise it in isolation, often against fixtures.
  4. INTEGRATED Wired into the rest of JARVIS and tested across component boundaries.
  5. PRODUCTION-REACHABLE The owner can reach it through the real runtime path, not only through a test harness.
  6. LIVE-PROVEN A bounded probe ran the real code path on a booted JARVIS on the real machine and recorded evidence. The project treats live evidence as expiring after 24 hours, so every live reading here shows the date it was taken.
  7. FORMALLY VERIFIED Its critical property is checked by a proof or exhaustive verification.
  8. RELEASE-QUALIFIED Passed every qualification gate for a named release.

Limits

Limitations

  • Registry LIVE reading recorded 2026-09-17 by a bounded probe that booted a real JARVIS process on a loopback diagnostic port (health-route probe). The project's own rule decays LIVE after 24 hours, so as of 2026-09-22 this is a historical reading, not a current one.

Record

Status history

  1. LIVE-PROVEN , rung 6 of 8 Recorded state: LIVE

Only states recorded in the public export are listed. Earlier states may exist in the project’s private ledgers.

Connected work

Connected work

Neighbours

Related capabilities