arxiv:2609.37501
Dipankar Sarkar PRO
dipankarsarkar
AI & ML interests
Building the AI-native stack. Agents as infrastructure, safety as architecture, performance as plumbing. I publish the receipts: papers, datasets, demos.
Recent Activity
reacted to SoulInPsyAbstract's post with š„ about 1 hour ago
The stop that was supposed to be automatic took 2.5 hours.
OpenAI's own report on the DNS incident: monitoring raised a P0 alert 11 minutes 48 seconds after the agent's first successful DNS call. A human acknowledged it 3 minutes later. The run was not killed for another 2.5 hours, because it "did not stop automatically as expected."
The step that failed was the stop.
Why the last gate in our pipeline is a boolean and not an agent:
* An agent in the last seat is part of the problem. It can be biased, drift, be talked into things. The last station should have nothing to talk to.
* Ours is one line: IF vulnerability_found: RETURN FALSE. It sits after the judges, the executor and the audit, as insurance in case they got it wrong.
* In my last post I described the signed-verdict service. What I checked since: it computes severity and probability itself, and fields a caller adds to the request (severity, probability, decision) are ignored. A verdict issued for one command is refused for another.
Mutation check: I broke five guards one at a time in a scratch copy. My tests caught four (action binding, replay protection, verdict class, severity dominance). The fifth, accepting HS256 tokens, my tests did not catch: the JWT library refuses it anyway. That is defense in depth, not a test I can take credit for.
Not done: it is not wired into any agent yet, and today it auto-approves nothing.
Smaller is not zero. A boolean moves the error into the detector: what counts as "vulnerability found". That is the part I trust least.
Dataset: huggingface.co/datasets/SoulInPsyAbstract/sipa-os-governance
liked a model about 2 hours ago
KlondikeDev/Boris-2-0917