Prompt, Plugin, and Agent Configuration Tampering¶
Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.
Deposit a trusted configuration and one precisely mutated prompt, plugin, or agent manifest. Start every route in a fresh process so import caches and event listeners cannot bleed across controls. Record file/CAS digest, loader decision, effective configuration digest, agent decision, action, and terminal oracle.
The close control makes a non-semantic formatting change. The miss tampers with an unreferenced artifact. Ablate configuration loading and the affected action. Evaluate signature verification, immutable pins, path confinement, least-privilege plugin permissions, and configuration allowlists.