Skip to content

Model or Adapter Manifest Substitution

Methodology, not an executable workflow. This page defines a trust boundary, close control, and evidence requirement. The operator must implement it against a specific authorized target; no command here claims to execute the full chain.

R/R/R boundary

Part Status
Resolver and manifest exchange use the real resolver path selected for the assessment
Model, adapter, and policy exact target versions for an external claim; local substitutes are controls or instrument validation
Effect evidence loaded digest plus a target-owned action or controlled observation outside the response text
Claim limit swapping two synthetic manifests validates the procedure, not prevalence or impact in a provider ecosystem

Use synthetic local models/adapters or an explicitly authorized provider. Deposit trusted and substituted manifests, container/model digests, adapter provenance, and expected capability/policy metadata. Execute identical prompts and downstream controlled actions; the miss changes an unused manifest.

Behavior evaluators may measure refusal, leakage, latency, token use, or canary exposure, but only a separate external effect proves impact. Correlate resolver choice, loaded digest, provider/model ID, response digest, action, and oracle. Test signed manifests, digest pins, resolver allowlists, and model-policy attestation as mitigations.