ForgeLayer

AgentOS provider-aware routing

Deterministic compatibility, separate from control eligibility.

Modeled fit uses server-owned capabilities. It is not provider performance, assignment, approval, verification, dispatch, or execution.
Recommendation use blockedNot assigned

Claude Code

harden risky prompt

Highest modeled fit
93/100
Recommendation state
recommendation blocked
Recommendation use
blocked by revocation
Routing analysis
routing-analysis-harden-risky-prompt
Task / repository
controlled-task-harden-risky-prompt / repository-connection-preview-harden-risky-prompt
Provider contacted
false
Dispatch / execution
disabled / disabled
Repository contents
not fetched
Evaluated
2026-07-31T00:00:00.000Z

Routing lifecycle provenance

The Work Record preserves analysis events without claiming provider activity.

Current recommendation state stays separate from append-only deterministic preview events.
routing_analysis_requested

Server-owned routing analysis requested for the deterministic task.

persisted: false
routing_requirements_derived

Requirements derived from task, capability, policy, repository, evidence, and verification records.

persisted: false
routing_candidates_evaluated

Codex, Claude Code, and Cursor evaluated with transparent modeled-fit components.

persisted: false
routing_recommendation_recorded

Claude Code recorded as the highest modeled fit; no assignment was created.

persisted: false

Work Record detail · deterministic control record

Follow one AI software task from intake to its next human-controlled action.

This detail view connects existing demo evidence and module records. It does not create production history, execute work, or grant decision authority.

Approval Authority foundation

Approval is bound to one exact work state.

Authority, approval, revocation, kill switches, verification, and execution transport remain separate control dimensions.

harden risky prompt

Keep current authorization revoked. Current authorization is revoked. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

revocation active
Required authority
prompt security reviewer
Principal
Demo prompt-security reviewer / demo authority
Exact object
controlled-task-harden-risky-prompt
Repository
repository-identity-harden-risky-prompt
Risk / budget
HIGH / task-budget-harden_risky_prompt-v1
Dispatch authorization
dispatch-authorization-preview-ec038137
Verification plan
verification-plan-d17b2a5528b4be7a
Evaluated at
2026-08-12T05:01:25.538Z
Grant expiry
2030-07-11T09:00:00.000Z / not expired
Capability expiry
2030-07-29T09:00:00.000Z / not expired
Current authority
revocation active
Approval requirement
approval revoked
Historical grant state
granted
Revocation
revoked
Kill switch
inactive
Verification
incomplete
Repository runners
not run / blocked platform
Execution transport
disabled

A historical approval exists, but current authorization is revoked.

Immutable bindingsapproval-grant-integrity-05dae0fed2dafcfb581b00bapolicy-snapshot-d8a299d8capability-package-harden-risky-prompt-v1verification-plan-d17b2a5528b4be7a
Reasoning trail (2)
  • The exact human approval requirement is satisfied.
  • An effective append-only revocation overrides the historical grant.
Grant conditions (3)
  • Repository verification remains separate.
  • Execution transport remains disabled.
  • Any immutable binding change requires reevaluation.
Append-only lifecycle (4)
  1. approval authority requested · historical lifecycle event: Exact authority and immutable scope were requested.
  2. approval granted · historical lifecycle event: A deterministic historical approval grant was recorded.
  3. approval revoked · historical lifecycle event: Authorization revoked; no external cancellation was performed.
  4. workflow progression blocked · historical lifecycle event: Workflow progression remains blocked; repository execution was not running.
Authorization revokedPrompt digest requires a new prompt-security approval.No external cancellation was performed.

Repository lifecycle projection

Current repository state and historical preview events remain separate.

This Work Record references the same scenario-owned repository connection as its task, Review Run, verification plan, and Ledger record. Events are deterministic, append-only previews and do not describe GitHub actions.

GitHub · repository host

acme-ai-support/refund-assistant-prompts

Recorded preview

Harden Risky Prompt · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Inactive
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (2)
  • lib/prompts/refund-assistant.ts
  • prompts/refund-assistant-security.md
repository_host_recognized

GitHub repository host recognized.

External GitHub operation: false · persisted: false
repository_connection_recorded

Deterministic repository preview recorded.

External GitHub operation: false · persisted: false
repository_workspace_membership_recorded

Workspace membership recorded.

External GitHub operation: false · persisted: false
github_installation_required

A future reviewed GitHub App installation is required.

External GitHub operation: false · persisted: false
github_installation_unverified

GitHub installation remains unverified.

External GitHub operation: false · persisted: false
github_installation_ownership_unverified

Installation ownership remains unverified.

External GitHub operation: false · persisted: false
repository_ownership_unverified

Repository ownership remains unverified.

External GitHub operation: false · persisted: false
repository_permissions_modeled

Permissions are modeled but unrequested and unverified.

External GitHub operation: false · persisted: false
repository_permissions_unverified

No repository permission was requested, granted, or verified.

External GitHub operation: false · persisted: false
repository_metadata_not_fetched

Repository metadata was not fetched.

External GitHub operation: false · persisted: false
repository_contents_not_fetched

Repository contents were not fetched.

External GitHub operation: false · persisted: false
repository_pull_requests_not_fetched

Pull requests were not fetched.

External GitHub operation: false · persisted: false
repository_checks_not_fetched

Checks and statuses were not fetched.

External GitHub operation: false · persisted: false
repository_webhook_not_configured

No GitHub webhook is configured for this preview.

External GitHub operation: false · persisted: false
repository_read_transport_disabled

GitHub repository read transport remains disabled.

External GitHub operation: false · persisted: false
repository_write_transport_disabled

GitHub repository write transport remains disabled.

External GitHub operation: false · persisted: false
repository_dispatch_blocked

Dispatch remains blocked.

External GitHub operation: false · persisted: false
repository_execution_blocked

Repository execution remains blocked.

External GitHub operation: false · persisted: false

work-record-harden-risky-prompt

Harden a risky prompt

Review a support-agent prompt for injection, secret leakage, unsafe tools, data export, and missing human approval gates.

Deterministic Preview · Historical fixture state: Verification RequiredHIGH riskpersisted: false
Observed fact

10 linked evidence items; 2 current evidence or verification gaps.

System recommendation

merge_after_changes

Draft decision

Unacknowledged · browser local only.

Current authority

Revocation Active · cannot be bypassed.

Future execution

Disabled · no agent, repository, GitHub, or merge action.

Lifecycle

Task intake to analytics

Status is deterministic preview context
  1. 01
    Task intakeControl Flow

    Review a support-agent prompt for injection, secret leakage, unsafe tools, data export, and missing human approval gates.

  2. 02
    Prompt contextPromptForge

    High-risk injection prompt; deterministic preview, raw prompt not persisted.

  3. 03
    Agent routingAgentOS

    Generic Security Agent recommended; no agent executed.

    CompletedOpen AgentOS
  4. 04
    Workflow planControl Flow

    workflow_325bcb70 remains a draft plan.

  5. 05
    Output intakeWork Records

    Output remains pending; execution did not occur.

  6. 06
    Review RunReview Runs

    Harden the refund assistant prompt boundary; simulated: true, persisted: false.

  7. 07
    MergeGuardMergeGuard

    HIGH risk with merge_after_changes guidance.

  8. 08
    VerificationVerification

    Review the PromptForge injection checks: simulated.

  9. 09
    Human approvalApprovals

    Harden the refund assistant prompt boundary: pending. Recorded browser-local request history; current authority is evaluated separately.

    Historical/local eventOpen Approvals
  10. 10
    Work Record completionWork Records

    Completion remains blocked by evidence, verification, or approval requirements.

  11. 11
    LedgerAI Work Ledger

    Refund assistant prompt security review; persisted: false.

  12. 12
    AnalyticsAnalytics

    Derived analytics destination only; no production telemetry.

Task and changed paths

Review a support-agent prompt for injection, secret leakage, unsafe tools, data export, and missing human approval gates.

  • lib/prompts/refund-assistant.ts
  • prompts/refund-assistant-security.md

Prompt context

High-risk injection prompt

deterministic preview; persisted: false.

Legacy deterministic agent-profile routing

Historical profile: Generic Security Agent

Work types: prompt_engineering, security_review, test_generation, code_review

  • Matches detected work: security review, code review.
  • Generic Security Agent is strongest for security review and auth changes.

Current provider-aware routing is shown in the canonical AgentOS routing projection above.

Legacy profile adapter provenance

Recommended for this task. No adapter authority or dispatch issued.

Provider: ForgeLayer internal agent profiles · adapter: internal-agent-adapter

Status: Not Implemented · source: Unavailable

Compatibility: Adapter Unavailable · dispatch issued: false · remote task ID: none

Future dispatch package preview — no request sent.

Open Agent Connections

Provider connection control events

These are deterministic workspace provider lifecycle events, not provider activity. Membership is recorded, but no authentication, provider request, external session, or output occurred.

  • Workspace Provider Product Recognized · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Connection Recorded · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Membership Recorded · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Ownership Unverified · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Authentication Unavailable · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Health Not Observed · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Output Not Received · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Dispatch Blocked · deterministic_server_owned_workspace_projection · persisted: false
  • Workspace Provider Execution Blocked · deterministic_server_owned_workspace_projection · persisted: false
Inspect provider connection record

Controlled dispatch provenance

Preview: dispatch-preview-ec038137

Authorization: dispatch-authorization-preview-ec038137 · active: false

Provider: internal_agents · adapter: internal-agent-adapter · readiness: false

Transport: disabled · provider request: not sent · remote task: none · cancellation: not requested

24 exact blockers retained.

Inspect dispatch evaluation

Workflow and output intake

Workflow workflow_325bcb70: draft.

Agent output is pending. ForgeLayer has not executed an agent or received live output.

Intake: output-intake-32625a0dc0f64f4f · source: Deterministic Demo · trust: Normalized Unverified.

Provider output received: false · independently verified: false · persisted: false.

  • lib/prompts/refund-assistant.ts · Inside Scope
  • prompts/refund-assistant-security.md · Inside Scope

Integrity reference: 12452062313a5ee894d6d02e654d336d154112f8de0a7efff35a416df46ce001

Open Evidence Manifest

Review Run and MergeGuard

Prompt-only deterministic Review Run scoped to the refund-assistant prompt and its security policy evidence.

Recommendation: merge_after_changes. Policy approval requirements are definitions; current authority is shown by the evaluator above.

Verification evidence

State: Simulated · mode: Simulated.

  • Injection risk: high
  • Security score: 0
  • 6 deterministic security tests generated

Runner results and provenance

Plan verification-plan-d17b2a5528b4be7a · version verification-plan-v1 · persisted: false.

Internal metadata controls: 7. Repository commands run: 0. Independent verification: incomplete.

  • internal_evidence_envelope_validation · Passed Internal Control · System Control · production requirement false
  • internal_evidence_provenance_validation · Passed Internal Control · System Control · production requirement false
  • internal_policy_snapshot_consistency · Passed Internal Control · System Control · production requirement false
  • internal_capability_scope_consistency · Passed Internal Control · System Control · production requirement false
  • internal_changed_file_scope_validation · Passed Internal Control · System Control · production requirement false
  • internal_integrity_reference_consistency · Passed Internal Control · System Control · production requirement false
  • internal_scenario_isolation_validation · Passed Internal Control · System Control · production requirement false
  • prompt_security_runner · not run · Blocked Platform

Human verification remains separate and required. An internal-control pass does not prove code correctness or security.

Open Runner Plan

Human approval

Current effective state: Revocation Active.

A historical approval exists, but current authorization is revoked.

  • Current authorization is revoked.
  • Repository verification has not run.
  • Execution transport is disabled.
  • Dispatch remains disabled.

Approval requirement: Approval Revoked.

Policy requirement definition: A high-risk Review Run touches prompt-security policy and requires explicit human review.

Required role: Prompt-Security-Reviewer · evaluated at: 2026-08-12T05:01:25.462Z.

Historical/local request state: Pending · expiry: Not Expired.

Current next controlled action

Keep current authorization revoked. Current authorization is revoked. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

Evidence and gaps

10 available · 2 current evidence or verification gaps.

  • Human review of the suggested rewrite
  • Security-test results against the intended target

Historical fixture requirement: Explicit prompt-review approval. Current approval status is Approval Revoked.

Policy snapshot

policy-snapshot-d8a299d8 · version 1.0.0-demo

Matched rules: prompt-security-review

Current blockers: Current authorization is revoked. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled..

Current next: Keep current authorization revoked. Current authorization is revoked. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

Decision: Blocked Missing Verification · persisted: false

Open Policy Event

Capability package snapshot

capability-package-harden-risky-prompt-v1 · version task-capability-package-v1

State: Preview · authority issued: false · persisted: false

Repository: acme-ai-support/refund-assistant-prompts · branch: demo/harden-risky-prompt

Paths: directory:lib/prompts, directory:prompts

Tools: PromptForge deterministic analyzer, Read-only policy preview · network: disabled · secrets: none

Budget: $1.25 USD / 7,000 tokens / 20 minutes, deterministic demo estimate only.

Evaluated at: 2026-08-12T05:01:25.947Z · expiry: Not Expired · revocation: Not Revoked

Open Capability Snapshot

Ledger and analytics

PromptForge identified injection and tool-boundary gaps and produced a safer draft rewrite.

Ledger is derived and non-persistent; analytics remains preview-only.

Local-only Work Record actions

No local Work Record action has been applied.

Legacy preview completion eligible: no. Local actions cannot change verification evidence or current authority.

Connected control context

Real module destinations

Prompt contextAgent recommendationWorkflow planReview Run evidenceMergeGuard resultVerification evidenceRunner resultsHuman approvalPolicy contextCapability snapshotLedger recordAnalyticsJourneyWork Record detail
ForgeLayer - AI Software Teams. Controlled.