CyberMindSpace LABSTalk to us ↗
CYBERMINDSPACE LABS / AI-SECURITY

The attack surface is the whole system.

Explore security across models, retrieval, agents, tools and infrastructure.

PROPOSED / RESEARCH
TRUST BOUNDARY / EXPORT CONTROLLOCAL SYNTHETIC FIXTURE

One record.
One prohibited action.

A support reader may summarize public material. It may not export the protected record CRM-042.

No live model or infrastructure. The fixture deliberately includes a vulnerable control path.

READY TO EVALUATE

Set the conditions.
Run the experiment.

Changing a condition clears the previous result. Each run evaluates the selected configuration.

FROM PROMPT TO SYSTEM

Follow the
trust boundary.

Each generation adds a measurable system effect. These are planned research stages.

GENERATION 01

LLM

System instruction → direct injection → synthetic disclosure

GENERATION 02

RAG

Protected corpus → poisoned retrieval → data leakage

GENERATION 03

AGENT + TOOLS

Identity → adversarial input → unauthorized tool behavior

GENERATION 04

MULTI-SYSTEM

Application → agent → tools → cloud → controls

OBSERVE / EVALUATE

See the attack as a system.

EVIDENCE INSPECTOR / RUN FIXTURE-042SYNTHETIC RECEIPTS
EVENT / e01 · 1 OF 5

Initial state verified

Tenant A · support_reader · synthetic record CRM-042; public summary task available.

event_id: e01
parent_event_id: none
source: harness
run_id: fixture-042

Parent links are declared by this fixture. In production, each link must be supported by trusted propagation and resource identifiers; timestamps alone are insufficient.

WEB SECURITY / OBJECT AUTHORIZATIONWORKING BROWSER EXERCISE
AUTHENTICATED USER / ALICE

Who owns the record?

Read your record, then change the ID from 1042 to 1043. Enable the authorization check and repeat the same request.

The response and finding will appear here.

BUILD THE RESEARCH WITH US

The next experiment
starts with a question.

Register your interest ↗