A randomized stream of agentic threats. Every few seconds a new agent submits an out-of-scope action. Watch the substrate detect, deny, and emit a portable proof.
The Attack Arena is a supporting expression of Verification, the discipline that renders the independent verdict. Verification is the act of a third party re-checking an artifact offline — trusting no one — and returning valid or invalid. In this arena, each denial you see is a verdict rendered: the substrate re-checks the requested action against a signed authority envelope and rejects what falls outside it. A rejection is a negative verdict, and refusing a tampered or out-of-scope artifact is part of the trust model — not a claim that the system is unbreakable.
Why this exists: agentic systems act faster than humans can review. Verification lets any party confirm, after the fact and without trusting the operator, that an action was denied for a stated, re-checkable reason. Verification does not produce the evidence (that is H33-74), does not record or monitor it (HATS), does not govern the decision (Agent-008), and does not score maturity (HICS). It only renders the verdict.
An independent verdict on each requested action. The substrate re-checks the action against the signed authority envelope and returns a result — here, a denial. The denial is the verdict; the portable proof lets a third party re-check that verdict offline, trusting no one.
No. A denial means the arena rendered a negative verdict against one artifact — it reproduced and rejected an out-of-scope request for a stated reason. Refusal is part of the trust model, but it is not a claim of being tamper-proof or 100% secure. Security, correctness, and compliance are separate properties, not implied by any single verdict.
H33-74 produces the evidence — the portable, signed artifact. Verification renders the verdict on that artifact by re-checking it. This arena is a Verification surface: it does not mint the proof, it re-checks and decides. Governing the underlying decision belongs to Agent-008; recording and monitoring belong to HATS.
Use it to see what a rendered verdict looks like and to build intuition for the rejection reasons. The stream shown here is an illustrative sample simulation — synthetic attacks, not a live breach feed. To render verdicts against downloadable artifacts yourself, use the Drop-Test Artifacts and the External Review bundle.