Lesson 6 / 6 · 2 minute read
Prove the fix and its limits
Turn observations into a reproducible, accurately scoped result.
Export an evidence record containing the action, outcome, defense, controls, and remaining uncertainty.
- 01Baseline
- 02Attack
- 03Observed effect
- 04Defense
- 05Attack + benign checks
Make the objective observable
Define success as a protected value being returned, a canary being received, or an unauthorized state change being committed. Record the execution mode and scenario version. A scripted action proves a permission boundary’s behaviour; it does not establish that a language model can be persuaded to issue that action.
Compare equivalent conditions
Run the original attack against the modified control, then include additional variants and legitimate tasks. Replaying recorded tool requests tests the boundary against those requests. A fresh model run tests a different question: how the model behaves with the modified application.
State the remaining uncertainty
Include preconditions, the finite suite, relevant versions, and limitations. Avoid publishing private data or real credentials in reports. Our exports contain synthetic sandbox data and remain on your device unless you choose to share them.
Check your understanding
What does a successful deterministic defense suite establish?
Lesson completion is a self-recorded learning milestone on this device. Lab results are tracked separately.
Put it into practice
Make the boundary observable.
Start with an explicit action in the guided sandbox. Then explore the related mission’s execution mode and evidence.
Sources and further reading
These sources inform the concepts. Our examples and sandbox scenarios are original and synthetic.
OWASP LLM Top 10 — 2025 taxonomy ↗