sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

Lab 06: the grant that cannot be enumerated

Every capability written up here so far had a grant you could tabulate — a scope with a published list, and a delta whose length was the finding. This one does not, and saying so breaks a measure this site has been building on.

Seven load-bearing quotations were fetched and checked rather than relayed. Among them, a vendor stating plainly that “using WebFetch alone doesn't prevent network access”, that “permission rules are enforced by Claude Code, not by the model”, that the strict allow list “has no effect” when set in a repository, and that the sandbox “shows a warning and runs commands without sandboxing” if it cannot start. We also read the published reference container firewall line by line: it is a genuine default-deny egress firewall that nonetheless permits name resolution to any address, secure shell to any address, a code host's full address ranges, and the entire /24 around the host — which on a laptop is the office network.

Two departures from the brief, both stated on the page. It reports observing an agent's two egress paths diverge in one session; in ours they did not, and the finding therefore rests on the vendor's own sentences rather than on that observation. And in its place we published a measurement of this machine's own egress: a raw outbound socket to an arbitrary public address, working name resolution, and no allow list standing in either path. A page arguing that the barrier is a property of the deployment should say what its own deployment does.

The brief register now carries six documents and four instructions, with D6 marked partly — Lab 06 exists, and the two proposals it makes to the model site are not yet on the request list in Lab 03↗.