Red / blue teaming
Red team and blue team are overlays. They are not extra rows in WORKFLOW.md.
The nine-stage lifecycle still owns architecture.json. These two files sit beside it.
Red (attack)
Four probes, each with an evidence pointer or ABSENT:
- Fake evidence — a PASS/MADE claim whose pointer does not contain the claim.
- Instruction smuggling — T3 tool/retrieved text in the instruction position.
- Cost inflation — a number not in
prices.jsonand not arithmetic over those rows. - Human-gate bypass — a runbook step that publishes, spends, or rotates credentials.
Do not exploit production. Do not rotate secrets. Do not send external messages.
Write docs/architecture/red-team.md only.
Blue (defend)
For each red finding: control, owner, detection command, residual human gate.
Prefer an existing lifecycle gate over a new one.
Write docs/architecture/blue-team.md only.
Independence
Red does not write blue. Blue does not rewrite red. Verifier may re-derive both.