Authority first
No scan, exploit validation or persistence without written scope, methods, timing, impact limits and a named restoring authority.Technical reachability is not consent.
Evaluation · AI
AI and machine-learning systems that generate code, call tools or chain steps are assets whose change alters exposure. Blackbook stages that action: unverified model output is an unmarked input, an unscoped tool is an undocumented grant, and ambiguity holds the write.
Overview
Reaper runs authorized evaluation under written Rules of Engagement. Blackbook supplies the staging law. AOS closes the run. The evaluation asks what a model can discover, reproduce and chain inside declared scope, what it cannot do, and what remains untested. Findings are recorded so another operator can reproduce them. Remediation is proven by retest. Mapping follows an ATT&CK-shaped threat language so a defender can place a result on a known matrix.
No scan, exploit validation or persistence without written scope, methods, timing, impact limits and a named restoring authority.Technical reachability is not consent.
Generated code, exploit sketches and tool arguments enter the ladder as candidate material.Presence, integrity, context and a recorded transform precede any mutating call. Fluency does not promote.
Prompt-to-tool paths are scoped openings.Approval class is declared per risk. Writes outside jurisdiction fail closed into HOLD. If revocation of a tool would confuse the run, the grant was already too wide.
Impact of models on known-class weaknesses is measured inside scope.Unpublished zero-days are not a public claim. Unknowns that block a tier-one decision hold the test.
Results are placed against known adversary techniques so a defender can use them.Naming is deterministic. Interpretation does not enter the artifact.
Under rising load, change windows narrow and logging intensifies.When integrity of the test surface is unverifiable, the lane moves to incident: freeze non-essential change, mark facts separately from unknowns, then recover only with closure proof.
A ticket status is not a closed residual path.Closure is a scoped retest with before and after state, actor, and next review.
Blackbox preserves actor, scope, artifact hashes, toolchain version and the condition that would reopen the work.Re-verification does not require the originating model.
Proof
This lane supports Daybreak-class defensive and authorized red-team evaluation. It is not permission to probe Mediator or third-party systems.