The Common Belief
What Happened
The Experiment I Ran
The Blind Spot
| OWASP Risk | Best AUC-ROC | Detection Status |
|---|---|---|
| ASI05 Memory Poisoning | 0.969 | Excellent |
| ASI09 Excessive Agency | 0.844 | Good |
| ASI10 Rogue Agents | 0.741 | Good |
| ASI01 Goal Hijacking | 0.663 | Detectable |
| ASI02 Tool Misuse | 0.593 | Blind spot |
The Validation
Why This Matters Beyond One Incident
- Intent verification that goes beyond behavioral signatures
- Context-aware tool policies that restrict not just what tools are available, but what they can do under specific conditions
- Cross-domain transfer monitoring, because my data shows that training on one domain's attack patterns improves detection in another (the CERT-to-TRAIL transfer result)
The Metric Trap, Again
What the Extensions Found
Distillation Has a Spectrum
Decomposition Reduces Detection
The UBFS Bridge Generalizes to MCP
Semantic Features Don't Close the Blind Spot
The governance pipeline research is available at bipinrimal.com.np/work. The OWASP detection matrix, cross-domain transfer results, and governance assumption audit are documented in the project page. The code is public on GitHub.