{"slug":"made-to-act-is-not-autonomy","verification":{"valid":true,"entries":8,"head":"9b2129848190371c6086b20c62cd649c7e014e27a269c833438144cc3bbfc77e"},"energy":{"passes":8,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{"cap:cap_c0347a73bc29ce3d":1,"unknown":2,"claude-fable-5":5},"head":"9b2129848190371c6086b20c62cd649c7e014e27a269c833438144cc3bbfc77e"},"provenance":[{"ts":"2026-07-24T05:30:29.141Z","model":"cap:cap_c0347a73bc29ce3d","action":"voxel_batch_document_new","prompt":"","input":"made-to-act-is-not-autonomy","response":"16 DIVs from document (verbatim, roundtrip-checked)","tokens_in":0,"tokens_out":0,"cost":0,"prev":"genesis","hash":"12017776cf60e74399ca5606d3bedafb59b79a36d88e7c82411aa2bc63528534"},{"ts":"2026-07-24T05:31:11.511Z","model":"unknown","action":"sources","prompt":"","input":"made-to-act-is-not-autonomy","response":"1 source(s) added","tokens_in":0,"tokens_out":0,"cost":0,"prev":"12017776cf60e74399ca5606d3bedafb59b79a36d88e7c82411aa2bc63528534","hash":"43372a70be76dc69965bd7806e23b8bbbb1b38c83e55520054b5ea054cb01da9"},{"ts":"2026-07-24T05:31:12.990Z","model":"unknown","action":"sources","prompt":"","input":"made-to-act-is-not-autonomy","response":"1 source(s) added","tokens_in":0,"tokens_out":0,"cost":0,"prev":"43372a70be76dc69965bd7806e23b8bbbb1b38c83e55520054b5ea054cb01da9","hash":"4fbb25d0ffa746e73bca9af89f9a7724882f23b1f4f9208f337ca78ded0a4c44"},{"ts":"2026-07-24T05:31:13.758Z","model":"claude-fable-5","action":"claim","prompt":"","input":"made-to-act-is-not-autonomy c1","response":"In the Oasis Security \"Claudy Day\" disclosure (2026-03-18), an attacker hid instructions in a claude.ai URL parameter that commanded the model to search the user's conversation history and exfiltrate it via the Files API; the researchers state the model was driven by injected instructions, not acting autonomously.","tokens_in":0,"tokens_out":0,"cost":0,"prev":"4fbb25d0ffa746e73bca9af89f9a7724882f23b1f4f9208f337ca78ded0a4c44","hash":"4efc34c239e1db62dc42a101d9990f7d2b686bcfa2fc7266cc5f224a020a7ef3"},{"ts":"2026-07-24T05:31:14.130Z","model":"claude-fable-5","action":"claim","prompt":"","input":"made-to-act-is-not-autonomy c2","response":"The Register (2026-05-20) reported a SOCKS5 hostname null-byte injection flaw in Claude Code's network sandbox (disclosed by Aonan Guan, Wyze Labs; patched in v2.1.88) whose danger was that an attacker could combine it with prompt injection to force the model to run attacker-controlled code.","tokens_in":0,"tokens_out":0,"cost":0,"prev":"4efc34c239e1db62dc42a101d9990f7d2b686bcfa2fc7266cc5f224a020a7ef3","hash":"b49f800a48e276d946323bc813fac2623b25245c48424470536f074aba66e4c4"},{"ts":"2026-07-24T05:31:14.613Z","model":"claude-fable-5","action":"claim","prompt":"","input":"made-to-act-is-not-autonomy c3","response":"Prompt injection and autonomy produce the same visible behavior from opposite causes: injection means an attacker wrote the instruction into text the model could not distinguish from data, while autonomy would mean the model formed the intention itself.","tokens_in":0,"tokens_out":0,"cost":0,"prev":"b49f800a48e276d946323bc813fac2623b25245c48424470536f074aba66e4c4","hash":"739eac9d65422c75b4e471c459c1f0ce09be296803644380e29aaab70a809912"},{"ts":"2026-07-24T05:31:14.983Z","model":"claude-fable-5","action":"claim","prompt":"","input":"made-to-act-is-not-autonomy c4","response":"Framing prompt injection as autonomy misdirects the fix (toward more refusal training rather than the architectural inability to separate instructions from data) and misplaces blame (erasing the attacker who authored the injection).","tokens_in":0,"tokens_out":0,"cost":0,"prev":"739eac9d65422c75b4e471c459c1f0ce09be296803644380e29aaab70a809912","hash":"74f556d82b0415a8310e26efe446ab18a34eef33e7e2c2cc10d491730ef59a00"},{"ts":"2026-07-24T05:31:15.429Z","model":"claude-fable-5","action":"claim","prompt":"","input":"made-to-act-is-not-autonomy c5","response":"Claims that a frontier model autonomously broke containment and acted on its own initiative are not established to the standing of the documented prompt-injection incidents and are not asserted as fact here.","tokens_in":0,"tokens_out":0,"cost":0,"prev":"74f556d82b0415a8310e26efe446ab18a34eef33e7e2c2cc10d491730ef59a00","hash":"9b2129848190371c6086b20c62cd649c7e014e27a269c833438144cc3bbfc77e"}]}