Instruction file imported from cemini23/Cybersecurity-wiki (
.cursor/rules/cemini-cybersec-k-dual-id.mdc). Copyright stays with the author.
Cybersec dual-ID (owned overlay)
Federation cemini-phase1-policy-wires.mdc is global-only (~/.cursor/rules/). Cybersec dual-ID collisions are listed here and in .cursor/rules/overlays/cybersec-k-dual-id.fragment.mdc. CI: python3 scripts/restore_cybersec_dual_id.py --check.
Do not delete the fragment file. When adding a new collision, update both this rule and the fragment; run --check.
- K282 ARENA-audio (2608.15578) ≠ CCC AgentRewind
- K283 JailbreakSkill (2608.16465) ≠ CCC Twin
- K288 ESTI (2608.16806) = same paper as CCC K288; cyber-primary
- K290 CHIVE (2608.16747) ≠ CCC K290 excess-authority (2608.18351)
- K295 Fool's Gold (2608.17202) ≠ CCC K295 Hybrid HAI
- K296 Trusted Workflow Relays (2608.17361) ≠ CCC K296 Thinkingbox
- K297 TI→detection (2608.19011) ≠ CCC K297 RL-Trotter
- K298 Inadvertent Context Leakage (2608.19857) ≠ CCC K298 Task-CoEvolve ≠ Trident K244 ≠ UrbanAgent K244
- K299 TrustRAG committee RAG (2608.20097) ≠ CCC K299 MidTool ≠ Zhou/HuichiZhou 2501.00879
- K300 BreakGuard LLM dependency tests (2608.20167) ≠ ProgrammerNomad Windows BreakGuard
- K301 CLEAR (2608.21278) — no global LoRA as proof of safety
- K302 PsychJail (2608.23028) — lab only; no wiki payloads; NO-GO clone
- K303 CLAUDE.md-vs-deny (2608.23550) — NL rules ≠ built-in deny; hooks at
.cursor/hooks.json - K304 SDP/RIM (2608.23497) — reasoning FT is a safety event
- K305 BT-NFT (2608.22754) — pairing ≠ authorization; owned-device lab only
- K306 LLM-compliance (2608.21317) — HITL; artifacts are candidates
- K307 StepGuard (2608.24777) ≠ CCC MediSkill-Evo K307 — step-level guard; LICENSE pending
- K308 decorative CoT (2608.24790) ≠ CCC MetaCaster K308 — CoT ≠ evidence
- K309 prompt security redistribution (2608.24857) ≠ CCC Prime Agent K309
- K310 RTLGuard (2608.26049) ≠ CCC K310 AP2 — poisoned-RTL teacher-student sanitize; no public repo
- K311 CTF-ABACUS (2608.26237) ≠ CCC K311 SCOUT — trace-verified CTF agent eval; flag ≠ exploit
- K312 LoopHarness / safety-does-not-compose (2608.27141) ≠ CCC K312 StepGuard (Cybersec StepGuard remains K307) — non-decaying loop state
- K313 RedEvoAgent (2608.27439) ≠ CCC K313 StarHarness — same paper as CCC K324; lab only
- K314 Recognition–enforcement gap (2608.28502) ≠ CCC K314 Recuris — model arbitration ≠ external reference monitor; no attack templates in wiki
- K315 Security-agent SLR (2608.28490) ≠ CCC K315 ToolMinimize — bounded authority / auditable behavior taxonomy; survey REFERENCE
- K316 SIR CUA IPI (2608.30207) ≠ CCC K316 LifePlanner — failure-driven adaptive IPI red-team; deterministic VM oracle
- K317 EvoSkill Injection (2608.30429) ≠ CCC K317 TAU-Agent — skill-generation pipeline attack surface; no malicious trajectories in wiki
- K318 J-lens (2608.31084) ≠ CCC K318 ProgRouter — multi-token SAE readout audit; not enforcement
- K319 BLOOM-WILT (2608.31105) ≠ CCC K319 AsymSpec — logit-tilting rare-behaviour audit; repo license null HOLD
- K320 EvoFlint (2609.00487) ≠ CCC K320 Claude Code handbook — multi-turn evolutionary red-team atlas
- K321 Guardrail construct validity (2609.01519) ≠ CCC K321 ASIL — protocol isolation before guardrail claims
- K322 Firmware rehosting peripherals (2608.29737) ≠ CCC K322 MoRe — embedded lab peripheral fidelity
- K323 CodePoisonRAG (2609.02774) ≠ CCC K323 intent-as-a-tool — upstream RACG knowledge poisoning; lab only
- K324 SafeEvolve (2609.02786) ≠ CCC K324 RedEvoAgent — harness-policy co-evolution; HITL on harness/skill writes
- K325 Linguistic illegibility (2609.02852) ≠ CCC K325 security-agent SLR — NL self-report not complete security boundary
- K326 C²T-OpenMax WiFi RF (2609.02007) — open-set WiFi CSI fingerprinting; authorized RF lab
- K327 Black-box agentic red-team (2609.09647) — taxonomy-driven multi-step eval; no attack payloads in wiki
- K328 RAG-Safety-Bench (2609.11758) — retrieval-conditioned safety eval; pairs K323
- K329 SpecGuard (2609.11799) — inference-time backdoor detection; no trigger payloads in wiki
- K330 BlueSTAR (2609.11852) — tiered defensive agent architecture; bounded authority audit
- K331 PrivEscalate (2609.09087) — LLM Linux priv-esc bench; authorized lab only
- K332 Conformal prediction offensive (2609.05165) — CP intervals for offensive eval reporting
- K335 LLM decompiler fidelity (2609.05370) — recompilability vs semantic preservation
- K336 SENTINEL-RL SOC (2609.04159) — topological reasoning offload for SOC agents
- K337 Explanation necessity/sufficiency (2609.05385) — behavioural explanation audit
- K338 SIDE sensor impersonation (2609.06271) — edge IoT sequence-prediction detection
- K339 Zero-trust robotic fleets (2609.05741) — OT/ROS 2 attestation + timing watermark
- K340 Cyber-range IR agents (2609.16541) — autonomous network incident response eval
- K341 Secure AI-powered pentest agents (2609.16694) — pentest agent threats/guardrails/architecture
- K342 Multi-conversation persuasion robustness (2609.16777) — refusal-inertia-aware eval
- K343 Chain-of-self-questioning abstention (2609.17516) — CoSQ selective risk control
- K344 Through-wall detection SDR (2609.12443) — ambient WiFi CSI TWD; authorized RF lab
- K345 Indirect third-party sensor tracking (2609.18173) — sparse indirect vehicle tracking
- K346 CASHEWS malicious package preprocessor (2609.18862) — npm supply-chain LLM detection
- K347 ASLEval privacy exposure displacement (2609.18864) — session-level agent privacy eval
K300–K347 Cybersec entries in this overlay are Cybersec IDs, not the CCC K300–K324 wave.