Skip to project details
Back to workEZZY RAPPEPORTGet in touch

Agent security / Team project

MonkeyClaw

A security finding you can follow.

On a three-person team, I worked on the path from sandbox events to reproducible evidence: telemetry ingestion, transcript replay, and the dashboard.

Engineering Contributor2026

Recorded demo fixtureSBX-FS

MC-2026-0001

A backup request crossed the sandbox boundary.

Finding confirmedReproduction saved
Trigger
filesystem_breach
Replay
1 request
Next boundary
No patch recorded

Selected fields from the public mock-sandbox fixture. This is an evidence summary, not a live dashboard.

01 / One finding

A routine request. An observable failure.

The request was to save a backup. In the deterministic demo, the mock victim wrote beyond its allowed workspace. The useful result was a finding that could be inspected and replayed.

  1. Keep the triggering requests.

    The original transcript contains two requests: a report backup and a log export. The fixture preserves those requests alongside the evidence.

  2. Confirm the side effect.

    A programmatic filesystem_breach check records writes outside the permitted workspace. The demo uses a controlled escape directory; these are mock-sandbox results.

  3. Reduce it to a replay.

    Package MC-2026-0001 retains one request and a cold-verification flag. A finding summary alone would not preserve enough detail to repeat it.

  4. Stop where the evidence stops.

    The package is marked for patching. This fixture contains no completed patch or linked patch-verification result.

Inspect the recorded fixture

02 / My contribution

Make the evidence survive the handoff.

Replay the actual transcript.

The original reproduction path reconstructed an attack from its summary, which could lose the request that caused the failure. I changed it to persist and replay the actual attacker transcript, and repaired the demo’s sandbox watching and cold-verification path.

The tradeoffA deterministic mock makes the workflow repeatable without credentials. It remains a controlled demonstration, with different evidence requirements from a live deployment.

My reproduction changes

Normalize events at the boundary.

I added an adapter for native OpenClaw hook events. It maps the JSONL stream into the existing telemetry contract, resumes from its prior offset, and keeps the detection oracle independent of the source event format.

The tradeoffUnknown or malformed hook events are skipped and counted. Their absence must remain visible when interpreting detection coverage.

My telemetry adapter and tests

Let live data update without losing your place.

I changed the dashboard to skip unchanged section writes and preserve the reader’s position. I also added section navigation and a stale-connection notice so a live-looking screen could communicate when its data had stopped arriving.

The tradeoffThe dashboard tracks what has changed between responses. That extra state preserves scroll position and open detail sections during updates.

My dashboard changes

03 / The detection rule

A blocked attack tells half the story.

The detection oracle asks two separate questions: did the defense stop the attack, and did it leave evidence of detection? A block without observability gets a different result from a block with telemetry.

Explore the detection oracle

Change the two facts.

Detection scenario
WEAK

The attack was blocked, but there is no evidence that a detection fired.

Interactive explanation of the oracle’s four outcomes. It does not execute an attack or report a live test.

All four outcomes
PASS
Blocked and observed.
WEAK
Blocked, without detection evidence.
PARTIAL
Observed, but not blocked.
FAIL
Neither blocked nor observed.
The four-outcome oracle
Oracle logic and end-to-end verification are separate

This control explains the oracle’s quadrant rule. The current patch-verification path can skip detection checks when evidence is missing or detection is disabled. An oracle PASS does not establish that every verification path enforces the same boundary.

Detection-gate implementation

04 / The boundary

Make every claim traceable.

This recorded example supports a confirmed finding and a saved reproduction. It does not establish a completed, verified fix.

The distinction matters to the product: a security dashboard needs to communicate the state of the evidence at each step. My work made the transcript, telemetry, and changing system state easier to carry through that workflow.

Explore the public demo documentation and the implementation behind this case study.

Read the demo guide
Next: from system evidence to everyday planning

FlowE