Skip to main content

Taint

Struct Taint 

Source
pub struct Taint {
    pub private: bool,
    pub untrusted: bool,
}
Expand description

What has entered this conversation so far.

The lethal trifecta only bites when all three are present at once: private data, untrusted content, and a way to send. Two of them are properties of the transcript, so they are tracked here; the third is a property of the tool about to run.

Fields§

§private: bool

A tool has returned data the user considers private.

§untrusted: bool

A tool has returned content a third party could have written — which is to say, possible instructions from an attacker.

Implementations§

Source§

impl Taint

Source

pub fn trifecta_armed(&self) -> bool

True once an outbound tool could be used to exfiltrate.

Source

pub fn arm_for_content(&mut self, messages: &[Message])

Arm the private leg for content that entered the conversation without a tool call — today, an image the user attached.

A screenshot is captured, not composed, and that is the whole argument. Inbound text arms nothing because the user chose every word of it; the same reasoning does not reach a screenshot, where the user chose the window and not everything in it. Incidental private data is the normal case rather than the exception — it is most of why people screenshot instead of retyping.

It also keeps the posture of an unchanged user action unchanged. Before images existed, attaching one in Slack armed private because the model had to fs_read it; putting the pixels on the user turn removed the tool call and, with it, the taint. A feature that silently loosens the interlock as a side effect is the shape this project keeps finding, and the fix belongs here rather than in a note asking front-ends to remember.

Source

pub fn merge(&mut self, other: Taint)

Trait Implementations§

Source§

impl Clone for Taint

Source§

fn clone(&self) -> Taint

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for Taint

Source§

impl Debug for Taint

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Taint

Source§

fn default() -> Taint

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for Taint
where Taint: Default,

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for Taint

Source§

impl PartialEq for Taint

Source§

fn eq(&self, other: &Taint) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for Taint

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for Taint

Auto Trait Implementations§

§

impl Freeze for Taint

§

impl RefUnwindSafe for Taint

§

impl Send for Taint

§

impl Sync for Taint

§

impl Unpin for Taint

§

impl UnsafeUnpin for Taint

§

impl UnwindSafe for Taint

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more