Skills
Branch the agent's context to read untrusted data instead of tainting it — exfiltration drops from 31–50% to 0–7%
APPA replaces permanent context contamination with engine-managed context branching: when an agent is about to acquire unvetted data, the system prospectively evaluates the label change, spawns an isolated trajectory to inspect the data, and returns only a bounded derivative through a trusted sanitizer to an unchanged parent context. Formally it's a two-monoid algebra over security labels and shared event logs, with Authorize/Accept remedy plans. Attack suppression is the headline — exfiltration success falls from 31–50% to 0–7% — but the more interesting result for builders is that on three of four models the branching recovered utility that ordinary taint tracking destroys.
↳ Follow the thread