Wizard Fortress

Fail closed

Security boundaries

Prompt text is not a security boundary. Anything a GPT sends is data. Authority lives in digest-bound human approval on the local control plane, which this site cannot reach.

Hard denies

Path / actionResult
/api/v1/execute and aliases403 FOREVER
approve / apply / promote / commit / pushnot in schema, 403 if probed
provider ids other than mockUNTRUSTED / DISABLED
auto_approve, silent fallback, role promotionrejected
file / shell / git handles for modelsnot exposed

Transport

Trust split

SurfaceTrust
This website + Pages FunctionsPublic, proposal-only, untrusted input
OpenAI GPT runtimeUntrusted client
Local Ara / Self-BuilderPrivate, HITL, not published here

Disclosure

See /.well-known/security.txt. Do not file public exploits against the tower. This site has no execution primitive to exploit into Ara unless someone later wires one — that wiring is forbidden without a separate reviewed gate.

Re-audit

Machine-readable checklist: /audit/checklist.json. Human copy: /audit/CHECKLIST.md. Run it after every DNS, header, schema, or function change. An agent loop may consume the JSON. It must not auto-apply fixes to Track A.