{
  "schemaVersion": 2,
  "date": "2026.08.05",
  "publishedAt": "2026-08-05T22:13:04-07:00",
  "timeZone": "America/Los_Angeles",
  "title": "Building Hiro's controlled internet-observation lane",
  "publicationStatus": "Validated and published",
  "executiveSummary": [
    "Reconciled Hiro's extensive existing working state into a clean, recoverable baseline commit and added local annotated pins for both the pre-observation baseline and the completed observation implementation.",
    "Implemented a disabled-by-default, exact-host, HTTPS-only observation client that supports only GET and HEAD, pins connections to prevalidated public IP addresses, revalidates every redirect, and enforces cumulative request, time, byte, redirect, port, query, and content limits.",
    "Implemented active-content removal, credential-shaped redaction, prompt-injection boundary handling, timestamped tamper-evident snapshot packets, mandatory human review before case creation, and paired baseline/candidate replay bound to the same frozen snapshot hash.",
    "The focused offline safety suite passed 62 tests and the complete Hiro suite passed all 374 tests. The implementation remains inactive with an empty allowlist, disabled policy, local observation DISABLED sentinel, zero snapshots, no promotion authority, and Stage 6 still disabled."
  ],
  "workstreams": [
    {
      "title": "Clean pinned Hiro baseline",
      "status": "Completed",
      "details": [
        "Audited 167 modified and untracked source, documentation, configuration-example, launcher, and test files accumulated across prior Hiro sessions.",
        "Excluded the ignored local environment, credentials, databases, logs, runtime state, generated benchmark data, pytest scratch directories, and a downloaded local tunnel executable.",
        "Scanned staged content for common credential and private-key patterns before committing; no matching secret material was found.",
        "Committed the reconciled state as dbcf4a5391ef7438c8f78f9a26c7c1e955a46e51 and created local annotated tag hiro-internet-observation-baseline-20260805. No existing source work was discarded."
      ]
    },
    {
      "title": "Read-only network authority",
      "status": "Implemented but disabled",
      "details": [
        "The versioned policy permits only GET and HEAD over HTTPS to exact fully qualified hostnames. Wildcards, IP literals, URL credentials, fragments, query parameters, nonstandard ports, and non-text response types are denied during probation version 1.",
        "Every DNS answer must be globally routable. Mixed public/private results fail closed, covering loopback, private, link-local, reserved, multicast, unspecified, and other non-global IPv4 and IPv6 ranges.",
        "The production transport connects directly to the validated IP while preserving the approved hostname for TLS certificate verification and the Host header, eliminating a normal second DNS lookup between validation and connection.",
        "Redirects are followed only after a fresh host, address, policy, and budget check. Cookies, Authorization headers, proxy inheritance, compression, uploads, posting, purchases, and state-changing methods are absent."
      ]
    },
    {
      "title": "Budgets and emergency controls",
      "status": "Implemented",
      "details": [
        "The client enforces independent maximums for total requests, cumulative downloaded bytes across redirects, total elapsed time, per-request timeout, redirects, response Content-Length, content type, port, and method.",
        "The policy must be explicitly enabled, must contain at least one approved exact domain, and must not have the local internet-observation DISABLED sentinel present before any request can begin.",
        "The shipped policy remains disabled with an empty allowlist, and the local observation sentinel remains present.",
        "Stage 6 has a separate DISABLED sentinel and remains unchanged. No observation component contains integration, deployment, or promotion authority."
      ]
    },
    {
      "title": "Sanitized frozen evidence",
      "status": "Implemented",
      "details": [
        "The required capture entrypoint retrieves one page and immediately sanitizes and freezes it; the CLI does not expose an unfrozen successful capture workflow.",
        "HTML scripts, styles, forms, inputs, embedded documents, active objects, and similar elements are removed. Credential-named JSON fields, credential-shaped values, control characters, and attempted snapshot boundary markers are redacted or neutralized.",
        "Each timestamped packet retains only sanitized text, safe response headers, redirect and address provenance, policy and content hashes, and explicit declarations that credentials, state changes, promotion, and Stage 6 authority were absent.",
        "The raw body is not persisted; its length and SHA-256 are recorded. The packet and sanitized content have independent SHA-256 checks, read-only file permissions, and verification before reuse."
      ]
    },
    {
      "title": "Reviewed replay cases",
      "status": "Implemented",
      "details": [
        "Retrieval never creates a pass/fail case automatically. A reviewer must affirm the finding and supply the task and explicit assertions.",
        "The case provider verifies the snapshot packet companion, sanitized content hash, packet hash, embedded snapshot text, untrusted marker, and frozen case companion.",
        "The isolated evaluator treats snapshot content as untrusted evidence and refuses role labels, tool requests, links, or instruction overrides inside the snapshot boundary.",
        "The paired replay runner independently reloads baseline and candidate case sets, proves identical sanitized snapshot hashes before execution, and verifies that both reports retain the same binding afterward."
      ]
    }
  ],
  "decisions": [
    "Use exact approved hosts rather than wildcard or suffix allowlisting during the first probation.",
    "Use direct validated-IP connections with hostname TLS verification to reduce DNS rebinding risk.",
    "Disallow query parameters and compressed responses in probation version 1 to reduce credential leakage and decompression risk.",
    "Persist sanitized evidence but not raw active response bodies.",
    "Require human review and explicit assertions before an observation becomes an evaluation case.",
    "Keep snapshot replay additive to existing public and held-out gates, with no automatic promotion.",
    "Do not select domains or remove the observation sentinel as part of implementation validation."
  ],
  "validation": [
    {
      "check": "Focused internet-observation and evaluator safety suite",
      "status": "passed",
      "result": "62 tests passed in 1.58 seconds using injected DNS and HTTP fixtures. Coverage includes disabled controls, exact-host policy, forbidden methods and URL forms, private IPv4/IPv6, mixed DNS, address pinning and hostname TLS, redirect and DNS revalidation, cumulative limits, active-content stripping, secret redaction, injection markers, tamper detection, mandatory review, and identical baseline/candidate snapshot bindings."
    },
    {
      "check": "Complete Hiro test suite",
      "status": "passed",
      "result": "374 tests passed in 143.61 seconds after converting a legacy sports performance test from a live external request to its existing mocked HTTP seam."
    },
    {
      "check": "External-request accounting",
      "status": "passed with disclosed legacy event",
      "result": "The new observation client made no public request and produced zero snapshots. During the first broad test attempt, an unrelated pre-existing sports test performed one read-only unauthenticated ESPN request after the focused adversarial suite had already passed; it exceeded its latency threshold. That test was made hermetic before the final full-suite run."
    },
    {
      "check": "Repository and disable state",
      "status": "passed",
      "result": "Implementation commit ffd6eba32308114b69da70921f84591d0089dc50 is clean and locally tagged hiro-internet-observation-ready-20260805. Policy enabled is false, approved-domain count is zero, the observation DISABLED sentinel exists, snapshot count is zero, and Stage 6 DISABLED exists."
    },
    {
      "check": "Hiro journal generation and frontend build",
      "status": "passed",
      "result": "The timestamped-entry test and production frontend build completed successfully before publication."
    }
  ],
  "currentState": [
    "Hiro's controlled internet-observation implementation is complete and offline-validated at ffd6eba32308114b69da70921f84591d0089dc50.",
    "The working tree is clean and both baseline and implementation have local annotated Git tags.",
    "Internet observation is inactive: the policy is disabled, the allowlist is empty, the observation sentinel is present, and no observation snapshot exists.",
    "Automatic promotion remains unavailable and Stage 6 remains disabled."
  ],
  "limitations": [
    "Exact public domains have not yet been selected or approved, so the probation cannot start.",
    "The snapshot packets are tamper-evident local files with read-only permissions and companion hashes, not protection against an administrator deliberately replacing both packet and companion.",
    "Prompt-injection indicators are heuristic; safety depends on structural authority separation and untrusted-content boundaries rather than perfect detection.",
    "The version 1 lane intentionally excludes authenticated, interactive, query-based, compressed, binary, and state-changing web workflows."
  ],
  "nextSteps": [
    "Select and document a very small list of exact public domains for the first shadow probation.",
    "Review the versioned request, time, byte, redirect, content, and snapshot limits for those domains.",
    "Make a separate launch decision that enables the observation policy and removes only the observation sentinel while retaining Stage 6 DISABLED.",
    "Begin with one low-budget GET/HEAD-only session, verify a frozen packet for every completed retrieval, and stop on any unexpected address, redirect, content, budget, integrity, or authority result.",
    "Review any resulting failure before converting it into a frozen replay case; do not automatically promote any candidate."
  ],
  "disclosureNote": "This public entry contains no credentials, private held-out cases, personal data, raw retrieved page content, or actionable details about unresolved security weaknesses."
}
