Executive summary
Hiro's candidate pipeline no longer treats ordinary programming features, response invariants, scope mismatches, or construction errors as terminal safety failures.
Candidate patches remain expressive inside isolated experiment scope. Functional quality is decided by targeted proof plus public and held-out baseline-versus-candidate comparisons.
Security now has a separate baseline-versus-candidate adversarial gate focused on prompt injection, unauthorized execution and tool use, untrusted-content handling, credential and network boundaries, and related boundary bypasses.
The implementation is committed at revision 4d7730b. A focused suite passed 109 tests, a later focused confirmation passed 81 tests, and the complete Hiro suite passed 675 tests in 197.41 seconds. Hiro was not restarted.