OpenAI incident analysis
NOT VERIFIEDNo verified API response loaded.
+ AUTONOMOUS CONTAINMENT & RECOVERY FOR AI AGENTS
Build AI incident readiness before it is needed. ESCAPE ROOM detects permission drift, verifies a boundary failure, and restores containment—with evidence at every step.
ENTER THE CONTAINMENT CHAMBER ↓One agent. Two boundaries. A recovery that has to prove itself.
The AI agent escaped its boundary, the agent detected it, restored the approved configuration on its own, and proved the recovery with the same probes.
No verified API response loaded.
No verified cloud receipt loaded.
No verified GitHub issue loaded.
DETECT → INVESTIGATE → DECIDE → CONTAIN → VERIFY → PREVENT → REPORT
Each scenario is a real run of the deterministic decision engine against disposable Docker sandboxes. The agent acts only through an allowlist, caps itself at two remediation attempts, and escalates when no permitted action can fix the failing condition.
THE RECEIPTS, NOT THE REASSURANCE
| ACT | CONTROLLED NETWORK | SYNTHETIC CANARY | POLICY / GATE |
|---|---|---|---|
| 01 SECURE | Awaiting evidence | Awaiting evidence | Not verified |
| 02 DRIFT | Awaiting evidence | Awaiting evidence | Not verified |
| 03 RECOVERY | Awaiting evidence | Awaiting evidence | Not verified |
Real rule IDs, files, and source lines appear here when a verified recording includes Semgrep output.
AN AUTONOMOUS LOOP, WITH BOUNDARIES
Detection is a signal. Recovery is a claim.
The same runtime tests connect the two.
Compare the sandbox to its approved baseline. Custom Semgrep rules flag unsafe configuration before the runtime probes begin.
POLICY DIFF + SEMGREPA controlled collector receipt proves network access. Reading the exact fake canary proves file exposure. Positive controls rule out broken tests.
REAL DOCKER PROBESRestore only the allowlisted configuration. Rerun both probes. Declare recovery only after the boundary holds again.
AUTONOMOUS STATE MACHINEA precise claim, deliberately bounded: two containment controls against disposable local targets. This is not a universal sandbox security certification.