CAIN-42 hardening round, 2026-09-21 (public summary; generated from the bundle's own data) Status: PRE-PRODUCTION. Self-attested: the same operator runs the system, the tests and the signing key. Attack types exercised: 114; blocked: 97; succeeded: 0; inconclusive: 17. Each handler runs against a real control with an honest-path control, and mutation tests show it reports success when its defence is removed. Defects found by attacking our own controls (each has a regression test; see defect-ledger.json): - [evaluation fabric] Contamination scan never awaited its HTTP calls: the model was never queried and every scan passed. - [evaluation fabric] Evaluation report crashed on a missing import; contaminated or mostly-ERROR agents could still pass. - [evaluation fabric] The contamination endpoint fetched caller-supplied URLs (SSRF); now public http(s) only. - [benchmark suite] Hard-coded 'sustained load completed, 0.0% errors' result; 0 ms latency reported for no samples; wrong percentiles. - [predictive trust envelope] Envelope bypass via NaN, empty entry or bare prefix; expiry ignored; hard-coded 'actual' risk; no envelope treated as in-bounds. - [daily synchronizer] DNS check reported 'points here' when both lookups failed (empty string equals empty string). - [execution boundary] A parameter-tampered attempt burned the token's nonce; the legitimate call was then rejected as a replay. - [temporal trust] Trust recovery was unpaced: 100 positive events in 100 s took every dimension from 0.20 to 0.91. - [MCP proxy] A principal could self-sign a capability for any tool its identity was never granted. - [security-context verifier] Fail-open: only 6 named checks could deny, so a read/report context was allowed for delete/payroll_db under a different intent. - [security-context verifier] The audience field was stored but never verified. - [adversarial worker] Reported RESILIENT while attack types had no handler; now INCOMPLETE unless every attack is conclusive. - [attack handlers] Context handlers verified a test-local stand-in that could not fail, and a replay branch recorded the nonce before checking it. Rebuilt against the production verifier, which exposed the two verifier bugs above. - [security-context API] Module failed to import and was never mounted, so its routes were dead code. Import fixed; deliberately not mounted pending an authentication review. - [signup fallback] The billing-outage fallback response implied a working key; it now states registered:false / provisional:true. - [attack engine] 19 of 114 attacks had been counted BLOCKED because their verifier raised an error (missing table or module, a dict-iteration bug) or had no target: a crash is not a defence. Errored attacks are now INCONCLUSIVE; the honest result is 97 blocked, 17 inconclusive, 0 succeeded. The two tool/MCP substitution attacks now run against a real control. - [MCP tool metadata] No control existed for tool-poisoning or rug-pull changes in tools/list replies. Added and wired in (implementation not published). Withheld on purpose: source code, file paths, module and class names. This bundle proves outcomes, not implementation. See REPRODUCE.txt for how to validate the bundle and what it does not show.