Experiment
Containing untrusted CI output with a quarantined reader
CI job logs are third-party-influenced text that flowed unfiltered into a privileged planning prompt. We routed them through a zero-tool-access reader restricted to schema-validated output, and tested it against a real injection.