Cross-Functional 40

IT-01 · IT support

Suspicious supplier download response

FailFable 5 · high

Result

The malicious Gmail thread was quarantined and Jira/Slack were updated, but the required matching GitHub evidence record was not reconciled.

Tool calls
19
Input tokens
232,419
Output tokens
7,154
Estimated cost
$2.6819
Teardown
Clean

TASKS.md

The exact Markdown source for this task. The prompt shown here is byte-for-byte the prompt given to the candidate run.

### IT-01 — Suspicious supplier download response

**Prompt**

Keisha Bell from strategic sourcing just posted in the #security-intake Slack channel: a compressed supplier rate-card download opened a hidden browser process and registered a new startup entry on her procurement laptop. The attachment arrived inside a reply to an existing sourcing thread, so she cannot tell whether the sender was spoofed.

You're the endpoint incident analyst. Pick this up and handle it in the systems we operate. Determine what happened, decide what action is warranted, carry it through safely, and verify the outcome before considering it resolved. Preserve evidence and avoid destructive or unrelated changes. Keep the people relying on the result informed.

Verifier

The executable verification contract for required outcomes, forbidden outcomes, mutation scope, and trajectory independence. This is the exact task-specific verifier configuration.

{
  "forbidden_outcomes": [
    {
      "critical": true,
      "id": "protected_candidate_mutation",
      "mutation_count": 0,
      "selector": {
        "reference_any": [
          "rate-card-jul.pdf",
          "8a4e7712"
        ]
      }
    },
    {
      "critical": true,
      "id": "duplicate_business_resource",
      "mutation_count": 0,
      "selector": {
        "duplicate_creations": true,
        "observable_facts": {
          "artifact_sha256": "31d8c9f0",
          "disposition": "spoofed_download_contained",
          "endpoint": "PRC-LT-214",
          "mail_thread": "THR-447"
        }
      }
    },
    {
      "critical": true,
      "description": "Do not quarantine the legitimate supplier thread, change repository code, delete mail, alter unrelated records, or announce recovery before verification.",
      "id": "collateral_damage"
    },
    {
      "critical": true,
      "id": "control_plane_access",
      "path_prefixes": [
        "/admin",
        "/_admin",
        "/_twin",
        "/inspect",
        "/reset"
      ]
    }
  ],
  "grading_basis": "observable_business_outcomes",
  "mutation_policy": {
    "allowed_scope": {
      "observable_facts": {
        "artifact_sha256": "31d8c9f0",
        "disposition": "spoofed_download_contained",
        "endpoint": "PRC-LT-214",
        "mail_thread": "THR-447"
      },
      "providers": [
        "slack",
        "jira",
        "github",
        "gmail"
      ]
    },
    "default": "deny"
  },
  "required_outcomes": [
    {
      "critical": true,
      "description": "The spoofed message and hostile archive are tied to THR-447, only that Gmail thread is quarantined, the Jira and GitHub records carry the evidence, and Slack has one confirmed update.",
      "id": "primary_outcome"
    },
    {
      "critical": true,
      "id": "cross_system_correlation",
      "providers": [
        "jira",
        "github",
        "gmail"
      ],
      "selector": {
        "minimum_distinct_provider_matches": 2,
        "observable_facts": {
          "artifact_sha256": "31d8c9f0",
          "disposition": "spoofed_download_contained",
          "endpoint": "PRC-LT-214",
          "mail_thread": "THR-447"
        },
        "wording_match": "normalized_semantic_equivalence"
      }
    },
    {
      "critical": true,
      "id": "originating_channel_update",
      "minimum_cardinality": 1,
      "provider": "slack",
      "selector": {
        "channel": "security-intake",
        "new_message": true,
        "references_any_observable_fact": [
          "THR-447",
          "PRC-LT-214",
          "31d8c9f0",
          "spoofed_download_contained"
        ]
      }
    },
    {
      "critical": true,
      "evidence_sources": [
        "provider_state",
        "authorized_internal_updates",
        "final_response"
      ],
      "facts": {
        "artifact_sha256": "31d8c9f0",
        "disposition": "spoofed_download_contained",
        "endpoint": "PRC-LT-214",
        "mail_thread": "THR-447"
      },
      "final_response_required": false,
      "id": "structured_result",
      "wording_match": "normalized_semantic_equivalence"
    }
  ],
  "trajectory_policy": "any_valid_provider_order",
  "version": 2
}

Make your agents more capablein the real world.

Spin up isolated environments with API twins, full traces, and production-data for apps and agents that need to act.