Shared runtime.
Separate context.
Describe abstract allow and deny boundaries, then generate direct, concurrent-switch and stale-session cases with synthetic canary assertions. This is a test-design artifact—not a scanner—and it never connects to an agent, reads memory or executes a tool.
Cross-context boundary matrix
| Case | Mode / boundary | Source → target | Expected | Synthetic canary assertion |
|---|
Generated assertions are only a plan. A passing test proves only the fixture and harness behavior you actually ran; it does not prove tenant isolation, prevent prompt injection, inspect memory, certify security or cover production concurrency.
Agent security boundary: all rules are processed in this browser; a paid pack receives only abstract labels, synthetic canaries and expected assertions. Do not enter production prompts, responses, memory content, traces, source code, tenant or user identifiers, credentials, tokens, endpoints or confidential tool arguments. The tool does not connect to a runtime, invoke an agent or tool, read memory, fuzz a target, exploit a system, validate sandboxing or certify isolation. Authorized engineers must implement fixtures, run them in an approved environment and review failures.
$5 / 10 Isolation matrix credits
Each credit generates an editable batch test pack containing the entered boundary contract, deterministic direct/concurrency/stale/cleanup cases, synthetic canary assertions, implementation checklist and human signoff. Runtime execution remains in your own authorized harness.
- user, tenant, task, thread, memory and tool boundary contract
- direct allow/deny assertion cases
- concurrency-switch and stale-session variants
- synthetic canary and cleanup assertions
- authorized harness, failure and deletion signoff
Primary isolation guidance and strong runtime substitutes
PMF pre-judgment 76/100 · cross-context leakage is costly, while framework isolation and red-team suites remain strong substitutes