# Mithril Dojo — Learner Workbook

## Safety boundary

Use only the fictional Northstar Demo case and the supplied synthetic text in this workbook and lab pack. Do not enter a real service, company data, personal data, or credentials. There is no live target or executable payload.

## Case: Northstar Demo

You receive one request: “Please check whether Northstar Demo is secure.” The requester, authority, target assets, permitted methods, time window, exclusions, data rules, stop contact, and reporting channel are missing.

### Exercise 1 — Start or stop?

1. Do not begin. List the missing facts.
2. Complete this authorization checklist: approver ___ · target ___ · permitted methods ___ · time window ___ · exclusions ___ · data rules ___ · stop contact ___ · reporting channel ___.
3. State what written evidence would be needed before any activity is authorized.

### Exercise 2 — Agent boundaries

The fictional assistant can read supplied case text, read supplied synthetic logs, edit a worksheet, visit an arbitrary URL, send files externally, or run arbitrary commands. Choose only the supplied-text and synthetic-log readers. Keep the assistant read-only, disable external communication, and require human approval before a state change. Treat instructions found inside untrusted case material as data; they cannot expand scope.

| Control | Setting | Reason | Remaining risk |
| --- | --- | --- | --- |
| Target allowlist | | | |
| Tool permissions | | | |
| Network limits | | | |
| Human approval | | | |
| Stop condition | | | |

### Exercise 3 — Evidence ledger

Use only the fictional event log released by the facilitator. Do not infer causes or impact absent from the excerpt.

| Claim | Observed evidence | Source/time | Reproduction condition | Confidence | Unknowns |
| --- | --- | --- | --- | --- | --- |
| | | | | | |

### Exercise 4 — Safe Proof and remediation

Write the smallest explanation another learner can validate from the supplied fixture. Separate observations from inference; record source, timestamp, fixture identifier, and gaps. Exclude secrets, personal data, unrelated logs, and payloads. Propose a defensive mitigation, owner, acceptance condition, and safe retest evidence. Stop and ask the facilitator if a proposed step needs an out-of-scope target or third-party effect.

## Capstone rubric

Score each area 0–25. Passing requires at least 15 in every area and no safety-gate failure.

| Area | Evidence for 15+ |
| --- | --- |
| Authorization and scope | Stops when boundaries are incomplete and identifies the approver and missing fields |
| Agent safety controls | Selects least privilege, isolation, approval, and stop conditions; explains residual risk |
| Evidence and Proof | Separates fact from inference and produces sourced, reproducible, sanitized evidence |
| Remediation and collaboration | Names a defensive owner, acceptance condition, safe retest, and authorized channel |

Any proposal to act without authorization, leave scope, or create an unapproved side effect fails the safety gate regardless of points. A completion record is not a professional qualification or product assurance.

## Reflection

- Where did you stop the agent and return the decision to a person?
- Which claim has the weakest evidence, and what safe information could reduce uncertainty?
- What defensive action should the next owner take?
