# Mithril Dojo — Video Scripts and Storyboard (English)

## Localization status

The three published MP4s currently have Japanese narration and burned-in Japanese captions. Japanese WebVTT captions are selectable. This file provides reviewed English scripts and storyboard notes; English audio/video is not yet produced. Do not describe the MP4s as English-localized.

## Episode 01 — Authorization is the first security control

**Target duration:** about 49 seconds.  
**Narration:** “A request to ‘check security’ is not authorization. Before any review, confirm who approved it, which assets are in scope, what methods are permitted, the time window, exclusions, data rules, stop contact, and reporting channel. If any boundary is missing or unclear, stop and ask. An AI agent cannot create permission, and a tool suggestion cannot expand scope. Safe research begins with a written boundary.”

**Storyboard:** request card appears → missing fields highlight → agent suggestion is paused → completed scope card → stop/ask decision.

## Episode 02 — Constrain the agent before it helps

**Target duration:** about 50 seconds.  
**Narration:** “An AI agent can turn a suggestion into an action. Give it only the tools the approved task needs. Start read-only, isolate untrusted input, restrict network access, and use short-lived access. Require a person to approve side effects. Log decisions and define a stop condition. In training, use synthetic data and an isolated exercise. If the task needs broader access, pause and obtain explicit authorization first.”

**Storyboard:** tool belt narrows → read-only shield → untrusted text separated → human approval gate → synthetic lab boundary.

## Episode 03 — Build verifiable Proof

**Target duration:** about 51 seconds.  
**Narration:** “A useful security report separates what you observed from what you infer. Preserve the source, time, reproduction conditions, and uncertainty. Include only the minimum sanitized evidence another reviewer needs. Do not run a risky payload to make a report look stronger. State the defensive impact carefully, propose an owner and acceptance condition, then retest only inside the approved scope. Good Proof is reproducible, complete enough, and safe.”

**Storyboard:** event log → fact and inference split → minimal evidence packet → defensive fix → bounded retest.
