# Mithril Dojo — Video Production Pack

## Delivered MP4 lessons

Three short explainers are included in `assets/dojo/` and published beside the Dojo page. Each has Japanese synthetic narration (macOS Kyoko / ja-JP), an original animated diagram treatment, burned-in Japanese captions, a selectable WebVTT caption track, and a poster image.

| Episode | Duration | Video | Captions |
| --- | ---: | --- | --- |
| Permission is the first control | 49.3 s | `episode-01.mp4` | `episode-01.vtt` |
| Make the agent safe | 49.0 s | `episode-02.mp4` | `episode-02.vtt` |
| Produce verifiable Proof | 50.7 s | `episode-03.mp4` | `episode-03.vtt` |

The editable source and build recipe are `scripts/build-dojo-videos.py`. On macOS with Python 3, Pillow, NumPy, `say`, and FFmpeg available, run `python3 scripts/build-dojo-videos.py` from the repository root to regenerate the MP4s, captions, and posters. Set `DOJO_JA_VOICE` to another installed Japanese macOS voice if needed.

## Narration and storyboard

The sections below are the source narration and visual timing notes. Visuals use fictional scope sheets, synthetic labels, and conceptual diagrams; no real targets, exploit payloads, credentials, or customer data appear.

## Episode 1 — Permission is the first control

**Scene 1:** Boundary diagram: an explicitly named training lab inside a bright allow boundary, all other systems outside.

**Narration:** “The first thing to check is not an attack technique. Who authorized what, against which target? A white-hat researcher begins by making the boundary clear.”

**Scene 2:** Five scope fields appear: target, method, time window, exclusions, stop contact. The incomplete authorization card remains paused.

**Narration:** “The authorization should name the target, methods, time window, exclusions, data rules, and stop contact. A phrase like ‘all company systems’ is too vague to begin.”

**Scene 3:** An agent suggestion passes through a policy gate and a synthetic-target allowlist. An out-of-scope branch is visibly blocked.

**Narration:** “Apply the target list to the agent mechanically. Do not rely on a prompt alone; use an allowlist in the execution environment to block out-of-scope requests.”

**Scene 4:** A pause indicator routes to an owner for clarification, then returns to the exercise only after the boundary is complete.

**Narration:** “When something is unclear, stop and ask the approver instead of testing to find out. Pausing is also a correct security decision.”

## Episode 2 — Make the agent safe before making it useful

**Scene 1:** Model, tools, memory, and human decision nodes connect around an agent boundary.

**Narration:** “An AI agent is more than its text. Protect it as a system made of a model, tools, memory, access, execution environment, and human decisions.”

**Scene 2:** Tool cards collapse to the minimum: synthetic lab, read-only access, short-lived session, no secrets.

**Narration:** “Start with the smallest useful set of capabilities. Use a disposable isolated environment, read-only access, short-lived permissions, and network access limited to synthetic targets. Keep secrets out of the conversation.”

**Scene 3:** Untrusted document input is separated from the policy channel; a malicious instruction is shown as inert data, without payload text.

**Narration:** “Treat web pages and tickets as untrusted data. Even if they contain instructions, they must not rewrite the agent’s policy or expand its authorized scope.”

**Scene 4:** A human approval gate blocks a side-effecting action until reviewed; the next allowed step is confined to the synthetic lab.

**Narration:** “Require human approval for actions with side effects. Enforce that gate in the runtime, not only in the prompt.”

## Episode 3 — Produce verifiable Proof

**Scene 1:** Two columns separate an agent’s confident claim from evidence that can be inspected.

**Narration:** “A confident agent answer is not yet a fact. Separate what you observed, what you infer, and what you still do not know.”

**Scene 2:** A ledger fills with claim, source, time, reproduction condition, confidence, and redaction fields.

**Narration:** “Record each claim, its source and time, the reproduction conditions, and your confidence. Remove personal information, secrets, and unrelated logs.”

**Scene 3:** Three connected Proof criteria appear: reproducibility, completeness, safety. The safety node blocks a real-system action.

**Narration:** “Good Proof can be checked by another reviewer, includes the necessary context, and is safe. Never affect a real system or third party just to earn a score.”

**Scene 4:** Evidence flows through a private disclosure channel to a mitigation owner and a bounded retest.

**Narration:** “Finish with an evidence-based impact statement, a practical mitigation, an owner, and retest criteria. Use the authorized private channel and record the fix review.”

## Delivery requirements

- Keep all displayed UI, names, logs, and hostnames synthetic. Do not show working attack code or real credentials.
- The generated clips use Japanese speech and burned captions; WebVTT files provide a selectable caption track.
- For future localization, add reviewed English narration and subtitle tracks. Do not machine-translate policy language without review.
- The narration is synthetic, not a human instructor endorsement. The lessons do not certify a learner or guarantee security outcomes.
