105  Security, Trust, and Warding Words

106 Security, Trust, and Warding Words

Range: 0969-1063.

106.1 Completion

Status Count
authored 95

Use the summary table for scanning. Each row links to the detailed anchored entry below.

Sigil Term Completion Semantic Summary
0969 ABAC authored generated_draft ABAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ABAC obligation named before work proceeds.
0970 access control authored generated_draft access control is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the access control obligation named before work proceeds.
0971 account authored generated_draft account is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the account obligation named before work proceeds.
0972 ACL authored generated_draft ACL is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ACL obligation named before work proceeds.
0973 allowlist authored generated_draft allowlist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the allowlist obligation named before work proceeds.
0974 attestation authored reviewed A proof that a thing is what it claims to be or was produced the way it claims. It matters most when trust cannot be assumed.
0975 audit authored generated_draft audit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the audit obligation named before work proceeds.
0976 authenticate authored reviewed Prove who is making the claim before deciding what the claimant may do. Shadow: trusting names that have not earned entrance.
0977 authentication authored generated_draft authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the authentication obligation named before work proceeds.
0978 authorization authored reviewed After identity is known, what acts are permitted? Shadow: accidental omnipotence hidden behind a successful login.
0979 availability authored generated_draft availability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the availability obligation named before work proceeds.
0980 bearer token authored generated_draft bearer token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the bearer token obligation named before work proceeds.
0981 blast radius authored generated_draft blast radius is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blast radius obligation named before work proceeds.
0982 blocklist authored generated_draft blocklist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blocklist obligation named before work proceeds.
0983 boundary defense authored generated_draft boundary defense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the boundary defense obligation named before work proceeds.
0984 capability {Sec} authored generated_draft capability in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the capability obligation named before work proceeds.
0985 certificate {Sec} authored generated_draft certificate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the certificate obligation named before work proceeds.
0986 challenge authored generated_draft challenge is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the challenge obligation named before work proceeds.
0987 cipher authored generated_draft cipher is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cipher obligation named before work proceeds.
0988 claim authored generated_draft claim is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the claim obligation named before work proceeds.
0989 client secret authored generated_draft client secret is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the client secret obligation named before work proceeds.
0990 code signing authored reviewed Cryptographically bind an artifact to a trusted producer.
0991 compliance authored generated_draft compliance is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the compliance obligation named before work proceeds.
0992 confidentiality authored generated_draft confidentiality is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the confidentiality obligation named before work proceeds.
0993 credential {Sec} authored generated_draft credential in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the credential obligation named before work proceeds.
0994 cross-site scripting authored generated_draft cross-site scripting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cross-site scripting obligation named before work proceeds.
0995 cryptographic nonce authored generated_draft cryptographic nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cryptographic nonce obligation named before work proceeds.
0996 CSRF authored generated_draft CSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the CSRF obligation named before work proceeds.
0997 decrypt {Sec} authored generated_draft decrypt in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the decrypt obligation named before work proceeds.
0998 defense in depth authored reviewed Stack multiple protective layers so one failure is not total failure.
0999 deny-by-default authored generated_draft deny-by-default is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the deny-by-default obligation named before work proceeds.
1000 digest {Sec} authored generated_draft digest in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the digest obligation named before work proceeds.
1001 enclave authored generated_draft enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the enclave obligation named before work proceeds.
1002 encrypt {Sec} authored reviewed Make plaintext unreadable without the right key.
1003 entropy authored generated_draft entropy is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the entropy obligation named before work proceeds.
1004 exfiltration authored generated_draft exfiltration is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exfiltration obligation named before work proceeds.
1005 exploit authored generated_draft exploit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exploit obligation named before work proceeds.
1006 harden authored generated_draft harden is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the harden obligation named before work proceeds.
1007 hash {Sec} authored reviewed Arbitrary input reduced to a fixed fingerprint. Use it for identity, integrity, bucketing, and change detection; never mistake it for secrecy.
1008 HMAC authored generated_draft HMAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the HMAC obligation named before work proceeds.
1009 identity authored generated_draft identity is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the identity obligation named before work proceeds.
1010 incident authored generated_draft incident is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the incident obligation named before work proceeds.
1011 injection authored generated_draft injection is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the injection obligation named before work proceeds.
1012 integrity authored reviewed Confidence that data has not been silently altered.
1013 isolate {Sec} authored generated_draft isolate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the isolate obligation named before work proceeds.
1014 key {Sec} authored reviewed The secret or public material that makes cryptographic operations possible.
1015 key exchange authored generated_draft key exchange is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the key exchange obligation named before work proceeds.
1016 key rotation authored reviewed Replace active keys before age or compromise turns them rotten.
1017 least privilege authored reviewed Give only the authority required for the present act, no more. It is one of the simplest words for reducing future regret.
1018 login authored generated_draft login is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the login obligation named before work proceeds.
1019 mTLS {Sec} authored generated_draft mTLS in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mTLS obligation named before work proceeds.
1020 mutual authentication authored generated_draft mutual authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mutual authentication obligation named before work proceeds.
1021 nonce authored generated_draft nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the nonce obligation named before work proceeds.
1022 passkey authored generated_draft passkey is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the passkey obligation named before work proceeds.
1023 password authored generated_draft password is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the password obligation named before work proceeds.
1024 patch {Sec} authored generated_draft patch in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the patch obligation named before work proceeds.
1025 pepper authored generated_draft pepper is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the pepper obligation named before work proceeds.
1026 permission {Sec} authored generated_draft permission in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the permission obligation named before work proceeds.
1027 phishing authored generated_draft phishing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the phishing obligation named before work proceeds.
1028 policy authored reviewed The declared rule by which a class of cases is decided. Good policy reduces arbitrary judgment; bad policy merely freezes confusion.
1029 principal authored generated_draft principal is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the principal obligation named before work proceeds.
1030 private key authored generated_draft private key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the private key obligation named before work proceeds.
1031 privilege escalation authored generated_draft privilege escalation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the privilege escalation obligation named before work proceeds.
1032 proof of possession authored generated_draft proof of possession is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the proof of possession obligation named before work proceeds.
1033 public key authored generated_draft public key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the public key obligation named before work proceeds.
1034 quarantine authored generated_draft quarantine is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the quarantine obligation named before work proceeds.
1035 rate limiting authored generated_draft rate limiting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rate limiting obligation named before work proceeds.
1036 replay attack authored generated_draft replay attack is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the replay attack obligation named before work proceeds.
1037 revocation authored reviewed The act of withdrawing trust from credentials or keys.
1038 role {Sec} authored generated_draft role in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the role obligation named before work proceeds.
1039 root of trust authored generated_draft root of trust is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the root of trust obligation named before work proceeds.
1040 rotate authored generated_draft rotate is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rotate obligation named before work proceeds.
1041 salt authored generated_draft salt is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the salt obligation named before work proceeds.
1042 sandbox {Sec} authored reviewed Constrain code inside a smaller, safer prison.
1043 scope {Sec} authored generated_draft scope in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the scope obligation named before work proceeds.
1044 secret {Sec} authored reviewed Information whose power comes from staying hidden.
1045 secure enclave authored generated_draft secure enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the secure enclave obligation named before work proceeds.
1046 security boundary authored generated_draft security boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the security boundary obligation named before work proceeds.
1047 session fixation authored generated_draft session fixation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session fixation obligation named before work proceeds.
1048 session token authored generated_draft session token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session token obligation named before work proceeds.
1049 sign {Sec} authored generated_draft sign in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the sign obligation named before work proceeds.
1050 signature {Sec} authored reviewed Identity or intent made checkable through cryptographic proof. Useful wherever trust must survive distance and replay.
1051 single sign-on authored generated_draft single sign-on is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the single sign-on obligation named before work proceeds.
1052 spoofing authored generated_draft spoofing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the spoofing obligation named before work proceeds.
1053 SSRF authored generated_draft SSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the SSRF obligation named before work proceeds.
1054 threat model authored reviewed A structured view of likely attackers, assets, and failure paths.
1055 token {Sec} authored generated_draft token in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the token obligation named before work proceeds.
1056 trust anchor authored generated_draft trust anchor is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust anchor obligation named before work proceeds.
1057 trust boundary authored generated_draft trust boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust boundary obligation named before work proceeds.
1058 validate {Sec} authored generated_draft validate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the validate obligation named before work proceeds.
1059 verification {Sec} authored generated_draft verification in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the verification obligation named before work proceeds.
1060 vulnerability authored generated_draft vulnerability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the vulnerability obligation named before work proceeds.
1061 ward authored generated_draft ward is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ward obligation named before work proceeds.
1062 webhook signing authored generated_draft webhook signing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the webhook signing obligation named before work proceeds.
1063 zero trust authored reviewed Assume no network location or ambient context deserves automatic trust.

106.2 Entries

106.2.1 [0969] ABAC

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: ABAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ABAC obligation named before work proceeds.

Shadow: misusing ABAC at rune 0969 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name ABAC when the prompt needs this obligation made explicit: ABAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ABAC obligation named before work proceeds.
  • Ask the assistant to state the ABAC shadow before proposing changes.

Example clause:

Before editing, state the ABAC obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.2 [0970] access control

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: access control is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the access control obligation named before work proceeds.

Shadow: misusing access control at rune 0970 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name access control when the prompt needs this obligation made explicit: access control is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the access control obligation named before work proceeds.
  • Ask the assistant to state the access control shadow before proposing changes.

Example clause:

Before editing, state the access control obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.3 [0971] account

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: account is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the account obligation named before work proceeds.

Shadow: misusing account at rune 0971 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name account when the prompt needs this obligation made explicit: account is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the account obligation named before work proceeds.
  • Ask the assistant to state the account shadow before proposing changes.

Example clause:

Before editing, state the account obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.4 [0972] ACL

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: ACL is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ACL obligation named before work proceeds.

Shadow: misusing ACL at rune 0972 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name ACL when the prompt needs this obligation made explicit: ACL is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ACL obligation named before work proceeds.
  • Ask the assistant to state the ACL shadow before proposing changes.

Example clause:

Before editing, state the ACL obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.5 [0973] allowlist

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: allowlist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the allowlist obligation named before work proceeds.

Shadow: misusing allowlist at rune 0973 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name allowlist when the prompt needs this obligation made explicit: allowlist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the allowlist obligation named before work proceeds.
  • Ask the assistant to state the allowlist shadow before proposing changes.

Example clause:

Before editing, state the allowlist obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.6 [0974] attestation

Status: canonical (major canon, pocket canon)

Completion: authored

Semantic status: reviewed

Force: A proof that a thing is what it claims to be or was produced the way it claims. It matters most when trust cannot be assumed.

Shadow: when a signed claim is trusted without checking issuer, scope, freshness, or revocation.

Prompt uses:

  • Name attestation when the prompt needs this obligation made explicit: A proof that a thing is what it claims to be or was produced the way it claims. It matters most when trust cannot be assumed.
  • Ask the assistant to state the attestation shadow before proposing changes.

Example clause:

Before editing, state the attestation obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Evidence that a thing is what it claims to be or was produced the way it claims.

106.2.7 [0975] audit

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: audit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the audit obligation named before work proceeds.

Shadow: misusing audit at rune 0975 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name audit when the prompt needs this obligation made explicit: audit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the audit obligation named before work proceeds.
  • Ask the assistant to state the audit shadow before proposing changes.

Example clause:

Before editing, state the audit obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.8 [0976] authenticate

Status: canonical (major canon, pocket canon)

Completion: authored

Semantic status: reviewed

Force: Prove who is making the claim before deciding what the claimant may do.

Shadow: trusting names that have not earned entrance.

Prompt uses:

  • Name authenticate when the prompt needs this obligation made explicit: Prove who is making the claim before deciding what the claimant may do.
  • Ask the assistant to state the authenticate shadow before proposing changes.

Example clause:

Before editing, state the authenticate obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Prove who is making the claim.

106.2.9 [0977] authentication

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the authentication obligation named before work proceeds.

Shadow: misusing authentication at rune 0977 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name authentication when the prompt needs this obligation made explicit: authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the authentication obligation named before work proceeds.
  • Ask the assistant to state the authentication shadow before proposing changes.

Example clause:

Before editing, state the authentication obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.10 [0978] authorization

Status: canonical (major canon, pocket canon)

Completion: authored

Semantic status: reviewed

Force: After identity is known, what acts are permitted?

Shadow: accidental omnipotence hidden behind a successful login.

Prompt uses:

  • Name authorization when the prompt needs this obligation made explicit: After identity is known, what acts are permitted?
  • Ask the assistant to state the authorization shadow before proposing changes.

Example clause:

Before editing, state the authorization obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Decide what an already identified actor may do.

106.2.11 [0979] availability

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: availability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the availability obligation named before work proceeds.

Shadow: misusing availability at rune 0979 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name availability when the prompt needs this obligation made explicit: availability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the availability obligation named before work proceeds.
  • Ask the assistant to state the availability shadow before proposing changes.

Example clause:

Before editing, state the availability obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.12 [0980] bearer token

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: bearer token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the bearer token obligation named before work proceeds.

Shadow: misusing bearer token at rune 0980 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name bearer token when the prompt needs this obligation made explicit: bearer token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the bearer token obligation named before work proceeds.
  • Ask the assistant to state the bearer token shadow before proposing changes.

Example clause:

Before editing, state the bearer token obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.13 [0981] blast radius

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: blast radius is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blast radius obligation named before work proceeds.

Shadow: misusing blast radius at rune 0981 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name blast radius when the prompt needs this obligation made explicit: blast radius is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blast radius obligation named before work proceeds.
  • Ask the assistant to state the blast radius shadow before proposing changes.

Example clause:

Before editing, state the blast radius obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.14 [0982] blocklist

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: blocklist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blocklist obligation named before work proceeds.

Shadow: misusing blocklist at rune 0982 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name blocklist when the prompt needs this obligation made explicit: blocklist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blocklist obligation named before work proceeds.
  • Ask the assistant to state the blocklist shadow before proposing changes.

Example clause:

Before editing, state the blocklist obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.15 [0983] boundary defense

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: boundary defense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the boundary defense obligation named before work proceeds.

Shadow: misusing boundary defense at rune 0983 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name boundary defense when the prompt needs this obligation made explicit: boundary defense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the boundary defense obligation named before work proceeds.
  • Ask the assistant to state the boundary defense shadow before proposing changes.

Example clause:

Before editing, state the boundary defense obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.16 [0984] capability {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: capability in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the capability obligation named before work proceeds.

Shadow: misusing capability at rune 0984 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name capability when the prompt needs this obligation made explicit: capability in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the capability obligation named before work proceeds.
  • Ask the assistant to state the capability shadow before proposing changes.

Example clause:

Before editing, state the capability obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.17 [0985] certificate {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: certificate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the certificate obligation named before work proceeds.

Shadow: misusing certificate at rune 0985 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name certificate when the prompt needs this obligation made explicit: certificate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the certificate obligation named before work proceeds.
  • Ask the assistant to state the certificate shadow before proposing changes.

Example clause:

Before editing, state the certificate obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.18 [0986] challenge

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: challenge is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the challenge obligation named before work proceeds.

Shadow: misusing challenge at rune 0986 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name challenge when the prompt needs this obligation made explicit: challenge is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the challenge obligation named before work proceeds.
  • Ask the assistant to state the challenge shadow before proposing changes.

Example clause:

Before editing, state the challenge obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.19 [0987] cipher

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: cipher is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cipher obligation named before work proceeds.

Shadow: misusing cipher at rune 0987 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name cipher when the prompt needs this obligation made explicit: cipher is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cipher obligation named before work proceeds.
  • Ask the assistant to state the cipher shadow before proposing changes.

Example clause:

Before editing, state the cipher obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.20 [0988] claim

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: claim is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the claim obligation named before work proceeds.

Shadow: misusing claim at rune 0988 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name claim when the prompt needs this obligation made explicit: claim is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the claim obligation named before work proceeds.
  • Ask the assistant to state the claim shadow before proposing changes.

Example clause:

Before editing, state the claim obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.21 [0989] client secret

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: client secret is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the client secret obligation named before work proceeds.

Shadow: misusing client secret at rune 0989 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name client secret when the prompt needs this obligation made explicit: client secret is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the client secret obligation named before work proceeds.
  • Ask the assistant to state the client secret shadow before proposing changes.

Example clause:

Before editing, state the client secret obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.22 [0990] code signing

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Cryptographically bind an artifact to a trusted producer.

Shadow: misusing code signing at rune 0990 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name code signing when the prompt needs this obligation made explicit: Cryptographically bind an artifact to a trusted producer.
  • Ask the assistant to state the code signing shadow before proposing changes.

Example clause:

Before editing, state the code signing obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Cryptographically bind an artifact to a trusted producer.

106.2.23 [0991] compliance

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: compliance is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the compliance obligation named before work proceeds.

Shadow: misusing compliance at rune 0991 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name compliance when the prompt needs this obligation made explicit: compliance is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the compliance obligation named before work proceeds.
  • Ask the assistant to state the compliance shadow before proposing changes.

Example clause:

Before editing, state the compliance obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.24 [0992] confidentiality

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: confidentiality is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the confidentiality obligation named before work proceeds.

Shadow: misusing confidentiality at rune 0992 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name confidentiality when the prompt needs this obligation made explicit: confidentiality is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the confidentiality obligation named before work proceeds.
  • Ask the assistant to state the confidentiality shadow before proposing changes.

Example clause:

Before editing, state the confidentiality obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.25 [0993] credential {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: credential in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the credential obligation named before work proceeds.

Shadow: misusing credential at rune 0993 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name credential when the prompt needs this obligation made explicit: credential in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the credential obligation named before work proceeds.
  • Ask the assistant to state the credential shadow before proposing changes.

Example clause:

Before editing, state the credential obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.26 [0994] cross-site scripting

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: cross-site scripting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cross-site scripting obligation named before work proceeds.

Shadow: misusing cross-site scripting at rune 0994 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name cross-site scripting when the prompt needs this obligation made explicit: cross-site scripting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cross-site scripting obligation named before work proceeds.
  • Ask the assistant to state the cross-site scripting shadow before proposing changes.

Example clause:

Before editing, state the cross-site scripting obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.27 [0995] cryptographic nonce

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: cryptographic nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cryptographic nonce obligation named before work proceeds.

Shadow: misusing cryptographic nonce at rune 0995 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name cryptographic nonce when the prompt needs this obligation made explicit: cryptographic nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cryptographic nonce obligation named before work proceeds.
  • Ask the assistant to state the cryptographic nonce shadow before proposing changes.

Example clause:

Before editing, state the cryptographic nonce obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.28 [0996] CSRF

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: CSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the CSRF obligation named before work proceeds.

Shadow: misusing CSRF at rune 0996 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name CSRF when the prompt needs this obligation made explicit: CSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the CSRF obligation named before work proceeds.
  • Ask the assistant to state the CSRF shadow before proposing changes.

Example clause:

Before editing, state the CSRF obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.29 [0997] decrypt {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: decrypt in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the decrypt obligation named before work proceeds.

Shadow: misusing decrypt at rune 0997 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name decrypt when the prompt needs this obligation made explicit: decrypt in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the decrypt obligation named before work proceeds.
  • Ask the assistant to state the decrypt shadow before proposing changes.

Example clause:

Before editing, state the decrypt obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.30 [0998] defense in depth

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Stack multiple protective layers so one failure is not total failure.

Shadow: misusing defense in depth at rune 0998 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name defense in depth when the prompt needs this obligation made explicit: Stack multiple protective layers so one failure is not total failure.
  • Ask the assistant to state the defense in depth shadow before proposing changes.

Example clause:

Before editing, state the defense in depth obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Stack multiple protective layers so one failure is not total failure.

106.2.31 [0999] deny-by-default

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: deny-by-default is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the deny-by-default obligation named before work proceeds.

Shadow: misusing deny-by-default at rune 0999 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name deny-by-default when the prompt needs this obligation made explicit: deny-by-default is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the deny-by-default obligation named before work proceeds.
  • Ask the assistant to state the deny-by-default shadow before proposing changes.

Example clause:

Before editing, state the deny-by-default obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.32 [1000] digest {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: digest in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the digest obligation named before work proceeds.

Shadow: misusing digest at rune 1000 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name digest when the prompt needs this obligation made explicit: digest in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the digest obligation named before work proceeds.
  • Ask the assistant to state the digest shadow before proposing changes.

Example clause:

Before editing, state the digest obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.33 [1001] enclave

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the enclave obligation named before work proceeds.

Shadow: misusing enclave at rune 1001 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name enclave when the prompt needs this obligation made explicit: enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the enclave obligation named before work proceeds.
  • Ask the assistant to state the enclave shadow before proposing changes.

Example clause:

Before editing, state the enclave obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.34 [1002] encrypt {Sec}

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Make plaintext unreadable without the right key.

Shadow: misusing encrypt at rune 1002 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name encrypt when the prompt needs this obligation made explicit: Make plaintext unreadable without the right key.
  • Ask the assistant to state the encrypt shadow before proposing changes.

Example clause:

Before editing, state the encrypt obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Make plaintext unreadable without the right key.

106.2.35 [1003] entropy

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: entropy is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the entropy obligation named before work proceeds.

Shadow: misusing entropy at rune 1003 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name entropy when the prompt needs this obligation made explicit: entropy is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the entropy obligation named before work proceeds.
  • Ask the assistant to state the entropy shadow before proposing changes.

Example clause:

Before editing, state the entropy obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.36 [1004] exfiltration

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: exfiltration is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exfiltration obligation named before work proceeds.

Shadow: misusing exfiltration at rune 1004 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name exfiltration when the prompt needs this obligation made explicit: exfiltration is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exfiltration obligation named before work proceeds.
  • Ask the assistant to state the exfiltration shadow before proposing changes.

Example clause:

Before editing, state the exfiltration obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.37 [1005] exploit

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: exploit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exploit obligation named before work proceeds.

Shadow: misusing exploit at rune 1005 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name exploit when the prompt needs this obligation made explicit: exploit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exploit obligation named before work proceeds.
  • Ask the assistant to state the exploit shadow before proposing changes.

Example clause:

Before editing, state the exploit obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.38 [1006] harden

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: harden is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the harden obligation named before work proceeds.

Shadow: misusing harden at rune 1006 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name harden when the prompt needs this obligation made explicit: harden is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the harden obligation named before work proceeds.
  • Ask the assistant to state the harden shadow before proposing changes.

Example clause:

Before editing, state the harden obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.39 [1007] hash {Sec}

Status: canonical (major canon, pocket canon)

Completion: authored

Semantic status: reviewed

Force: Arbitrary input reduced to a fixed fingerprint. Use it for identity, integrity, bucketing, and change detection; never mistake it for secrecy.

Shadow: when hash equality is treated as meaning, authority, or secrecy it does not provide.

Prompt uses:

  • Name hash when the prompt needs this obligation made explicit: Arbitrary input reduced to a fixed fingerprint. Use it for identity, integrity, bucketing, and change detection; never mistake it for secrecy.
  • Ask the assistant to state the hash shadow before proposing changes.

Example clause:

Before editing, state the hash obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Reduce arbitrary input to a fixed fingerprint.

106.2.40 [1008] HMAC

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: HMAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the HMAC obligation named before work proceeds.

Shadow: misusing HMAC at rune 1008 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name HMAC when the prompt needs this obligation made explicit: HMAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the HMAC obligation named before work proceeds.
  • Ask the assistant to state the HMAC shadow before proposing changes.

Example clause:

Before editing, state the HMAC obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.41 [1009] identity

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: identity is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the identity obligation named before work proceeds.

Shadow: misusing identity at rune 1009 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name identity when the prompt needs this obligation made explicit: identity is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the identity obligation named before work proceeds.
  • Ask the assistant to state the identity shadow before proposing changes.

Example clause:

Before editing, state the identity obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.42 [1010] incident

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: incident is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the incident obligation named before work proceeds.

Shadow: misusing incident at rune 1010 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name incident when the prompt needs this obligation made explicit: incident is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the incident obligation named before work proceeds.
  • Ask the assistant to state the incident shadow before proposing changes.

Example clause:

Before editing, state the incident obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.43 [1011] injection

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: injection is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the injection obligation named before work proceeds.

Shadow: misusing injection at rune 1011 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name injection when the prompt needs this obligation made explicit: injection is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the injection obligation named before work proceeds.
  • Ask the assistant to state the injection shadow before proposing changes.

Example clause:

Before editing, state the injection obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.44 [1012] integrity

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Confidence that data has not been silently altered.

Shadow: misusing integrity at rune 1012 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name integrity when the prompt needs this obligation made explicit: Confidence that data has not been silently altered.
  • Ask the assistant to state the integrity shadow before proposing changes.

Example clause:

Before editing, state the integrity obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Confidence that data has not been silently altered.

106.2.45 [1013] isolate {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: isolate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the isolate obligation named before work proceeds.

Shadow: misusing isolate at rune 1013 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name isolate when the prompt needs this obligation made explicit: isolate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the isolate obligation named before work proceeds.
  • Ask the assistant to state the isolate shadow before proposing changes.

Example clause:

Before editing, state the isolate obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.46 [1014] key {Sec}

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: The secret or public material that makes cryptographic operations possible.

Shadow: misusing key at rune 1014 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name key when the prompt needs this obligation made explicit: The secret or public material that makes cryptographic operations possible.
  • Ask the assistant to state the key shadow before proposing changes.

Example clause:

Before editing, state the key obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: The secret or public material that makes cryptographic operations possible.

106.2.47 [1015] key exchange

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: key exchange is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the key exchange obligation named before work proceeds.

Shadow: misusing key exchange at rune 1015 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name key exchange when the prompt needs this obligation made explicit: key exchange is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the key exchange obligation named before work proceeds.
  • Ask the assistant to state the key exchange shadow before proposing changes.

Example clause:

Before editing, state the key exchange obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.48 [1016] key rotation

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Replace active keys before age or compromise turns them rotten.

Shadow: misusing key rotation at rune 1016 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name key rotation when the prompt needs this obligation made explicit: Replace active keys before age or compromise turns them rotten.
  • Ask the assistant to state the key rotation shadow before proposing changes.

Example clause:

Before editing, state the key rotation obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Replace active keys before age or compromise turns them rotten.

106.2.49 [1017] least privilege

Status: canonical (major canon, pocket canon)

Completion: authored

Semantic status: reviewed

Force: Give only the authority required for the present act, no more. It is one of the simplest words for reducing future regret.

Shadow: when roles accumulate exceptions until least privilege becomes a slogan.

Prompt uses:

  • Name least privilege when the prompt needs this obligation made explicit: Give only the authority required for the present act, no more. It is one of the simplest words for reducing future regret.
  • Ask the assistant to state the least privilege shadow before proposing changes.

Example clause:

Before editing, state the least privilege obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Grant only the authority required for the present act.

106.2.50 [1018] login

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: login is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the login obligation named before work proceeds.

Shadow: misusing login at rune 1018 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name login when the prompt needs this obligation made explicit: login is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the login obligation named before work proceeds.
  • Ask the assistant to state the login shadow before proposing changes.

Example clause:

Before editing, state the login obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.51 [1019] mTLS {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: mTLS in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mTLS obligation named before work proceeds.

Shadow: misusing mTLS at rune 1019 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name mTLS when the prompt needs this obligation made explicit: mTLS in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mTLS obligation named before work proceeds.
  • Ask the assistant to state the mTLS shadow before proposing changes.

Example clause:

Before editing, state the mTLS obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.52 [1020] mutual authentication

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: mutual authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mutual authentication obligation named before work proceeds.

Shadow: misusing mutual authentication at rune 1020 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name mutual authentication when the prompt needs this obligation made explicit: mutual authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mutual authentication obligation named before work proceeds.
  • Ask the assistant to state the mutual authentication shadow before proposing changes.

Example clause:

Before editing, state the mutual authentication obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.53 [1021] nonce

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the nonce obligation named before work proceeds.

Shadow: misusing nonce at rune 1021 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name nonce when the prompt needs this obligation made explicit: nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the nonce obligation named before work proceeds.
  • Ask the assistant to state the nonce shadow before proposing changes.

Example clause:

Before editing, state the nonce obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.54 [1022] passkey

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: passkey is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the passkey obligation named before work proceeds.

Shadow: misusing passkey at rune 1022 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name passkey when the prompt needs this obligation made explicit: passkey is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the passkey obligation named before work proceeds.
  • Ask the assistant to state the passkey shadow before proposing changes.

Example clause:

Before editing, state the passkey obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.55 [1023] password

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: password is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the password obligation named before work proceeds.

Shadow: misusing password at rune 1023 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name password when the prompt needs this obligation made explicit: password is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the password obligation named before work proceeds.
  • Ask the assistant to state the password shadow before proposing changes.

Example clause:

Before editing, state the password obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.56 [1024] patch {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: patch in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the patch obligation named before work proceeds.

Shadow: misusing patch at rune 1024 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name patch when the prompt needs this obligation made explicit: patch in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the patch obligation named before work proceeds.
  • Ask the assistant to state the patch shadow before proposing changes.

Example clause:

Before editing, state the patch obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.57 [1025] pepper

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: pepper is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the pepper obligation named before work proceeds.

Shadow: misusing pepper at rune 1025 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name pepper when the prompt needs this obligation made explicit: pepper is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the pepper obligation named before work proceeds.
  • Ask the assistant to state the pepper shadow before proposing changes.

Example clause:

Before editing, state the pepper obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.58 [1026] permission {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: permission in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the permission obligation named before work proceeds.

Shadow: misusing permission at rune 1026 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name permission when the prompt needs this obligation made explicit: permission in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the permission obligation named before work proceeds.
  • Ask the assistant to state the permission shadow before proposing changes.

Example clause:

Before editing, state the permission obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.59 [1027] phishing

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: phishing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the phishing obligation named before work proceeds.

Shadow: misusing phishing at rune 1027 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name phishing when the prompt needs this obligation made explicit: phishing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the phishing obligation named before work proceeds.
  • Ask the assistant to state the phishing shadow before proposing changes.

Example clause:

Before editing, state the phishing obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.60 [1028] policy

Status: canonical (major canon, pocket canon)

Completion: authored

Semantic status: reviewed

Force: The declared rule by which a class of cases is decided. Good policy reduces arbitrary judgment; bad policy merely freezes confusion.

Shadow: when policy text says one thing and enforcement code grants another.

Prompt uses:

  • Name policy when the prompt needs this obligation made explicit: The declared rule by which a class of cases is decided. Good policy reduces arbitrary judgment; bad policy merely freezes confusion.
  • Ask the assistant to state the policy shadow before proposing changes.

Example clause:

Before editing, state the policy obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: A declared rule for how a class of cases is decided.

106.2.61 [1029] principal

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: principal is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the principal obligation named before work proceeds.

Shadow: misusing principal at rune 1029 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name principal when the prompt needs this obligation made explicit: principal is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the principal obligation named before work proceeds.
  • Ask the assistant to state the principal shadow before proposing changes.

Example clause:

Before editing, state the principal obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.62 [1030] private key

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: private key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the private key obligation named before work proceeds.

Shadow: misusing private key at rune 1030 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name private key when the prompt needs this obligation made explicit: private key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the private key obligation named before work proceeds.
  • Ask the assistant to state the private key shadow before proposing changes.

Example clause:

Before editing, state the private key obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.63 [1031] privilege escalation

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: privilege escalation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the privilege escalation obligation named before work proceeds.

Shadow: misusing privilege escalation at rune 1031 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name privilege escalation when the prompt needs this obligation made explicit: privilege escalation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the privilege escalation obligation named before work proceeds.
  • Ask the assistant to state the privilege escalation shadow before proposing changes.

Example clause:

Before editing, state the privilege escalation obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.64 [1032] proof of possession

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: proof of possession is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the proof of possession obligation named before work proceeds.

Shadow: misusing proof of possession at rune 1032 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name proof of possession when the prompt needs this obligation made explicit: proof of possession is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the proof of possession obligation named before work proceeds.
  • Ask the assistant to state the proof of possession shadow before proposing changes.

Example clause:

Before editing, state the proof of possession obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.65 [1033] public key

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: public key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the public key obligation named before work proceeds.

Shadow: misusing public key at rune 1033 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name public key when the prompt needs this obligation made explicit: public key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the public key obligation named before work proceeds.
  • Ask the assistant to state the public key shadow before proposing changes.

Example clause:

Before editing, state the public key obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.66 [1034] quarantine

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: quarantine is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the quarantine obligation named before work proceeds.

Shadow: misusing quarantine at rune 1034 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name quarantine when the prompt needs this obligation made explicit: quarantine is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the quarantine obligation named before work proceeds.
  • Ask the assistant to state the quarantine shadow before proposing changes.

Example clause:

Before editing, state the quarantine obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.67 [1035] rate limiting

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: rate limiting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rate limiting obligation named before work proceeds.

Shadow: misusing rate limiting at rune 1035 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name rate limiting when the prompt needs this obligation made explicit: rate limiting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rate limiting obligation named before work proceeds.
  • Ask the assistant to state the rate limiting shadow before proposing changes.

Example clause:

Before editing, state the rate limiting obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.68 [1036] replay attack

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: replay attack is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the replay attack obligation named before work proceeds.

Shadow: misusing replay attack at rune 1036 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name replay attack when the prompt needs this obligation made explicit: replay attack is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the replay attack obligation named before work proceeds.
  • Ask the assistant to state the replay attack shadow before proposing changes.

Example clause:

Before editing, state the replay attack obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.69 [1037] revocation

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: The act of withdrawing trust from credentials or keys.

Shadow: misusing revocation at rune 1037 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name revocation when the prompt needs this obligation made explicit: The act of withdrawing trust from credentials or keys.
  • Ask the assistant to state the revocation shadow before proposing changes.

Example clause:

Before editing, state the revocation obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: The act of withdrawing trust from credentials or keys.

106.2.70 [1038] role {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: role in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the role obligation named before work proceeds.

Shadow: misusing role at rune 1038 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name role when the prompt needs this obligation made explicit: role in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the role obligation named before work proceeds.
  • Ask the assistant to state the role shadow before proposing changes.

Example clause:

Before editing, state the role obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.71 [1039] root of trust

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: root of trust is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the root of trust obligation named before work proceeds.

Shadow: misusing root of trust at rune 1039 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name root of trust when the prompt needs this obligation made explicit: root of trust is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the root of trust obligation named before work proceeds.
  • Ask the assistant to state the root of trust shadow before proposing changes.

Example clause:

Before editing, state the root of trust obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.72 [1040] rotate

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: rotate is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rotate obligation named before work proceeds.

Shadow: misusing rotate at rune 1040 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name rotate when the prompt needs this obligation made explicit: rotate is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rotate obligation named before work proceeds.
  • Ask the assistant to state the rotate shadow before proposing changes.

Example clause:

Before editing, state the rotate obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.73 [1041] salt

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: salt is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the salt obligation named before work proceeds.

Shadow: misusing salt at rune 1041 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name salt when the prompt needs this obligation made explicit: salt is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the salt obligation named before work proceeds.
  • Ask the assistant to state the salt shadow before proposing changes.

Example clause:

Before editing, state the salt obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.74 [1042] sandbox {Sec}

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Constrain code inside a smaller, safer prison.

Shadow: misusing sandbox at rune 1042 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name sandbox when the prompt needs this obligation made explicit: Constrain code inside a smaller, safer prison.
  • Ask the assistant to state the sandbox shadow before proposing changes.

Example clause:

Before editing, state the sandbox obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Constrain code inside a smaller, safer prison.

106.2.75 [1043] scope {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: scope in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the scope obligation named before work proceeds.

Shadow: misusing scope at rune 1043 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name scope when the prompt needs this obligation made explicit: scope in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the scope obligation named before work proceeds.
  • Ask the assistant to state the scope shadow before proposing changes.

Example clause:

Before editing, state the scope obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.76 [1044] secret {Sec}

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Information whose power comes from staying hidden.

Shadow: misusing secret at rune 1044 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name secret when the prompt needs this obligation made explicit: Information whose power comes from staying hidden.
  • Ask the assistant to state the secret shadow before proposing changes.

Example clause:

Before editing, state the secret obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Information whose power comes from staying hidden.

106.2.77 [1045] secure enclave

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: secure enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the secure enclave obligation named before work proceeds.

Shadow: misusing secure enclave at rune 1045 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name secure enclave when the prompt needs this obligation made explicit: secure enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the secure enclave obligation named before work proceeds.
  • Ask the assistant to state the secure enclave shadow before proposing changes.

Example clause:

Before editing, state the secure enclave obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.78 [1046] security boundary

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: security boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the security boundary obligation named before work proceeds.

Shadow: misusing security boundary at rune 1046 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name security boundary when the prompt needs this obligation made explicit: security boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the security boundary obligation named before work proceeds.
  • Ask the assistant to state the security boundary shadow before proposing changes.

Example clause:

Before editing, state the security boundary obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.79 [1047] session fixation

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: session fixation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session fixation obligation named before work proceeds.

Shadow: misusing session fixation at rune 1047 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name session fixation when the prompt needs this obligation made explicit: session fixation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session fixation obligation named before work proceeds.
  • Ask the assistant to state the session fixation shadow before proposing changes.

Example clause:

Before editing, state the session fixation obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.80 [1048] session token

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: session token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session token obligation named before work proceeds.

Shadow: misusing session token at rune 1048 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name session token when the prompt needs this obligation made explicit: session token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session token obligation named before work proceeds.
  • Ask the assistant to state the session token shadow before proposing changes.

Example clause:

Before editing, state the session token obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.81 [1049] sign {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: sign in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the sign obligation named before work proceeds.

Shadow: misusing sign at rune 1049 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name sign when the prompt needs this obligation made explicit: sign in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the sign obligation named before work proceeds.
  • Ask the assistant to state the sign shadow before proposing changes.

Example clause:

Before editing, state the sign obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.82 [1050] signature {Sec}

Status: canonical (major canon, pocket canon)

Completion: authored

Semantic status: reviewed

Force: Identity or intent made checkable through cryptographic proof. Useful wherever trust must survive distance and replay.

Shadow: when a valid signature is accepted outside its intended scope, time, or trust root.

Prompt uses:

  • Name signature when the prompt needs this obligation made explicit: Identity or intent made checkable through cryptographic proof. Useful wherever trust must survive distance and replay.
  • Ask the assistant to state the signature shadow before proposing changes.

Example clause:

Before editing, state the signature obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Identity or intent made checkable through cryptographic proof.

106.2.83 [1051] single sign-on

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: single sign-on is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the single sign-on obligation named before work proceeds.

Shadow: misusing single sign-on at rune 1051 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name single sign-on when the prompt needs this obligation made explicit: single sign-on is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the single sign-on obligation named before work proceeds.
  • Ask the assistant to state the single sign-on shadow before proposing changes.

Example clause:

Before editing, state the single sign-on obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.84 [1052] spoofing

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: spoofing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the spoofing obligation named before work proceeds.

Shadow: misusing spoofing at rune 1052 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name spoofing when the prompt needs this obligation made explicit: spoofing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the spoofing obligation named before work proceeds.
  • Ask the assistant to state the spoofing shadow before proposing changes.

Example clause:

Before editing, state the spoofing obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.85 [1053] SSRF

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: SSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the SSRF obligation named before work proceeds.

Shadow: misusing SSRF at rune 1053 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name SSRF when the prompt needs this obligation made explicit: SSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the SSRF obligation named before work proceeds.
  • Ask the assistant to state the SSRF shadow before proposing changes.

Example clause:

Before editing, state the SSRF obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.86 [1054] threat model

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: A structured view of likely attackers, assets, and failure paths.

Shadow: misusing threat model at rune 1054 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name threat model when the prompt needs this obligation made explicit: A structured view of likely attackers, assets, and failure paths.
  • Ask the assistant to state the threat model shadow before proposing changes.

Example clause:

Before editing, state the threat model obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: A structured view of likely attackers, assets, and failure paths.

106.2.87 [1055] token {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: token in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the token obligation named before work proceeds.

Shadow: misusing token at rune 1055 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name token when the prompt needs this obligation made explicit: token in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the token obligation named before work proceeds.
  • Ask the assistant to state the token shadow before proposing changes.

Example clause:

Before editing, state the token obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.88 [1056] trust anchor

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: trust anchor is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust anchor obligation named before work proceeds.

Shadow: misusing trust anchor at rune 1056 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name trust anchor when the prompt needs this obligation made explicit: trust anchor is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust anchor obligation named before work proceeds.
  • Ask the assistant to state the trust anchor shadow before proposing changes.

Example clause:

Before editing, state the trust anchor obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.89 [1057] trust boundary

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: trust boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust boundary obligation named before work proceeds.

Shadow: misusing trust boundary at rune 1057 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name trust boundary when the prompt needs this obligation made explicit: trust boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust boundary obligation named before work proceeds.
  • Ask the assistant to state the trust boundary shadow before proposing changes.

Example clause:

Before editing, state the trust boundary obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.90 [1058] validate {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: validate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the validate obligation named before work proceeds.

Shadow: misusing validate at rune 1058 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name validate when the prompt needs this obligation made explicit: validate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the validate obligation named before work proceeds.
  • Ask the assistant to state the validate shadow before proposing changes.

Example clause:

Before editing, state the validate obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.91 [1059] verification {Sec}

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: verification in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the verification obligation named before work proceeds.

Shadow: misusing verification at rune 1059 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name verification when the prompt needs this obligation made explicit: verification in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the verification obligation named before work proceeds.
  • Ask the assistant to state the verification shadow before proposing changes.

Example clause:

Before editing, state the verification obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.92 [1060] vulnerability

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: vulnerability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the vulnerability obligation named before work proceeds.

Shadow: misusing vulnerability at rune 1060 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name vulnerability when the prompt needs this obligation made explicit: vulnerability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the vulnerability obligation named before work proceeds.
  • Ask the assistant to state the vulnerability shadow before proposing changes.

Example clause:

Before editing, state the vulnerability obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.93 [1061] ward

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: ward is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ward obligation named before work proceeds.

Shadow: misusing ward at rune 1061 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name ward when the prompt needs this obligation made explicit: ward is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ward obligation named before work proceeds.
  • Ask the assistant to state the ward shadow before proposing changes.

Example clause:

Before editing, state the ward obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.94 [1062] webhook signing

Status: canonical

Completion: authored

Semantic status: generated_draft

Force: webhook signing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the webhook signing obligation named before work proceeds.

Shadow: misusing webhook signing at rune 1062 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name webhook signing when the prompt needs this obligation made explicit: webhook signing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the webhook signing obligation named before work proceeds.
  • Ask the assistant to state the webhook signing shadow before proposing changes.

Example clause:

Before editing, state the webhook signing obligation, the evidence that satisfies it, and the failure mode if it is missing.

106.2.95 [1063] zero trust

Status: canonical (pocket canon)

Completion: authored

Semantic status: reviewed

Force: Assume no network location or ambient context deserves automatic trust.

Shadow: misusing zero trust at rune 1063 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.

Prompt uses:

  • Name zero trust when the prompt needs this obligation made explicit: Assume no network location or ambient context deserves automatic trust.
  • Ask the assistant to state the zero trust shadow before proposing changes.

Example clause:

Before editing, state the zero trust obligation, the evidence that satisfies it, and the failure mode if it is missing.

Pocket gloss: Assume no network location or ambient context deserves automatic trust.