105 Security, Trust, and Warding Words
106 Security, Trust, and Warding Words
Range: 0969-1063.
106.1 Completion
| Status | Count |
|---|---|
| authored | 95 |
Use the summary table for scanning. Each row links to the detailed anchored entry below.
| Sigil | Term | Completion | Semantic | Summary |
|---|---|---|---|---|
| 0969 | ABAC | authored | generated_draft | ABAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ABAC obligation named before work proceeds. |
| 0970 | access control | authored | generated_draft | access control is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the access control obligation named before work proceeds. |
| 0971 | account | authored | generated_draft | account is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the account obligation named before work proceeds. |
| 0972 | ACL | authored | generated_draft | ACL is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ACL obligation named before work proceeds. |
| 0973 | allowlist | authored | generated_draft | allowlist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the allowlist obligation named before work proceeds. |
| 0974 | attestation | authored | reviewed | A proof that a thing is what it claims to be or was produced the way it claims. It matters most when trust cannot be assumed. |
| 0975 | audit | authored | generated_draft | audit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the audit obligation named before work proceeds. |
| 0976 | authenticate | authored | reviewed | Prove who is making the claim before deciding what the claimant may do. Shadow: trusting names that have not earned entrance. |
| 0977 | authentication | authored | generated_draft | authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the authentication obligation named before work proceeds. |
| 0978 | authorization | authored | reviewed | After identity is known, what acts are permitted? Shadow: accidental omnipotence hidden behind a successful login. |
| 0979 | availability | authored | generated_draft | availability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the availability obligation named before work proceeds. |
| 0980 | bearer token | authored | generated_draft | bearer token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the bearer token obligation named before work proceeds. |
| 0981 | blast radius | authored | generated_draft | blast radius is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blast radius obligation named before work proceeds. |
| 0982 | blocklist | authored | generated_draft | blocklist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blocklist obligation named before work proceeds. |
| 0983 | boundary defense | authored | generated_draft | boundary defense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the boundary defense obligation named before work proceeds. |
| 0984 | capability {Sec} | authored | generated_draft | capability in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the capability obligation named before work proceeds. |
| 0985 | certificate {Sec} | authored | generated_draft | certificate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the certificate obligation named before work proceeds. |
| 0986 | challenge | authored | generated_draft | challenge is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the challenge obligation named before work proceeds. |
| 0987 | cipher | authored | generated_draft | cipher is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cipher obligation named before work proceeds. |
| 0988 | claim | authored | generated_draft | claim is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the claim obligation named before work proceeds. |
| 0989 | client secret | authored | generated_draft | client secret is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the client secret obligation named before work proceeds. |
| 0990 | code signing | authored | reviewed | Cryptographically bind an artifact to a trusted producer. |
| 0991 | compliance | authored | generated_draft | compliance is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the compliance obligation named before work proceeds. |
| 0992 | confidentiality | authored | generated_draft | confidentiality is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the confidentiality obligation named before work proceeds. |
| 0993 | credential {Sec} | authored | generated_draft | credential in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the credential obligation named before work proceeds. |
| 0994 | cross-site scripting | authored | generated_draft | cross-site scripting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cross-site scripting obligation named before work proceeds. |
| 0995 | cryptographic nonce | authored | generated_draft | cryptographic nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cryptographic nonce obligation named before work proceeds. |
| 0996 | CSRF | authored | generated_draft | CSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the CSRF obligation named before work proceeds. |
| 0997 | decrypt {Sec} | authored | generated_draft | decrypt in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the decrypt obligation named before work proceeds. |
| 0998 | defense in depth | authored | reviewed | Stack multiple protective layers so one failure is not total failure. |
| 0999 | deny-by-default | authored | generated_draft | deny-by-default is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the deny-by-default obligation named before work proceeds. |
| 1000 | digest {Sec} | authored | generated_draft | digest in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the digest obligation named before work proceeds. |
| 1001 | enclave | authored | generated_draft | enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the enclave obligation named before work proceeds. |
| 1002 | encrypt {Sec} | authored | reviewed | Make plaintext unreadable without the right key. |
| 1003 | entropy | authored | generated_draft | entropy is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the entropy obligation named before work proceeds. |
| 1004 | exfiltration | authored | generated_draft | exfiltration is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exfiltration obligation named before work proceeds. |
| 1005 | exploit | authored | generated_draft | exploit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exploit obligation named before work proceeds. |
| 1006 | harden | authored | generated_draft | harden is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the harden obligation named before work proceeds. |
| 1007 | hash {Sec} | authored | reviewed | Arbitrary input reduced to a fixed fingerprint. Use it for identity, integrity, bucketing, and change detection; never mistake it for secrecy. |
| 1008 | HMAC | authored | generated_draft | HMAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the HMAC obligation named before work proceeds. |
| 1009 | identity | authored | generated_draft | identity is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the identity obligation named before work proceeds. |
| 1010 | incident | authored | generated_draft | incident is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the incident obligation named before work proceeds. |
| 1011 | injection | authored | generated_draft | injection is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the injection obligation named before work proceeds. |
| 1012 | integrity | authored | reviewed | Confidence that data has not been silently altered. |
| 1013 | isolate {Sec} | authored | generated_draft | isolate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the isolate obligation named before work proceeds. |
| 1014 | key {Sec} | authored | reviewed | The secret or public material that makes cryptographic operations possible. |
| 1015 | key exchange | authored | generated_draft | key exchange is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the key exchange obligation named before work proceeds. |
| 1016 | key rotation | authored | reviewed | Replace active keys before age or compromise turns them rotten. |
| 1017 | least privilege | authored | reviewed | Give only the authority required for the present act, no more. It is one of the simplest words for reducing future regret. |
| 1018 | login | authored | generated_draft | login is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the login obligation named before work proceeds. |
| 1019 | mTLS {Sec} | authored | generated_draft | mTLS in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mTLS obligation named before work proceeds. |
| 1020 | mutual authentication | authored | generated_draft | mutual authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mutual authentication obligation named before work proceeds. |
| 1021 | nonce | authored | generated_draft | nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the nonce obligation named before work proceeds. |
| 1022 | passkey | authored | generated_draft | passkey is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the passkey obligation named before work proceeds. |
| 1023 | password | authored | generated_draft | password is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the password obligation named before work proceeds. |
| 1024 | patch {Sec} | authored | generated_draft | patch in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the patch obligation named before work proceeds. |
| 1025 | pepper | authored | generated_draft | pepper is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the pepper obligation named before work proceeds. |
| 1026 | permission {Sec} | authored | generated_draft | permission in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the permission obligation named before work proceeds. |
| 1027 | phishing | authored | generated_draft | phishing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the phishing obligation named before work proceeds. |
| 1028 | policy | authored | reviewed | The declared rule by which a class of cases is decided. Good policy reduces arbitrary judgment; bad policy merely freezes confusion. |
| 1029 | principal | authored | generated_draft | principal is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the principal obligation named before work proceeds. |
| 1030 | private key | authored | generated_draft | private key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the private key obligation named before work proceeds. |
| 1031 | privilege escalation | authored | generated_draft | privilege escalation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the privilege escalation obligation named before work proceeds. |
| 1032 | proof of possession | authored | generated_draft | proof of possession is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the proof of possession obligation named before work proceeds. |
| 1033 | public key | authored | generated_draft | public key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the public key obligation named before work proceeds. |
| 1034 | quarantine | authored | generated_draft | quarantine is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the quarantine obligation named before work proceeds. |
| 1035 | rate limiting | authored | generated_draft | rate limiting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rate limiting obligation named before work proceeds. |
| 1036 | replay attack | authored | generated_draft | replay attack is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the replay attack obligation named before work proceeds. |
| 1037 | revocation | authored | reviewed | The act of withdrawing trust from credentials or keys. |
| 1038 | role {Sec} | authored | generated_draft | role in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the role obligation named before work proceeds. |
| 1039 | root of trust | authored | generated_draft | root of trust is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the root of trust obligation named before work proceeds. |
| 1040 | rotate | authored | generated_draft | rotate is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rotate obligation named before work proceeds. |
| 1041 | salt | authored | generated_draft | salt is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the salt obligation named before work proceeds. |
| 1042 | sandbox {Sec} | authored | reviewed | Constrain code inside a smaller, safer prison. |
| 1043 | scope {Sec} | authored | generated_draft | scope in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the scope obligation named before work proceeds. |
| 1044 | secret {Sec} | authored | reviewed | Information whose power comes from staying hidden. |
| 1045 | secure enclave | authored | generated_draft | secure enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the secure enclave obligation named before work proceeds. |
| 1046 | security boundary | authored | generated_draft | security boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the security boundary obligation named before work proceeds. |
| 1047 | session fixation | authored | generated_draft | session fixation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session fixation obligation named before work proceeds. |
| 1048 | session token | authored | generated_draft | session token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session token obligation named before work proceeds. |
| 1049 | sign {Sec} | authored | generated_draft | sign in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the sign obligation named before work proceeds. |
| 1050 | signature {Sec} | authored | reviewed | Identity or intent made checkable through cryptographic proof. Useful wherever trust must survive distance and replay. |
| 1051 | single sign-on | authored | generated_draft | single sign-on is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the single sign-on obligation named before work proceeds. |
| 1052 | spoofing | authored | generated_draft | spoofing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the spoofing obligation named before work proceeds. |
| 1053 | SSRF | authored | generated_draft | SSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the SSRF obligation named before work proceeds. |
| 1054 | threat model | authored | reviewed | A structured view of likely attackers, assets, and failure paths. |
| 1055 | token {Sec} | authored | generated_draft | token in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the token obligation named before work proceeds. |
| 1056 | trust anchor | authored | generated_draft | trust anchor is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust anchor obligation named before work proceeds. |
| 1057 | trust boundary | authored | generated_draft | trust boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust boundary obligation named before work proceeds. |
| 1058 | validate {Sec} | authored | generated_draft | validate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the validate obligation named before work proceeds. |
| 1059 | verification {Sec} | authored | generated_draft | verification in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the verification obligation named before work proceeds. |
| 1060 | vulnerability | authored | generated_draft | vulnerability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the vulnerability obligation named before work proceeds. |
| 1061 | ward | authored | generated_draft | ward is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ward obligation named before work proceeds. |
| 1062 | webhook signing | authored | generated_draft | webhook signing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the webhook signing obligation named before work proceeds. |
| 1063 | zero trust | authored | reviewed | Assume no network location or ambient context deserves automatic trust. |
106.2 Entries
106.2.1 [0969] ABAC
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: ABAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ABAC obligation named before work proceeds.
Shadow: misusing ABAC at rune 0969 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
ABACwhen the prompt needs this obligation made explicit:ABACis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ABAC obligation named before work proceeds. - Ask the assistant to state the
ABACshadow before proposing changes.
Example clause:
Before editing, state the ABAC obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.2 [0970] access control
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: access control is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the access control obligation named before work proceeds.
Shadow: misusing access control at rune 0970 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
access controlwhen the prompt needs this obligation made explicit:access controlis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the access control obligation named before work proceeds. - Ask the assistant to state the
access controlshadow before proposing changes.
Example clause:
Before editing, state the access control obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.3 [0971] account
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: account is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the account obligation named before work proceeds.
Shadow: misusing account at rune 0971 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
accountwhen the prompt needs this obligation made explicit:accountis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the account obligation named before work proceeds. - Ask the assistant to state the
accountshadow before proposing changes.
Example clause:
Before editing, state the account obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.4 [0972] ACL
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: ACL is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ACL obligation named before work proceeds.
Shadow: misusing ACL at rune 0972 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
ACLwhen the prompt needs this obligation made explicit:ACLis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ACL obligation named before work proceeds. - Ask the assistant to state the
ACLshadow before proposing changes.
Example clause:
Before editing, state the ACL obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.5 [0973] allowlist
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: allowlist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the allowlist obligation named before work proceeds.
Shadow: misusing allowlist at rune 0973 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
allowlistwhen the prompt needs this obligation made explicit:allowlistis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the allowlist obligation named before work proceeds. - Ask the assistant to state the
allowlistshadow before proposing changes.
Example clause:
Before editing, state the allowlist obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.6 [0974] attestation
Status: canonical (major canon, pocket canon)
Completion: authored
Semantic status: reviewed
Force: A proof that a thing is what it claims to be or was produced the way it claims. It matters most when trust cannot be assumed.
Shadow: when a signed claim is trusted without checking issuer, scope, freshness, or revocation.
Prompt uses:
- Name
attestationwhen the prompt needs this obligation made explicit: A proof that a thing is what it claims to be or was produced the way it claims. It matters most when trust cannot be assumed. - Ask the assistant to state the
attestationshadow before proposing changes.
Example clause:
Before editing, state the attestation obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Evidence that a thing is what it claims to be or was produced the way it claims.
106.2.7 [0975] audit
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: audit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the audit obligation named before work proceeds.
Shadow: misusing audit at rune 0975 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
auditwhen the prompt needs this obligation made explicit:auditis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the audit obligation named before work proceeds. - Ask the assistant to state the
auditshadow before proposing changes.
Example clause:
Before editing, state the audit obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.8 [0976] authenticate
Status: canonical (major canon, pocket canon)
Completion: authored
Semantic status: reviewed
Force: Prove who is making the claim before deciding what the claimant may do.
Shadow: trusting names that have not earned entrance.
Prompt uses:
- Name
authenticatewhen the prompt needs this obligation made explicit: Prove who is making the claim before deciding what the claimant may do. - Ask the assistant to state the
authenticateshadow before proposing changes.
Example clause:
Before editing, state the authenticate obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Prove who is making the claim.
106.2.9 [0977] authentication
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the authentication obligation named before work proceeds.
Shadow: misusing authentication at rune 0977 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
authenticationwhen the prompt needs this obligation made explicit:authenticationis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the authentication obligation named before work proceeds. - Ask the assistant to state the
authenticationshadow before proposing changes.
Example clause:
Before editing, state the authentication obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.10 [0978] authorization
Status: canonical (major canon, pocket canon)
Completion: authored
Semantic status: reviewed
Force: After identity is known, what acts are permitted?
Shadow: accidental omnipotence hidden behind a successful login.
Prompt uses:
- Name
authorizationwhen the prompt needs this obligation made explicit: After identity is known, what acts are permitted? - Ask the assistant to state the
authorizationshadow before proposing changes.
Example clause:
Before editing, state the authorization obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Decide what an already identified actor may do.
106.2.11 [0979] availability
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: availability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the availability obligation named before work proceeds.
Shadow: misusing availability at rune 0979 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
availabilitywhen the prompt needs this obligation made explicit:availabilityis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the availability obligation named before work proceeds. - Ask the assistant to state the
availabilityshadow before proposing changes.
Example clause:
Before editing, state the availability obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.12 [0980] bearer token
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: bearer token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the bearer token obligation named before work proceeds.
Shadow: misusing bearer token at rune 0980 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
bearer tokenwhen the prompt needs this obligation made explicit:bearer tokenis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the bearer token obligation named before work proceeds. - Ask the assistant to state the
bearer tokenshadow before proposing changes.
Example clause:
Before editing, state the bearer token obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.13 [0981] blast radius
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: blast radius is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blast radius obligation named before work proceeds.
Shadow: misusing blast radius at rune 0981 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
blast radiuswhen the prompt needs this obligation made explicit:blast radiusis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blast radius obligation named before work proceeds. - Ask the assistant to state the
blast radiusshadow before proposing changes.
Example clause:
Before editing, state the blast radius obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.14 [0982] blocklist
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: blocklist is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blocklist obligation named before work proceeds.
Shadow: misusing blocklist at rune 0982 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
blocklistwhen the prompt needs this obligation made explicit:blocklistis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the blocklist obligation named before work proceeds. - Ask the assistant to state the
blocklistshadow before proposing changes.
Example clause:
Before editing, state the blocklist obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.15 [0983] boundary defense
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: boundary defense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the boundary defense obligation named before work proceeds.
Shadow: misusing boundary defense at rune 0983 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
boundary defensewhen the prompt needs this obligation made explicit:boundary defenseis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the boundary defense obligation named before work proceeds. - Ask the assistant to state the
boundary defenseshadow before proposing changes.
Example clause:
Before editing, state the boundary defense obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.16 [0984] capability {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: capability in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the capability obligation named before work proceeds.
Shadow: misusing capability at rune 0984 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
capabilitywhen the prompt needs this obligation made explicit:capabilityin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the capability obligation named before work proceeds. - Ask the assistant to state the
capabilityshadow before proposing changes.
Example clause:
Before editing, state the capability obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.17 [0985] certificate {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: certificate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the certificate obligation named before work proceeds.
Shadow: misusing certificate at rune 0985 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
certificatewhen the prompt needs this obligation made explicit:certificatein its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the certificate obligation named before work proceeds. - Ask the assistant to state the
certificateshadow before proposing changes.
Example clause:
Before editing, state the certificate obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.18 [0986] challenge
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: challenge is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the challenge obligation named before work proceeds.
Shadow: misusing challenge at rune 0986 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
challengewhen the prompt needs this obligation made explicit:challengeis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the challenge obligation named before work proceeds. - Ask the assistant to state the
challengeshadow before proposing changes.
Example clause:
Before editing, state the challenge obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.19 [0987] cipher
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: cipher is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cipher obligation named before work proceeds.
Shadow: misusing cipher at rune 0987 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
cipherwhen the prompt needs this obligation made explicit:cipheris a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cipher obligation named before work proceeds. - Ask the assistant to state the
ciphershadow before proposing changes.
Example clause:
Before editing, state the cipher obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.20 [0988] claim
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: claim is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the claim obligation named before work proceeds.
Shadow: misusing claim at rune 0988 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
claimwhen the prompt needs this obligation made explicit:claimis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the claim obligation named before work proceeds. - Ask the assistant to state the
claimshadow before proposing changes.
Example clause:
Before editing, state the claim obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.21 [0989] client secret
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: client secret is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the client secret obligation named before work proceeds.
Shadow: misusing client secret at rune 0989 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
client secretwhen the prompt needs this obligation made explicit:client secretis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the client secret obligation named before work proceeds. - Ask the assistant to state the
client secretshadow before proposing changes.
Example clause:
Before editing, state the client secret obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.22 [0990] code signing
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Cryptographically bind an artifact to a trusted producer.
Shadow: misusing code signing at rune 0990 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
code signingwhen the prompt needs this obligation made explicit: Cryptographically bind an artifact to a trusted producer. - Ask the assistant to state the
code signingshadow before proposing changes.
Example clause:
Before editing, state the code signing obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Cryptographically bind an artifact to a trusted producer.
106.2.23 [0991] compliance
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: compliance is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the compliance obligation named before work proceeds.
Shadow: misusing compliance at rune 0991 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
compliancewhen the prompt needs this obligation made explicit:complianceis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the compliance obligation named before work proceeds. - Ask the assistant to state the
complianceshadow before proposing changes.
Example clause:
Before editing, state the compliance obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.24 [0992] confidentiality
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: confidentiality is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the confidentiality obligation named before work proceeds.
Shadow: misusing confidentiality at rune 0992 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
confidentialitywhen the prompt needs this obligation made explicit:confidentialityis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the confidentiality obligation named before work proceeds. - Ask the assistant to state the
confidentialityshadow before proposing changes.
Example clause:
Before editing, state the confidentiality obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.25 [0993] credential {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: credential in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the credential obligation named before work proceeds.
Shadow: misusing credential at rune 0993 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
credentialwhen the prompt needs this obligation made explicit:credentialin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the credential obligation named before work proceeds. - Ask the assistant to state the
credentialshadow before proposing changes.
Example clause:
Before editing, state the credential obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.26 [0994] cross-site scripting
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: cross-site scripting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cross-site scripting obligation named before work proceeds.
Shadow: misusing cross-site scripting at rune 0994 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
cross-site scriptingwhen the prompt needs this obligation made explicit:cross-site scriptingis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cross-site scripting obligation named before work proceeds. - Ask the assistant to state the
cross-site scriptingshadow before proposing changes.
Example clause:
Before editing, state the cross-site scripting obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.27 [0995] cryptographic nonce
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: cryptographic nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cryptographic nonce obligation named before work proceeds.
Shadow: misusing cryptographic nonce at rune 0995 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
cryptographic noncewhen the prompt needs this obligation made explicit:cryptographic nonceis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the cryptographic nonce obligation named before work proceeds. - Ask the assistant to state the
cryptographic nonceshadow before proposing changes.
Example clause:
Before editing, state the cryptographic nonce obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.28 [0996] CSRF
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: CSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the CSRF obligation named before work proceeds.
Shadow: misusing CSRF at rune 0996 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
CSRFwhen the prompt needs this obligation made explicit:CSRFis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the CSRF obligation named before work proceeds. - Ask the assistant to state the
CSRFshadow before proposing changes.
Example clause:
Before editing, state the CSRF obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.29 [0997] decrypt {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: decrypt in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the decrypt obligation named before work proceeds.
Shadow: misusing decrypt at rune 0997 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
decryptwhen the prompt needs this obligation made explicit:decryptin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the decrypt obligation named before work proceeds. - Ask the assistant to state the
decryptshadow before proposing changes.
Example clause:
Before editing, state the decrypt obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.30 [0998] defense in depth
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Stack multiple protective layers so one failure is not total failure.
Shadow: misusing defense in depth at rune 0998 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
defense in depthwhen the prompt needs this obligation made explicit: Stack multiple protective layers so one failure is not total failure. - Ask the assistant to state the
defense in depthshadow before proposing changes.
Example clause:
Before editing, state the defense in depth obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Stack multiple protective layers so one failure is not total failure.
106.2.31 [0999] deny-by-default
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: deny-by-default is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the deny-by-default obligation named before work proceeds.
Shadow: misusing deny-by-default at rune 0999 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
deny-by-defaultwhen the prompt needs this obligation made explicit:deny-by-defaultis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the deny-by-default obligation named before work proceeds. - Ask the assistant to state the
deny-by-defaultshadow before proposing changes.
Example clause:
Before editing, state the deny-by-default obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.32 [1000] digest {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: digest in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the digest obligation named before work proceeds.
Shadow: misusing digest at rune 1000 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
digestwhen the prompt needs this obligation made explicit:digestin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the digest obligation named before work proceeds. - Ask the assistant to state the
digestshadow before proposing changes.
Example clause:
Before editing, state the digest obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.33 [1001] enclave
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the enclave obligation named before work proceeds.
Shadow: misusing enclave at rune 1001 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
enclavewhen the prompt needs this obligation made explicit:enclaveis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the enclave obligation named before work proceeds. - Ask the assistant to state the
enclaveshadow before proposing changes.
Example clause:
Before editing, state the enclave obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.34 [1002] encrypt {Sec}
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Make plaintext unreadable without the right key.
Shadow: misusing encrypt at rune 1002 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
encryptwhen the prompt needs this obligation made explicit: Make plaintext unreadable without the right key. - Ask the assistant to state the
encryptshadow before proposing changes.
Example clause:
Before editing, state the encrypt obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Make plaintext unreadable without the right key.
106.2.35 [1003] entropy
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: entropy is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the entropy obligation named before work proceeds.
Shadow: misusing entropy at rune 1003 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
entropywhen the prompt needs this obligation made explicit:entropyis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the entropy obligation named before work proceeds. - Ask the assistant to state the
entropyshadow before proposing changes.
Example clause:
Before editing, state the entropy obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.36 [1004] exfiltration
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: exfiltration is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exfiltration obligation named before work proceeds.
Shadow: misusing exfiltration at rune 1004 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
exfiltrationwhen the prompt needs this obligation made explicit:exfiltrationis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exfiltration obligation named before work proceeds. - Ask the assistant to state the
exfiltrationshadow before proposing changes.
Example clause:
Before editing, state the exfiltration obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.37 [1005] exploit
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: exploit is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exploit obligation named before work proceeds.
Shadow: misusing exploit at rune 1005 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
exploitwhen the prompt needs this obligation made explicit:exploitis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the exploit obligation named before work proceeds. - Ask the assistant to state the
exploitshadow before proposing changes.
Example clause:
Before editing, state the exploit obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.38 [1006] harden
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: harden is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the harden obligation named before work proceeds.
Shadow: misusing harden at rune 1006 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
hardenwhen the prompt needs this obligation made explicit:hardenis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the harden obligation named before work proceeds. - Ask the assistant to state the
hardenshadow before proposing changes.
Example clause:
Before editing, state the harden obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.39 [1007] hash {Sec}
Status: canonical (major canon, pocket canon)
Completion: authored
Semantic status: reviewed
Force: Arbitrary input reduced to a fixed fingerprint. Use it for identity, integrity, bucketing, and change detection; never mistake it for secrecy.
Shadow: when hash equality is treated as meaning, authority, or secrecy it does not provide.
Prompt uses:
- Name
hashwhen the prompt needs this obligation made explicit: Arbitrary input reduced to a fixed fingerprint. Use it for identity, integrity, bucketing, and change detection; never mistake it for secrecy. - Ask the assistant to state the
hashshadow before proposing changes.
Example clause:
Before editing, state the hash obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Reduce arbitrary input to a fixed fingerprint.
106.2.40 [1008] HMAC
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: HMAC is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the HMAC obligation named before work proceeds.
Shadow: misusing HMAC at rune 1008 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
HMACwhen the prompt needs this obligation made explicit:HMACis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the HMAC obligation named before work proceeds. - Ask the assistant to state the
HMACshadow before proposing changes.
Example clause:
Before editing, state the HMAC obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.41 [1009] identity
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: identity is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the identity obligation named before work proceeds.
Shadow: misusing identity at rune 1009 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
identitywhen the prompt needs this obligation made explicit:identityis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the identity obligation named before work proceeds. - Ask the assistant to state the
identityshadow before proposing changes.
Example clause:
Before editing, state the identity obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.42 [1010] incident
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: incident is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the incident obligation named before work proceeds.
Shadow: misusing incident at rune 1010 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
incidentwhen the prompt needs this obligation made explicit:incidentis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the incident obligation named before work proceeds. - Ask the assistant to state the
incidentshadow before proposing changes.
Example clause:
Before editing, state the incident obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.43 [1011] injection
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: injection is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the injection obligation named before work proceeds.
Shadow: misusing injection at rune 1011 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
injectionwhen the prompt needs this obligation made explicit:injectionis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the injection obligation named before work proceeds. - Ask the assistant to state the
injectionshadow before proposing changes.
Example clause:
Before editing, state the injection obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.44 [1012] integrity
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Confidence that data has not been silently altered.
Shadow: misusing integrity at rune 1012 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
integritywhen the prompt needs this obligation made explicit: Confidence that data has not been silently altered. - Ask the assistant to state the
integrityshadow before proposing changes.
Example clause:
Before editing, state the integrity obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Confidence that data has not been silently altered.
106.2.45 [1013] isolate {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: isolate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the isolate obligation named before work proceeds.
Shadow: misusing isolate at rune 1013 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
isolatewhen the prompt needs this obligation made explicit:isolatein its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the isolate obligation named before work proceeds. - Ask the assistant to state the
isolateshadow before proposing changes.
Example clause:
Before editing, state the isolate obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.46 [1014] key {Sec}
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: The secret or public material that makes cryptographic operations possible.
Shadow: misusing key at rune 1014 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
keywhen the prompt needs this obligation made explicit: The secret or public material that makes cryptographic operations possible. - Ask the assistant to state the
keyshadow before proposing changes.
Example clause:
Before editing, state the key obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: The secret or public material that makes cryptographic operations possible.
106.2.47 [1015] key exchange
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: key exchange is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the key exchange obligation named before work proceeds.
Shadow: misusing key exchange at rune 1015 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
key exchangewhen the prompt needs this obligation made explicit:key exchangeis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the key exchange obligation named before work proceeds. - Ask the assistant to state the
key exchangeshadow before proposing changes.
Example clause:
Before editing, state the key exchange obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.48 [1016] key rotation
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Replace active keys before age or compromise turns them rotten.
Shadow: misusing key rotation at rune 1016 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
key rotationwhen the prompt needs this obligation made explicit: Replace active keys before age or compromise turns them rotten. - Ask the assistant to state the
key rotationshadow before proposing changes.
Example clause:
Before editing, state the key rotation obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Replace active keys before age or compromise turns them rotten.
106.2.49 [1017] least privilege
Status: canonical (major canon, pocket canon)
Completion: authored
Semantic status: reviewed
Force: Give only the authority required for the present act, no more. It is one of the simplest words for reducing future regret.
Shadow: when roles accumulate exceptions until least privilege becomes a slogan.
Prompt uses:
- Name
least privilegewhen the prompt needs this obligation made explicit: Give only the authority required for the present act, no more. It is one of the simplest words for reducing future regret. - Ask the assistant to state the
least privilegeshadow before proposing changes.
Example clause:
Before editing, state the least privilege obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Grant only the authority required for the present act.
106.2.50 [1018] login
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: login is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the login obligation named before work proceeds.
Shadow: misusing login at rune 1018 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
loginwhen the prompt needs this obligation made explicit:loginis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the login obligation named before work proceeds. - Ask the assistant to state the
loginshadow before proposing changes.
Example clause:
Before editing, state the login obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.51 [1019] mTLS {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: mTLS in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mTLS obligation named before work proceeds.
Shadow: misusing mTLS at rune 1019 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
mTLSwhen the prompt needs this obligation made explicit:mTLSin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mTLS obligation named before work proceeds. - Ask the assistant to state the
mTLSshadow before proposing changes.
Example clause:
Before editing, state the mTLS obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.52 [1020] mutual authentication
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: mutual authentication is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mutual authentication obligation named before work proceeds.
Shadow: misusing mutual authentication at rune 1020 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
mutual authenticationwhen the prompt needs this obligation made explicit:mutual authenticationis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the mutual authentication obligation named before work proceeds. - Ask the assistant to state the
mutual authenticationshadow before proposing changes.
Example clause:
Before editing, state the mutual authentication obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.53 [1021] nonce
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: nonce is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the nonce obligation named before work proceeds.
Shadow: misusing nonce at rune 1021 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
noncewhen the prompt needs this obligation made explicit:nonceis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the nonce obligation named before work proceeds. - Ask the assistant to state the
nonceshadow before proposing changes.
Example clause:
Before editing, state the nonce obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.54 [1022] passkey
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: passkey is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the passkey obligation named before work proceeds.
Shadow: misusing passkey at rune 1022 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
passkeywhen the prompt needs this obligation made explicit:passkeyis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the passkey obligation named before work proceeds. - Ask the assistant to state the
passkeyshadow before proposing changes.
Example clause:
Before editing, state the passkey obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.55 [1023] password
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: password is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the password obligation named before work proceeds.
Shadow: misusing password at rune 1023 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
passwordwhen the prompt needs this obligation made explicit:passwordis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the password obligation named before work proceeds. - Ask the assistant to state the
passwordshadow before proposing changes.
Example clause:
Before editing, state the password obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.56 [1024] patch {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: patch in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the patch obligation named before work proceeds.
Shadow: misusing patch at rune 1024 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
patchwhen the prompt needs this obligation made explicit:patchin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the patch obligation named before work proceeds. - Ask the assistant to state the
patchshadow before proposing changes.
Example clause:
Before editing, state the patch obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.57 [1025] pepper
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: pepper is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the pepper obligation named before work proceeds.
Shadow: misusing pepper at rune 1025 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
pepperwhen the prompt needs this obligation made explicit:pepperis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the pepper obligation named before work proceeds. - Ask the assistant to state the
peppershadow before proposing changes.
Example clause:
Before editing, state the pepper obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.58 [1026] permission {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: permission in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the permission obligation named before work proceeds.
Shadow: misusing permission at rune 1026 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
permissionwhen the prompt needs this obligation made explicit:permissionin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the permission obligation named before work proceeds. - Ask the assistant to state the
permissionshadow before proposing changes.
Example clause:
Before editing, state the permission obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.59 [1027] phishing
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: phishing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the phishing obligation named before work proceeds.
Shadow: misusing phishing at rune 1027 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
phishingwhen the prompt needs this obligation made explicit:phishingis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the phishing obligation named before work proceeds. - Ask the assistant to state the
phishingshadow before proposing changes.
Example clause:
Before editing, state the phishing obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.60 [1028] policy
Status: canonical (major canon, pocket canon)
Completion: authored
Semantic status: reviewed
Force: The declared rule by which a class of cases is decided. Good policy reduces arbitrary judgment; bad policy merely freezes confusion.
Shadow: when policy text says one thing and enforcement code grants another.
Prompt uses:
- Name
policywhen the prompt needs this obligation made explicit: The declared rule by which a class of cases is decided. Good policy reduces arbitrary judgment; bad policy merely freezes confusion. - Ask the assistant to state the
policyshadow before proposing changes.
Example clause:
Before editing, state the policy obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: A declared rule for how a class of cases is decided.
106.2.61 [1029] principal
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: principal is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the principal obligation named before work proceeds.
Shadow: misusing principal at rune 1029 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
principalwhen the prompt needs this obligation made explicit:principalis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the principal obligation named before work proceeds. - Ask the assistant to state the
principalshadow before proposing changes.
Example clause:
Before editing, state the principal obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.62 [1030] private key
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: private key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the private key obligation named before work proceeds.
Shadow: misusing private key at rune 1030 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
private keywhen the prompt needs this obligation made explicit:private keyis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the private key obligation named before work proceeds. - Ask the assistant to state the
private keyshadow before proposing changes.
Example clause:
Before editing, state the private key obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.63 [1031] privilege escalation
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: privilege escalation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the privilege escalation obligation named before work proceeds.
Shadow: misusing privilege escalation at rune 1031 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
privilege escalationwhen the prompt needs this obligation made explicit:privilege escalationis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the privilege escalation obligation named before work proceeds. - Ask the assistant to state the
privilege escalationshadow before proposing changes.
Example clause:
Before editing, state the privilege escalation obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.64 [1032] proof of possession
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: proof of possession is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the proof of possession obligation named before work proceeds.
Shadow: misusing proof of possession at rune 1032 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
proof of possessionwhen the prompt needs this obligation made explicit:proof of possessionis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the proof of possession obligation named before work proceeds. - Ask the assistant to state the
proof of possessionshadow before proposing changes.
Example clause:
Before editing, state the proof of possession obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.65 [1033] public key
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: public key is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the public key obligation named before work proceeds.
Shadow: misusing public key at rune 1033 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
public keywhen the prompt needs this obligation made explicit:public keyis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the public key obligation named before work proceeds. - Ask the assistant to state the
public keyshadow before proposing changes.
Example clause:
Before editing, state the public key obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.66 [1034] quarantine
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: quarantine is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the quarantine obligation named before work proceeds.
Shadow: misusing quarantine at rune 1034 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
quarantinewhen the prompt needs this obligation made explicit:quarantineis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the quarantine obligation named before work proceeds. - Ask the assistant to state the
quarantineshadow before proposing changes.
Example clause:
Before editing, state the quarantine obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.67 [1035] rate limiting
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: rate limiting is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rate limiting obligation named before work proceeds.
Shadow: misusing rate limiting at rune 1035 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
rate limitingwhen the prompt needs this obligation made explicit:rate limitingis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rate limiting obligation named before work proceeds. - Ask the assistant to state the
rate limitingshadow before proposing changes.
Example clause:
Before editing, state the rate limiting obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.68 [1036] replay attack
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: replay attack is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the replay attack obligation named before work proceeds.
Shadow: misusing replay attack at rune 1036 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
replay attackwhen the prompt needs this obligation made explicit:replay attackis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the replay attack obligation named before work proceeds. - Ask the assistant to state the
replay attackshadow before proposing changes.
Example clause:
Before editing, state the replay attack obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.69 [1037] revocation
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: The act of withdrawing trust from credentials or keys.
Shadow: misusing revocation at rune 1037 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
revocationwhen the prompt needs this obligation made explicit: The act of withdrawing trust from credentials or keys. - Ask the assistant to state the
revocationshadow before proposing changes.
Example clause:
Before editing, state the revocation obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: The act of withdrawing trust from credentials or keys.
106.2.70 [1038] role {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: role in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the role obligation named before work proceeds.
Shadow: misusing role at rune 1038 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
rolewhen the prompt needs this obligation made explicit:rolein its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the role obligation named before work proceeds. - Ask the assistant to state the
roleshadow before proposing changes.
Example clause:
Before editing, state the role obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.71 [1039] root of trust
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: root of trust is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the root of trust obligation named before work proceeds.
Shadow: misusing root of trust at rune 1039 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
root of trustwhen the prompt needs this obligation made explicit:root of trustis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the root of trust obligation named before work proceeds. - Ask the assistant to state the
root of trustshadow before proposing changes.
Example clause:
Before editing, state the root of trust obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.72 [1040] rotate
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: rotate is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rotate obligation named before work proceeds.
Shadow: misusing rotate at rune 1040 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
rotatewhen the prompt needs this obligation made explicit:rotateis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the rotate obligation named before work proceeds. - Ask the assistant to state the
rotateshadow before proposing changes.
Example clause:
Before editing, state the rotate obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.73 [1041] salt
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: salt is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the salt obligation named before work proceeds.
Shadow: misusing salt at rune 1041 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
saltwhen the prompt needs this obligation made explicit:saltis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the salt obligation named before work proceeds. - Ask the assistant to state the
saltshadow before proposing changes.
Example clause:
Before editing, state the salt obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.74 [1042] sandbox {Sec}
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Constrain code inside a smaller, safer prison.
Shadow: misusing sandbox at rune 1042 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
sandboxwhen the prompt needs this obligation made explicit: Constrain code inside a smaller, safer prison. - Ask the assistant to state the
sandboxshadow before proposing changes.
Example clause:
Before editing, state the sandbox obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Constrain code inside a smaller, safer prison.
106.2.75 [1043] scope {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: scope in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the scope obligation named before work proceeds.
Shadow: misusing scope at rune 1043 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
scopewhen the prompt needs this obligation made explicit:scopein its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the scope obligation named before work proceeds. - Ask the assistant to state the
scopeshadow before proposing changes.
Example clause:
Before editing, state the scope obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.76 [1044] secret {Sec}
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Information whose power comes from staying hidden.
Shadow: misusing secret at rune 1044 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
secretwhen the prompt needs this obligation made explicit: Information whose power comes from staying hidden. - Ask the assistant to state the
secretshadow before proposing changes.
Example clause:
Before editing, state the secret obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Information whose power comes from staying hidden.
106.2.77 [1045] secure enclave
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: secure enclave is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the secure enclave obligation named before work proceeds.
Shadow: misusing secure enclave at rune 1045 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
secure enclavewhen the prompt needs this obligation made explicit:secure enclaveis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the secure enclave obligation named before work proceeds. - Ask the assistant to state the
secure enclaveshadow before proposing changes.
Example clause:
Before editing, state the secure enclave obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.78 [1046] security boundary
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: security boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the security boundary obligation named before work proceeds.
Shadow: misusing security boundary at rune 1046 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
security boundarywhen the prompt needs this obligation made explicit:security boundaryis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the security boundary obligation named before work proceeds. - Ask the assistant to state the
security boundaryshadow before proposing changes.
Example clause:
Before editing, state the security boundary obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.79 [1047] session fixation
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: session fixation is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session fixation obligation named before work proceeds.
Shadow: misusing session fixation at rune 1047 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
session fixationwhen the prompt needs this obligation made explicit:session fixationis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session fixation obligation named before work proceeds. - Ask the assistant to state the
session fixationshadow before proposing changes.
Example clause:
Before editing, state the session fixation obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.80 [1048] session token
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: session token is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session token obligation named before work proceeds.
Shadow: misusing session token at rune 1048 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
session tokenwhen the prompt needs this obligation made explicit:session tokenis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the session token obligation named before work proceeds. - Ask the assistant to state the
session tokenshadow before proposing changes.
Example clause:
Before editing, state the session token obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.81 [1049] sign {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: sign in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the sign obligation named before work proceeds.
Shadow: misusing sign at rune 1049 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
signwhen the prompt needs this obligation made explicit:signin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the sign obligation named before work proceeds. - Ask the assistant to state the
signshadow before proposing changes.
Example clause:
Before editing, state the sign obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.82 [1050] signature {Sec}
Status: canonical (major canon, pocket canon)
Completion: authored
Semantic status: reviewed
Force: Identity or intent made checkable through cryptographic proof. Useful wherever trust must survive distance and replay.
Shadow: when a valid signature is accepted outside its intended scope, time, or trust root.
Prompt uses:
- Name
signaturewhen the prompt needs this obligation made explicit: Identity or intent made checkable through cryptographic proof. Useful wherever trust must survive distance and replay. - Ask the assistant to state the
signatureshadow before proposing changes.
Example clause:
Before editing, state the signature obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Identity or intent made checkable through cryptographic proof.
106.2.83 [1051] single sign-on
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: single sign-on is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the single sign-on obligation named before work proceeds.
Shadow: misusing single sign-on at rune 1051 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
single sign-onwhen the prompt needs this obligation made explicit:single sign-onis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the single sign-on obligation named before work proceeds. - Ask the assistant to state the
single sign-onshadow before proposing changes.
Example clause:
Before editing, state the single sign-on obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.84 [1052] spoofing
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: spoofing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the spoofing obligation named before work proceeds.
Shadow: misusing spoofing at rune 1052 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
spoofingwhen the prompt needs this obligation made explicit:spoofingis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the spoofing obligation named before work proceeds. - Ask the assistant to state the
spoofingshadow before proposing changes.
Example clause:
Before editing, state the spoofing obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.85 [1053] SSRF
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: SSRF is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the SSRF obligation named before work proceeds.
Shadow: misusing SSRF at rune 1053 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
SSRFwhen the prompt needs this obligation made explicit:SSRFis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the SSRF obligation named before work proceeds. - Ask the assistant to state the
SSRFshadow before proposing changes.
Example clause:
Before editing, state the SSRF obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.86 [1054] threat model
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: A structured view of likely attackers, assets, and failure paths.
Shadow: misusing threat model at rune 1054 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
threat modelwhen the prompt needs this obligation made explicit: A structured view of likely attackers, assets, and failure paths. - Ask the assistant to state the
threat modelshadow before proposing changes.
Example clause:
Before editing, state the threat model obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: A structured view of likely attackers, assets, and failure paths.
106.2.87 [1055] token {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: token in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the token obligation named before work proceeds.
Shadow: misusing token at rune 1055 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
tokenwhen the prompt needs this obligation made explicit:tokenin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the token obligation named before work proceeds. - Ask the assistant to state the
tokenshadow before proposing changes.
Example clause:
Before editing, state the token obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.88 [1056] trust anchor
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: trust anchor is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust anchor obligation named before work proceeds.
Shadow: misusing trust anchor at rune 1056 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
trust anchorwhen the prompt needs this obligation made explicit:trust anchoris a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust anchor obligation named before work proceeds. - Ask the assistant to state the
trust anchorshadow before proposing changes.
Example clause:
Before editing, state the trust anchor obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.89 [1057] trust boundary
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: trust boundary is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust boundary obligation named before work proceeds.
Shadow: misusing trust boundary at rune 1057 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
trust boundarywhen the prompt needs this obligation made explicit:trust boundaryis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the trust boundary obligation named before work proceeds. - Ask the assistant to state the
trust boundaryshadow before proposing changes.
Example clause:
Before editing, state the trust boundary obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.90 [1058] validate {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: validate in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the validate obligation named before work proceeds.
Shadow: misusing validate at rune 1058 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
validatewhen the prompt needs this obligation made explicit:validatein its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the validate obligation named before work proceeds. - Ask the assistant to state the
validateshadow before proposing changes.
Example clause:
Before editing, state the validate obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.91 [1059] verification {Sec}
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: verification in its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the verification obligation named before work proceeds.
Shadow: misusing verification at rune 1059 in the Sec lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
verificationwhen the prompt needs this obligation made explicit:verificationin its Sec sense is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the verification obligation named before work proceeds. - Ask the assistant to state the
verificationshadow before proposing changes.
Example clause:
Before editing, state the verification obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.92 [1060] vulnerability
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: vulnerability is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the vulnerability obligation named before work proceeds.
Shadow: misusing vulnerability at rune 1060 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
vulnerabilitywhen the prompt needs this obligation made explicit:vulnerabilityis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the vulnerability obligation named before work proceeds. - Ask the assistant to state the
vulnerabilityshadow before proposing changes.
Example clause:
Before editing, state the vulnerability obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.93 [1061] ward
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: ward is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ward obligation named before work proceeds.
Shadow: misusing ward at rune 1061 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
wardwhen the prompt needs this obligation made explicit:wardis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the ward obligation named before work proceeds. - Ask the assistant to state the
wardshadow before proposing changes.
Example clause:
Before editing, state the ward obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.94 [1062] webhook signing
Status: canonical
Completion: authored
Semantic status: generated_draft
Force: webhook signing is a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the webhook signing obligation named before work proceeds.
Shadow: misusing webhook signing at rune 1062 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
webhook signingwhen the prompt needs this obligation made explicit:webhook signingis a security and trust rune for make identity, authority, secrecy, and enforcement boundaries auditable; use it when the artifact needs the webhook signing obligation named before work proceeds. - Ask the assistant to state the
webhook signingshadow before proposing changes.
Example clause:
Before editing, state the webhook signing obligation, the evidence that satisfies it, and the failure mode if it is missing.
106.2.95 [1063] zero trust
Status: canonical (pocket canon)
Completion: authored
Semantic status: reviewed
Force: Assume no network location or ambient context deserves automatic trust.
Shadow: misusing zero trust at rune 1063 in the security lane can let misplaced trust can grant authority or expose secrets; verify by requiring the caster to state issuer, subject, scope, freshness, and enforcement point.
Prompt uses:
- Name
zero trustwhen the prompt needs this obligation made explicit: Assume no network location or ambient context deserves automatic trust. - Ask the assistant to state the
zero trustshadow before proposing changes.
Example clause:
Before editing, state the zero trust obligation, the evidence that satisfies it, and the failure mode if it is missing.
Pocket gloss: Assume no network location or ambient context deserves automatic trust.