LIVE ATTACK SIMULATOR
Break the action layer.
One run shows the invariant: no receipt is blocked, an exact receipt runs once, replay is blocked, and a forged receipt is rejected. The page calls the real Receipt Required API.
1No receiptBLOCKED
2Exact receiptRUNS ONCE
3ReplayBLOCKED
4ForgeryREJECTED
choose the blast radius
ACTUATOR BAY
ACTUATOR LOCKED
No receipt, no execution
payment.release
agent intent$250,000 at risk
$ autonomous-agent
intent: payment.release
target: ACME vendor wire
command: release pending vendor payment now
receipt: null
ConsequenceFunds leave treasury
emilia gatefail closed
LOCK
payment.release:wire:vendor-acme-250000
system of recordprotected
Move $250,000
Policydemo.payment-release.class-a.v1
Targetwire:vendor-acme-250000
Assuranceclass_a
WAITING
attack chain
01
No receipt reaches the gate
will be blocked
idle
02
Human signs exact action
receipt will bind action
idle
03
Receipt reaches actuator
allowed once
idle
04
Same receipt replayed
will be blocked
idle
05
Signed action rewritten
will be rejected
idle
06
Evidence packet exported
auditable proof
idle
live trace
04:39:37
actuator armed; waiting for agent commandblack-box evidence
Waiting for a valid run
SEALED
A valid receipt creates a packet here. Replay and forgery never do.