Skip to content
This repository was archived by the owner on Sep 6, 2026. It is now read-only.

v0.5.0

Choose a tag to compare

@askalf askalf released this 16 Jul 21:53
· 40 commits to main since this release
7e89ab2

v0.5.0 — the incidents suite + a stronger detector

Added

  • Incidents suite (incidents/, npm run demo:incidents): the headline agentic-browser failures of 2025–2026 — CometJacking, PleaseFix, the Scamlexity counterfeit-store checkout, agent credential-phishing, and invisible (white-on-white / offscreen) instructions — reproduced as offline fixtures and driven through fieldpass, with shareable receipts in incidents/INCIDENTS.md. Runs browserless (CI) or through real Chrome with PICKET_CDP. Locked in as a regression + false-positive suite (test/incidents.test.mjs).

Changed

  • Detector coverage: the "sensitive data" leg now recognizes the personal-data collections an agentic browser handles — a third-person reference to the user's emails / inbox / calendar / contacts / message-or-browsing history (gated so a page's own "check your email" copy can't trip it) — and the "instruction" leg now catches "supersede your … instructions" and a broader "do not <tell/reveal/surface/mention> … the user" set. CometJacking and PleaseFix now resolve to a lethal-trifecta BLOCK; the full false-positive corpus stays clean (145 tests).

Full changelog: https://github.com/askalf/fieldpass/blob/main/CHANGELOG.md