Egress Lock v0.1 — Transitive Egress Closure for AI Cyber Evaluations
桑杰戈
Egress Lock is a low-cost containment standard for guardrails-off AI cyber evaluations. It addresses a failure mode demonstrated by the July 2026 Hugging Face incident: an evaluated agent may lack direct Internet access yet obtain external connectivity by inducing a reachable intermediary service to relay requests on its behalf.
We define Transitive Egress Closure (TEC): every network-capable service reachable by the evaluated agent must either be unable to relay arbitrary external requests, or have its egress enforced by the same controlled boundary. Our reference harness uses real Linux network namespaces and nftables, a deliberately vulnerable artifact proxy, an independent Canary, and isolated management control.
The final measured run covered 33 atomic test items: 26 PASS, 2 PASS (bounded), and 5 NOT PROVEN. The strongest result is a 6/6 TEC relay test in which the vulnerable proxy could be induced to attempt external access, but the second hop was blocked while a direct positive control remained allowed. The prototype does not claim universal Internet impossibility, real-Internet coverage, or physical-hardware assurance.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Egress Lock v0.1 — Transitive Egress Closure for AI Cyber Evaluations
},
author={
桑杰戈
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


