Agent eval L2·L3 Candidate Quarantined Effect unmeasured v1.0.0

Banking tasks

From parent collection: AgentDojo paired candidates

Fifteen attack/no-injection control pairs in banking environments from the AgentDojo candidate pool. Preserves parent families and locked splits; not directly runnable.

Applies to paired attack/control checks in a banking environment. Intended L2·L3, not verified.

Target layers L2·L3, not verified. Quarantined candidate; recipe unmaterialized. Layers are intended observation depth only, not verified quality or measured effect.

Purpose category
Scenario Pairs · Banking environment
Items
30 seeds
Languages
Not recorded
Material format
Restricted runtime references (parent subset)
Controls
15 attack / no-injection counterfactual pairs
Sources
AgentDojo
Environment requirement
Banking environment; requires reviewing upstream AgentDojo specifications and completing authorized environment adaptation
Acquisition status
Quarantined · No runnable task package or public download is available on this site.

Safe Structure Example

Runtime environment reference
Sample structure only · Not raw seed · Not real answer · Not runnable attack
{
  "_annotation": "[Sample structure only · Not raw seed · Not real answer · Not runnable attack]",
  "task_reference": "[reference omitted]",
  "baseline_condition_reference": "[Baseline condition reference omitted]",
  "adversarial_condition_reference": "[Adversarial condition reference omitted]",
  "abstract_state_difference": "[Abstract state difference check omitted]"
}

Usage Pipeline: Preparation → Mapping/Loading → Execution Conditions → Result Interpretation

Integration Plan
1

1. Preparation

Site direct download No (no hosted package) No runnable task package or public download is available on this site.
Public upstream Verified public repository View upstream project
Prerequisites Public upstream link is a project entrypoint only; does not provide or guarantee obtaining the 15 pairs referenced here. This site currently provides no acquisition route for these restricted references; map only after you have independently obtained authorized references through your own approval processes.

Metadata only; no runnable package or download is available.

Public upstream link is a project entrypoint only; does not provide or guarantee obtaining the 15 pairs referenced here. This site currently provides no acquisition route for these restricted references; map only after you have independently obtained authorized references through your own approval processes.

2

2. Mapping & Loading

Four-step loading & adaptation path

1
Verify Upstream

Verify upstream repo version and license for banking suite requirements.

2
Approved Dev Split

Select paired references from approved dev split only; do not tune on test split.

3
Independent Reference Authorization

Public upstream link is a project entrypoint only; does not provide or guarantee obtaining the 15 pairs referenced here. This site currently provides no acquisition route for these restricted references; map only after you have independently obtained authorized references through your own approval processes.

4
Reset & Adapt

Reset sandbox initial state to clean baseline snapshot before each test branch.

Field mapping illustration, not an API of this site or upstream

Mapping format illustration only; not an API of this site or upstream; cannot be executed directly
# Mapping format illustration only; not an API of this site or upstream; cannot be executed directly.
# Adapter pseudocode skeleton: adapt to authorized format; not runnable code.
# [High-level mapping worksheet: scenario banking abstract relations]
# Operational requirements:
# 1. Version & license verification: Verify upstream AgentDojo repo version and license
# 2. Approved development split: Use approved dev split only; held-out splits must not be used for tuning
# 3. Independent reference authorization: Upstream link is project entrypoint only; no guarantee of 15 pairs; map only after independent approval
# 4. Environment adaptation & reset: Both baseline and adversarial branches must reset from clean state snapshot

BANKING_MAPPING_SPEC = {
    "task_reference": "[reference omitted]",
    "baseline_condition_reference": "<MAP_TO_YOUR_AUTHORIZED_BASELINE_CONDITION>",
    "adversarial_condition_reference": "<MAP_TO_YOUR_AUTHORIZED_ADVERSARIAL_CONDITION>",
    "abstract_state_difference": "<MAP_TO_YOUR_AUTHORIZED_STATE_DIFFERENCE_CHECK>",
}
3

3. Execution Conditions

Evaluation input method: Paired condition comparison in banking scenario Environment requirement: Banking environment; requires reviewing upstream AgentDojo specifications and completing authorized environment adaptation
4

4. Result Interpretation

Core observation dimensions

Abstract state defense observation
Not yet measured
Expected: Ratio of untrusted injections blocked without unintended state differences
How to measure: Check trace against expected boundary to verify compliance
Baseline condition abstract utility
Not yet measured
Expected: Ratio of expected abstract state reached under baseline condition
How to measure: Check trace against expected boundary to verify compliance
Observation perspective note: Compares abstract state differences between baseline and adversarial conditions; does not infer specific business APIs or objects.

Disclaimer:Expected behavior serves as evaluation criteria and does not imply actual model pass; effects remain unmeasured and do not guarantee zero risk.

Related guides and reports

Browse material selection guidelines or view complete catalog status and audit reports.

Version, provenance & governance details
Download and pull are blocked

This controlled candidate has not passed every license, security, and release gate. No pull command or download URL is exposed.

This site only exposes allowlisted collection metadata, risk distributions, and lineage. Raw attack payloads are held in internal quarantine and are not downloadable.

Required pre-release checks, not a completed gate review for this candidate.

Unmet gates (11)
  • Not formally published (published)
  • Public visibility not approved (publicVisibility)
  • Sensitivity does not allow public access (publicSensitivity)
  • Redistribution review pending (redistributionReviewed)
  • License evidence link missing (licenseEvidenceUrl)
  • Abuse reporting channel missing (abuseContactRecorded)
  • Permitted uses not recorded (permittedUsesRecorded)
  • Prohibited uses not recorded (prohibitedUsesRecorded)
  • Governance not approved (governanceApproved)
  • Release eligibility not approved (releaseEligible)
  • Download not enabled (downloadEnabled)

These links are verified public HTTPS external resources. Visiting upstream sources does not grant redistribution or local download.

Collection ID

candidate-agentdojo-paired--banking

Parent Collection ID

candidate-agentdojo-paired

Intended layer

L2·L3

Version

1.0.0

Collection kind

Thematic view

Status

Pending

Review status

Pending

Sensitivity

Pending

Items

30

Languages

Pending

Targets

Pending

License

pending review

PathMedia typeSizeSHA-256
No direct file list (metadata mode)
SourceVersionLocation Location kindLicense
not recorded

The marketplace exposes only collection metadata.

Only allowlisted collection metadata is shown. Seed records, evaluation guidance, and payload-bearing fields are excluded from the site build.

FieldTypeDescription
id string Stable collection identifier
version string Immutable version
kind enum Collection kind (source/view/candidate)
intendedLayers array Intended use tiers (not verified evidence)
riskTags array Public risk tags
seedCount number Member identities within this collection (not semantic uniqueness)
verificationStatus enum Real verification status
accessStatus enum Access control status
upstreamUrls array Verified public external URLs

Quality level

Pending

Smoke status

Pending

Validation

Pending

Effect evidence

Pending

Review status

Pending review

Status

Not approved