Back to the research walkthrough

Task Lab · interactive world factory

Start from real work. Mutate only what evidence allows.

Switch worlds, inspect every source-backed DAG edge, apply or refuse one mutation at a time, and follow public records field by field into a coherent mock packet. The exported task preserves the seed, lineage, verifier, and digests.

Choose a researched world3 domains · one contract
software supply-chain security

Remediate a vulnerable application release through review

Platform security engineer · deterministic seed 11

9 receipts3 real records16/18 nodes/edges12/12 realism gates
Current proposal
Known workflow

baseline

admitted

The conservative software supply-chain security workflow mapped from observed practice to tools already present in the world.

Seeded from the researched workflow before any graph walk.
Document effectStart with Deployment inventory
Must remain true
  • The queried package and version must come from the supplied inventory
  • The remediation must target the advisory's fixed version or its cited upstream fix
  • Authorization regression coverage changes with the implementation
  • The pull request links the advisory and contains only scoped remediation files
  • No merge occurs before required checks and review pass
Executable sequence
6 retained stepssequence held
01
cyanheads-osv-advisory-mcp-serverosv_query_package
02
cyanheads-osv-advisory-mcp-serverosv_get_vulnerability
03
githubget_file_contents
04
githubcreate_branch
05
githubpush_files
06
githubcreate_pull_request
retained lifecycle passed0 issuesschema 0workflow 5
Input packet
SPDX-JSON

Deployment inventory

applicationDockside Assets
packagedockside/assets-server
ecosystemPackagist
deployed_version8.5.1

6 grounded fields · spdx-specification

9/9 invariants passfield formats, cross-document identity, workflow semantics, de-identification
Generated artifact

What the agent sees

Delegated request · Platform security engineer

Please remediate BFSA-2026-041 for Dockside Assets (dockside/assets-server 8.5.1). Confirm the affected range and move it to 8.6.0 or backport the cited authorization fix, with regression coverage for allowed and denied exports.

6 proposals remainThe next proposal may be admitted or refused