Line of inquiry
Inquiring lines›What determines the reliability an…›How robust are security defenses a…›this line of inquiry
Can defenses detect attacks composed across multiple skills?
A broader line of inquiry — a family of 32 specific questions the research asks around this. Follow one into its inquiring-line page, or move sideways to a related line below.
Questions in this line of inquiry 32
Specific inquiring lines the field asks around this — ordered from the most general framing down to the most specific angle.
- How do chain-level defenses differ from per-skill scanner detection approaches?
- Can defenders detect attacks that probe scanner feedback as a learning signal?
- Why do skill scanners fail when evaluating composed behaviors instead of isolated skills?
- Should input defenses be validated separately for each channel?
- What signals could refinement loops exploit in defense verdict systems?
- Can skill scanners detect attacks spanning multiple skills in a chain?
- How does the copyable-rule squeeze interact with the false-alert cost squeeze?
- Why do workflow-level defenses catch attacks that single-skill inspection cannot detect?
- Can defenses check skill chains at execution time instead of scan time?
- Why does scanning skill pairs not fully prevent cross-skill attacks?
- Does ChainGuard maintain effectiveness when attackers adapt their approach to the defense?
- How much does attack success depend on tuning to specific scanners versus general robustness?
- What defensive levers shorten the time before probing gets contained?
- How do authorization layers differ from input-boundary defenses in blocking attacks?
- Why does a single approval point create an easy target for attackers?
- Do attackers adapt their plans when monitors deepen their reasoning budget?
- How does the attack chain stage you measure shape what you conclude?
- Why do tighter local checks leave composed behavior gaps in place?
- What feedback signal lets an attacker learn response distributions during classification?
- Can defenses tuned against appended attacks stop prepended payloads?
- What makes a defense mechanism transfer directly rather than just function analogously?
- Why should defense evaluations test against adaptive rather than static attacks?
- Can false positives from input filtering be reduced without sacrificing defense?
- What distinguishes flow-preserving measurement from cognitive vulnerability profiling?
- What feedback does ChainGuard return that an attacker could optimize against?
- How many probes does an attacker need to reach near-zero classification error?
- What happens when probing triggers containment and feedback stops arriving?
- How can a trust boundary check be evaluated to confirm it specifies the defense?
- How do compress gates assume injection payloads appear at the user-prompt boundary?
- What information should a proposer receive about failed guardrail checks?
- How do power-law distributions differ from uniform collision assumptions?
- How does rubber-stamping differ from loss of scrutiny capacity in review processes?