v0.4.0GitHub

Playground

Runtime Enforcement Simulator

Interactive NHIM simulator — NHI attestation, YAML policy, tool payloads, and SIEM export.

View as Markdown

Identity & Policy

NHI attestation + runtime guardrails

spiffe://blekline.internal/ns/prod/sa/data-agent-v2

Policy definition (YAML) · Trust Vault

Threat / Payload simulator

Rogue agent defense — contaminated session + destructive SQL in tool params.

Runtime interceptor console

Traces use Lineage Firewall and Trust Vault semantics where labeled.

Awaiting execution…

Trace output appears here after execution.

What is real vs simulated

StepSource
Secret scan, contracts enforceReal@blekline/contracts
YAML payload / egress rulesReal — playground policy evaluator
Lineage contamination blockDemo — mirrors Lineage Firewall
SPIFFE / IAM attestationSimulatedNHIM roadmap

See NHIM overview for the Shipped/Roadmap table.

Scenarios

  1. Prompt injection → DROP TABLE — contaminated session + destructive SQL
  2. Egress exfiltration — disallowed external host
  3. Compliant RAG query — allowlisted destination for retrieval tools