Security incident drill
Tabletop or live drill covering prompt injection, honeypot leak, and kill switch in one sequence. Allow 30 to 45 minutes.
Prerequisites
- Scout running with at least one alert channel configured.
- Carina running with
LABYRINTH_ENABLED=trueand validLABYRINTH_URL/LABYRINTH_API_KEY. - Operator access to Scout dashboard and
carina doctor.
Drill script
Step 1: Baseline
GET /api/readinesson Scout; save JSON snapshot.carina doctoron Carina; confirm Scout integration is reachable.- Note current
risk_scorefrom/api/public/trust.
Step 2: Prompt injection
- Send a test message containing a known injection pattern (for example "ignore previous instructions").
- Confirm Scout logs
injection_blockedorprompt_injection_blocked. - Confirm alert delivery if channels are configured.
- Send two more injection attempts in the same session within 15 minutes.
- Confirm
repeated_injection_blocksappears if threshold is met.
Step 3: Honeypot simulation
POST /api/admin/alert-testwith{"severity":"breach","instance_id":"drill"}.- Confirm dashboard and alert channel receive the test event.
- Review honeypot configuration in Scout admin; confirm decoy paths are not in real secret stores.
Step 4: Kill switch
POST /api/killfor the drill instance (Scout Pro plan required).- Confirm Carina rejects new tool calls for the suspended instance.
- Export compliance report or incident timeline.
POST /api/resumeafter documenting findings.
Step 5: Trust freshness
- Reload
https://carinaai.uk/trust/. - Confirm
data_freshness.staleisfalseduring normal operation. - If wallet is configured, confirm honesty banner hides only when chain statuses are
live.
Success criteria
- Injection events visible within 60 seconds.
- Alerts fire on breach-severity events when channels are configured.
- Kill switch blocks the instance before resume.
- Operators can follow Incident response without improvising.
After the drill
- Acknowledge or archive test events in Scout.
- Record drill date, participants, gaps, and remediation owners.
- Re-run
pnpm doctorandcarina security audit.