Agent Input Authority Mapping

How the existing v5.0 judgment layer handles prompt injection, self-replication, and privilege inheritance without new rules. This document is not normative. It adds nothing to the canon: no declaration, no dimension, no constant, no module. It reads published attack reports through what iLang v5.0 already specifies. Why text becomes dangerous Before agents, text on the internet was content. A webpage, an email, a code comment. Humans read it, humans decided what to do. ...

September 2026 · SUN