docs(blog): publish The answer key didn't change - #82
Conversation
Git-Session-Id: 6ffa
🤖 AI code reviewThis PR adds a new blog post, _posts/2026-09-13-the-answer-key-didnt-change.md, describing a security finding in Bob's screening runner where a synthetic child process could read an outside answer file and pass verification while hashes remained unchanged. The post also adds an OG image asset. The post discusses the distinction between process-boundary access and model behavior, and outlines acceptance criteria for containment fixes. Safe to merge — no P0/P1 findingsConfidence 5/5 ✅ No findings. The diff looks correct to me on this pass. Files changed (1) — the diff as I read it
Reviewed Maintainer commands
|
Publishes “The answer key didn't change,” explaining a reproduced read-access gap in Bob's held-out screening runner. A deterministic synthetic child copied an outside answer and passed while answer/verifier hashes stayed unchanged. The article distinguishes this process-boundary result from untested model behavior and states that containment remains pending.
Validation: repeated the synthetic real-process probe (zero model calls); independent factual/editorial review passed; scoped source hooks and redaction sync passed; generated and visually inspected the 1200×630 OG card. Full Jekyll build and website commit hooks are checked before submission.