Incident workspace
Cross-domain Message Validation Weakness
A fictional research disclosure models a cross-domain receiver that validates message shape but not the expected origin domain.
Phase 1 · Fictional Content
Fictional data used to validate the TraceFi interface. This is not a real security incident.
Replay Lab
Non-executable replay material only.
- Replay type
- Static Code Walkthrough
- Replay status
- Available
- Execution label
- Non-executable
- Environment
- Annotated fictional code
Requirements
- Browser reading only
Limitations
- Research-only record
- No executable bridge fixture
- No real bridge message data
Investigation lab not packaged yet
This prototype incident does not include a curated browser IDE lab. Review the incident overview, evidence, and Learn Mode while the lab package is planned.
Interactive Foundry Challenge Preview
This phase is non-functional. There is no editor, terminal, runner, scoring persistence, API, wallet, RPC endpoint, or code execution.
Verification State
Verification: ReviewedLast verified: