ctipilot.ch

2026-08-28T1500Z-audit

One pipeline fire, in full · audit run of 2026-08-28 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations — and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-08-28/2026-08-28T1500Z-audit.md.

Run telemetry

2026-08-28T1500Z-audit audit prompt v4.2 publish pending
7h 15m duration 0 published 39 updates
Claude Fable 5 (claude-fable-5) main agent
quality-review-A unknown (unknown)
Items returned
18
Duration
2m 13s
Tool calls
not reported
Cited sources
none
quality-review-B unknown (unknown)
Items returned
17
Duration
2m 01s
Tool calls
not reported
Cited sources
none

Verification

unconfirmed CLEAN · waived: Single final CLEAN at iteration 4 (iterations 1-3 NEEDS_FIXES, every finding rem #1 NEEDS_FIXES · Sonnet 5 · t=2 e=0 a=5 #2 NEEDS_FIXES · Sonnet 5 · t=4 e=0 a=3 #3 NEEDS_FIXES · Sonnet 5 · t=4 e=1 a=5 #4 CLEAN · Sonnet 5 · t=0 e=0 a=0

Deep dive

Entries this run published (0) and updated (39)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

2 tier standard -> essential (operator-named critical source; not attempted by the 2026-08-28 fire under rotation).

SourceChangeFrom → ToReason
heise-sectier standard -> essential (operator-named critical source; not attempted by the 2026-08-28 fire under rotation)— → —
inside-it-chtier standard -> essential (operator-named critical source; not attempted by the 2026-08-28 fire under rotation)— → —

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

No coverage gaps in this run · every source the brief needed returned usable content via its documented recipe.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls — every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps — so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-08-28T1500Z-audit · audit · "Fable 5" # Anthropic Claude Fable 5 (Mythos-class, above Opus) — self-identified from the harness model line; correct, not a Series-5 Sonnet/Opus · window 17 h · 0 entries published

Operator-directed review session — 2026-08-28 (v4.2)

This record books an operator-directed interactive session (Claude Code, sandboxed container, read-only git — the operator stages and commits on the host), not a scheduled fire. The operator's directive: review the latest fire's findings; stop pinning the two agent definitions to a dated model id; keep pipeline internals out of reader-facing text (note them in the changelog with no user-facing message and no new timestamp); rebalance the inclusion/length discipline toward quality over quantity; and confirm the operator-named critical sources (NCSC-CH, Heise Security, Inside-IT) actually deliver article detail, not just headlines.

What changed

  1. v4.2 lifecycle mechanics (site/content_model.py, site/build.py, docs/pipeline.md, both master prompts, .claude/agents/cti-verification.md, CLAUDE.md): updates[] records may carry internal: true — changelog-only, no body section, never rendered; updated_at now mirrors only the last non-internal type: update record, so corrections and improvements no longer re-float entries in /live/. Store migration: 8 entries' updated_at recomputed; the Lazarus CVE-2025-49113 metadata correction converted to internal (its reader-facing section removed); the Gemini CLI CVSS-divergence correction section rewritten reader-facing.
  2. Editorial pass over the 2026-08-28T0409Z fire's 36 entries (two read-only review passes, fixes applied centrally): composition-rationale narration ("actions[] is empty because…", "techniques[] maps only…", "per this pipeline's house rules", registry keys in prose, "this pipeline/store/run" self-references) removed from bodies and sourcing notes; the worst verbosity cut (Manchester Airports technique-mapping justification; Suez sourcing-difficulty paragraph; NCSC-UK generic OT-hardening list compressed; Taiwan attribution paragraph compressed; Winnipeg redundant closer; protection-civile null closer; Copeland inline 17-CVE re-list; JFrog KEV-exposition; Danfoss restatement; GTIG cross-entry comparison; kernel-KEV meta-discussion). One wording fix: the redundant "chipset-free," deleted from "a chipset-free, purely configuration-driven authentication bypass" (ownCloud entry). No factual claim changed; every touched entry carries one internal improvement record with run_id 2026-08-28T1500Z-audit.
  3. Model pins: cti-research and cti-verification frontmatter model: changed claude-sonnet-5 -> sonnet (generic alias tracks the current Sonnet generation).
  4. Sources: heise-sec and inside-it-ch promoted to tier: essential — neither was attempted by the 2026-08-28 fire (rotation), heise last contributed 2026-06-20. Known constraint surfaced to the operator: the jina reader pool was fully exhausted (7/7 keys) during the 2026-08-28 fire; heise article bodies are fetch_method: jina-dependent, so until keys are refilled heise coverage is headline-only even on the essential floor. NCSC-CH coverage is healthy (essential tier, attempted and used by the fire via the Security Hub API recipe).
  5. Prompt/CHANGELOG: v4.2 entry; PD-11 rebalanced (sound throughout; complete on critical/high signal; below that, quality over quantity — shorter or not at all).

Governance note (both verifier iterations flagged it; acknowledged, not fixed). This session edited already-published changelog-section prose and record summaries in place in five entries (Lazarus, Thermo Fisher, SAP, Unit 42 autonomous-AI, Keycloak) to remove pipeline jargon and translate quotes — in tension with the "earlier records are never edited" invariant. This was operator-directed (the 2026-08-28 directive explicitly covers retrofitting internals out of reader-facing text), is fully visible in the commit diff, and is a one-time migration; routine fires must never do this.

The 0409Z fire's 7 verification residuals — disposition. Two resolved this session offline (DOJ QScan 2018-dating sentence splice; YOOtheme spliced evidence quote). Five remain for the next audit with network access: Unisoc device/CWE/date details vs the unreachable Dark Reading source; Copeland CVE-2026-21718 mechanism mapping (entry's own inference); ownCloud/Hunt.io ZKTeco BioTime personnel-surveillance angle (missed coverage); Unit 42 AI-malware telemetry-window staleness caveat; miniOrange third WordPress-side CVE in the same disclosure.

For the next audit's warning sweep. Two warnings are this run's own telemetry facts, left for the audit per the no-self-acknowledgment rule: (a) duration_seconds ~7.2 h — an operator-interactive session paced by human turns and four verification iterations, not a stalled routine fire; (b) the recorded confirmation waiver above. Also for awareness: the editorial quality review used two general-purpose read-only passes rather than the named definitions — deliberate (the task was editorial review of published text, not source research or Phase 5.7 verification, and the named definitions embed duties that do not apply), surfaced here because iteration 4's verifier flagged the tension with the named-sub-agent rule.

Coverage gaps: none newly identified beyond the reader-pool exhaustion above (operator action: refill JINA_API_KEYS).

← Operations dashboard · run-record contract: docs/pipeline.md