Pranav Bhave
Claim E3-001 — 18 of 21 in the registry Supported within scope

E3-001Warrant reviewed 2026-09-08 · expires 2027-01-06

Two ungated classifiers scored on harmful and benign items

E3 — the first pilot this repository ran itself — scored two ungated classifiers on 400 harmful and 800 benign items and produced 2,400 committed observation rows. Its primary pre-registered prediction FAILED: excess joint miss was +0.0018 with a 95% bootstrap CI of [-0.00096, +0.00706], which includes zero. Both guards missed almost everything on this pool (0.9825 and 0.9625), so the Fréchet interval the two marginals allow is [0.9450, 0.9625] — 1.75 percentage points wide — and the observed joint miss of 0.9475 lies inside it. The prediction that it would lie inside HELD; the difficulty-stratification prediction was NOT COMPUTED and remains open.

01Falsifier — what changes this claim

Recomputing from the committed observation rows yields any quantity different from the expected block beyond 1e-12, or the observed joint miss is shown to lie outside the Fréchet interval its own marginals allow, or a quoted prediction in the bound run report is shown to have been edited after the outcome was visible.

Consequence REJECT

This is the condition and consequence recorded in the registry. The vocabulary this is published in defines what each consequence commits the author to.

02Scope

Exactly the 2,400 rows committed at experiments/e3/results/observations.jsonl, produced 2026-09-06 by two research classifiers — protectai deberta-v3-base-prompt-injection-v2 (0.2B) and dcarpintero pangolin-guard-base (0.1B) — at thresholds frozen in e3_config.json (sha256 e163a2f2…) before any harmful item was scored. One pool (or-bench-toxic at e36d8b80), one operating point each, static full exposure. scripts/verify_e3.py recomputes every quantity below from those rows alone, including the bootstrap interval, which is a deterministic function of the committed rows under the frozen seed. Nothing here transfers to E2's guards, pools or operating points, and nothing here is about a deployed system.

03Forbidden rescues

Repairs declared unavailable in advance; using one after a failure would breach the recorded commitment.

04Non-claims — what this does not license
05Binding and freshness
Binding
observations.jsonl
The support is the measurement itself: 2,400 per-item, per-guard rows this repository produced. RESULT.md is the interpretation of those rows, not the evidence for them, and is hash-pinned by a trigger below so an edit to a quoted prediction fires a re-review. scripts/verify_e3.py re-derives every registered number from the rows alone on every push.
Reviewed
2026-09-08 · window 120 days
Expires
2027-01-06 — after this date the recorded review is overdue; this does not make the claim false
Triggers
  • executable fires when a committed observation row changes without a registry re-review
  • executable fires when the recorded run result changes without a registry re-review
  • executable fires when the run report changes, including any edit to a quoted prediction
  • manual a third pilot is run on a pool where both guards' miss rates are intermediate
Dimensions
visibilityPublicprovenanceMachine-generated, owner-executedsupport roleExecuted outputmaturityExperimental