Before persisting any output, Canon Boundary Guard checks for contamination — phrases or patterns that indicate non-L0 material has entered the content. Contaminated content cannot be markedDocumentation Index
Fetch the complete documentation index at: https://mintlify.com/xxyoudeadpunkxx/canon-boundary-guard-for-gpt-project/llms.txt
Use this file to discover all available pages before exploring further.
[SAFE TO SAVE] and must not be written to canon without operator review and explicit authorization. This page lists each contamination category, the phrases that trigger a flag, and the conditions under which contaminated phrases are permitted.
Conversation residue
The following phrases indicate that L1 material — content sourced from the current or prior conversation rather than from inspected L0 evidence — may have entered the output:Agent-control residue
The following phrases indicate that L2 material — behavioral steering, reminders, or agent-facing instructions — may have leaked into project content:Authorized delta.
Version ghosts
Any version number, release identifier, or API version claimed in output that is not found in an actively inspected L0 source is a potential L3 ghost. This includes:- Software version numbers (e.g.,
v3.2.1,Python 3.11,Node 20) - Framework or library release names
- Schema version fields
- API version strings
[L3] and either remove it, verify it against an inspected source, or obtain explicit operator approval before persisting.
Model-prior claims
The following phrases indicate that L3 material — unverified model memory, generic conventions, or assumed best practices — may have entered the output:Filesystem promotion ghosts
The following phrases indicate a forbidden direct filesystem promotion — moving content from scratch space to canon without running the gate:/mnt/data/scratch/** to any canon or final destination requires the gate to run first. If any of these phrases appear in a write operation, block the write, verify that the gate was run for the content being promoted, and restate the dossier with the correct promotion record.
When contamination is allowed
A contaminated phrase does not automatically invalidate output. Contamination is permitted in exactly three contexts:- Grounded in L0 — the phrase or claim appears verbatim in an inspected L0 source and is being faithfully reproduced, not asserted independently.
- Explicitly approved as L1A — the operator granted explicit authorization in the current turn for the specific scope containing the phrase, and the authorization is recorded in the dossier under
Authorized delta. - Intentionally written in historical or migration context — the phrase is documenting a prior state, a deprecated convention, or a migration baseline rather than asserting current guidance. This context must be clearly marked in the output and recorded in the dossier.
For the full persistence rules that govern what may and may not be written to durable artifacts, see the Protocol reference.