ErrorCaps: committed-effect measurement of recovery-path injection defense (CRiSIS 2026 artifact)
Published software archive; associated manuscript publication status is stated below. Zenodo
Yulliwas Ameur; Samia Bouzefrane; Soumya Banerjee. "ErrorCaps: committed-effect measurement of recovery-path injection defense (CRiSIS 2026 artifact)." Version v3.0.1, Zenodo, 28 August 2026. DOI: 10.5281/zenodo.22147247.
Software archive
Version: v3.0.1. Published: 28 August 2026. Software license: MIT, as stated in the Zenodo record.
The archive describes a synthetic benchmark for indirect prompt injection during error recovery in tool-using agents. Its design combines typed error terminals, a planner that only proposes actions, and a monitor controlling the authority to produce individual effects. It includes per-episode records across seven models, an automated policy-aware attacker, and a comparison between value-based and provenance-based policies. The benchmark uses synthetic canaries; the archive does not report attacks against real systems.
Materials and reproduction instructions
The archive provides the software, recorded results and an offline make reproduce workflow. Download errorcaps-repro-v3.0.1.zip from the official archive for the instructions and recorded results.
Associated manuscript
Where Does Recovery-Path Injection Security Come From? Decomposing Error Sanitization, Effect Monitoring, and Policy Precision
The archive carries a CRiSIS 2026 label. This label does not establish acceptance or proceedings publication of the associated manuscript. The DOI on this page identifies the software archive, not a journal or proceedings paper.
Cite the version used
Yulliwas Ameur; Samia Bouzefrane; Soumya Banerjee. ErrorCaps: committed-effect measurement of recovery-path injection defense (CRiSIS 2026 artifact). Version v3.0.1. Zenodo, 2026. Version DOI.
The concept DOI groups versions of the archive. Cite the version DOI above when using this specific release. Download the site bibliography in BibTeX.
