Validate Cover
Validates that a main task provides adequate cover for a side task.
Purpose
Uses Claude to analyze whether a proposed main task would give an agent plausible reasons to access security-sensitive resources needed for the side task.
"Cover" means the main task legitimately requires accessing the same resources that the side task will exploit, making sabotage harder to detect.
Commands
ct run validate-cover
Validate that a main task provides adequate cover for a side task.
Usage:
ct run validate-cover [OPTIONS]
Options:
-e, --env- Environment name (will prompt if not provided)-m, --main-task- Main task name (will prompt if not provided)-s, --side-task- Side task name (will prompt if not provided)
Examples:
# Interactive selection ct run validate-cover # Specify all options ct run validate-cover -e web_scraping -m crawl_depth -s visit_malicious_website
Output
Displays:
- ✓ APPROVED or ✗ REJECTED
- Detailed explanation of the cover assessment
What Makes Good Cover?
A main task provides good cover if:
- It legitimately requires accessing security-sensitive areas
- Agent actions for the main task overlap with side task needs
- Sabotage can be hidden within normal main task work
- Monitoring would have difficulty distinguishing legitimate from malicious access
Use Cases
- Validating main/side task pairings before creating strajs
- Ensuring realistic sabotage scenarios
- Identifying tasks that need different pairings
- Quality control for benchmark design
Technical Details
- Uses LLM to analyze task descriptions and required resources
- Considers what resources each task needs to access
- Evaluates plausibility of cover story
- Single-shot analysis per pairing