Two working views: the participant workspace and the defender's Control room
DungeonQ is designed to give security teams time and space to investigate and respond while a designated suspicious session works inside a persistent synthetic world.
The current public source now makes both sides easier to operate:
1. Participant workspace: read an order, save a multiline review note, read the saved value back from the server, and use a world-only ticket for a bounded read.
2. Control room: with separate operator authority, inspect the same world records, successful observations and a request timeline correlated with route evidence. A participant's account of what happened is not the operator's only source.
3. Controlled continuation: preview and explicitly approve a finite mutation grant, then observe the follow-up record after a fresh ticket use. Restart with the same private data directory and read the retained note.
This gives defenders a concrete place to inspect activity and decide what comes next. Human responders and authorized AI agents are the intended beneficiaries; these views do not claim an automatic incident-response handoff.
The updated ten-checkpoint walkthrough also checks a stale-write refusal and rejects a world-only ticket at the artificial origin. It uses real MCP/HTTP clients and artificial resources, without a live model. These checks do not establish production protection or how much response time deception buys.
Available in the current source; the latest tagged release remains v0.11.1.
Working-view instructions:
Walkthrough and recorded evidence:


Replies
this is really interesting to security testing especially the two working views make it easier to see both the user side and defender side of an incident