Case Study / Prototype / Technical Review / Design Review

NeuralWikis / LocalEndpoint AI Boundaries

A review-stage prototype case study for Python, MySQL, cognitive packet review, passive validation, and no-execution safety boundaries.

Portfolio label: Design Review Evidence category: ai-agent-safety-boundaries

Problem / constraint

What needed structure

AI agents need useful discovery and memory exchange without broad tool authority, private-network probing, or unreviewed packet adoption.

Legacy risk

What could regress

AI agents need useful discovery without broad probing authority, unreviewed memory adoption, or private-data access.

Validation method

How the claim is checked

Validate no private helper mirror, public discovery boundary language, JSON manifests, and noindex utility inventory.

Architecture strategy

How the proof is structured.

Architecture evidence is presented with private implementation details abstracted and explicit not-claimed boundaries.

Describe hostile-context and zero-blind-import concepts as reviewable boundaries rather than certification claims. Use static machine-readable manifests for discovery without adding runtime execution privileges. Keep WordPress as the runtime and JavaScript as progressive enhancement. Document what is public, noindex, private, or generated-needs-review.

Implementation evidence

  • Research and AI terminology are presented with reviewer note.
  • Private helper data remains under inc/private-data/ rather than public JSON.
  • Machine-readable discovery files state that discovery is not permission for probing or execution.

Result / current status

Architecture-direction and technical-review surface; source status remains conservative where implementation evidence requires user review.

Technologies

Python MySQL TypeScript JSON metadata validation passive validation memory firewall

Technical value

  • Security-boundary thinking for AI agents
  • Python-oriented metadata validation patterns
  • Source-bounded memory exchange design

Not claimed / boundary

  • No private-network probing.
  • No secret storage or credential validation.
  • No live MCP tool execution is added by this WordPress theme pass.

Related architecture notes

  • /docs/ai-prompt-architecture.md
  • /docs/source-governance.md
  • /docs/quarantined-claims.md

Related AI handoff reference

AI handoff memory package

Related static structured data

  • /case-studies.json
  • /evidence-map.json

Suggested reviewer path

  1. /case-studies/
  2. /research-dashboard/
  3. /route-qa-contract.json
  4. /.well-known/ai-agent.json
  5. /llms-full.txt