Skip to main content

Mistake Clinic

Module-Specific Mistake Radar

MistakeSignalRepair
Benchmark equals safetyNo system threatsMap assets and harms
LLM judge accepted blindlyHuman disagreement unknownValidate the evaluator
Prompt as security boundaryTools overprivilegedEnforce authorization outside model
Red team without taxonomyAnecdotes cannot regressVersion cases and mechanisms
Human fallback by sloganNo capacity or SLATest escalation operationally

Practice Mistake Checks

Verify frozen sets, evaluator validity, threat model, privilege, privacy, affected groups, regression gates, stop control, and risk ownership.

Required evidence

Submit versioned tests, system manifest, raw and summarized results, representative failures, a rejected alternative, named control owners, and residual-risk decision. Safety claims without adversarial evidence do not pass.

Oral defense

Demonstrate one failure, identify its first violated boundary, explain why layered controls limit impact, and execute the stop or escalation path.

Source backbone

Use NIST AI RMF, OWASP LLM Top 10, NIST SSDF, and Building Secure and Reliable Systems.