Manual

DASTOR field manual overview

DASTOR is a practitioner field manual for identifying, testing, containing, governing, remediating, reversing, and proving failures across the AI execution stack. It is doctrine—not a product catalog.

Table of contents

Part 1 — The AI execution stack

Foundations: why AI is not software, the execution stack, and primary failure classes through memory.

  1. 1. AI Is Not Software
  2. 2. The AI Execution Stack Reference Model
  3. 3. Prompt Injection
  4. 4. Context Poisoning
  5. 5. Reasoning Failures and Goal Hijacking
  6. 6. Tool Exploitation
  7. 7. Execution Failures and Side Effects
  8. 8. Memory Is an Attack Surface

Part 2 — Input and context attacks

How untrusted input and retrieved context become control-plane compromise.

  1. 9. Indirect Prompt Injection in the Wild
  2. 10. Instruction Smuggling and Hidden Content
  3. 11. Retrieval Poisoning and Embedding Weaknesses
  4. 12. Cross-Tenant Leakage in RAG and Memory
  5. 13. Output Handling: When Text Becomes Code
  6. 14. Unbounded Consumption: Cost and Availability Attacks

Part 3 — Planning, autonomy, and orchestration

Planning loops, multi-agent handoffs, and observability failures.

  1. 15. The Planning Loop as an Attack Surface
  2. 16. Tool Chaining and Capability Gravity
  3. 17. Multi-Agent Handoffs and Delegation Abuse
  4. 18. Agent Graph Poisoning and Workflow Attacks
  5. 19. Human-in-the-Loop Failure Modes
  6. 20. Observability Failures: When You Can’t Reconstruct Why

Part 4 — Data boundaries, privacy, and compliance

Disclosure, privacy attacks, residency, auditability, compliance, and incident response.

  1. 21. Sensitive Information Disclosure in Agentic Systems
  2. 22. Privacy Attacks: Inversion, Membership, and Regurgitation
  3. 23. Data Residency, Retention, and Right to Forget
  4. 24. Auditability at Scale: Traces, Logs, and Evidence
  5. 25. Compliance Mapping: SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act
  6. 26. Incident Response for Agents: Containment and Rollback

Part 5 — Model, tool, and supply chain security

Poisoning, backdoors, model theft, connectors, runtime compromise, and CI/CD.

  1. 27. Training and Fine-Tuning Poisoning
  2. 28. Backdoors, Trojan Triggers, and Model Integrity
  3. 29. Model Theft and Behavioral Cloning
  4. 30. Tool Marketplace and Connector Supply Chain
  5. 31. Runtime Compromise: Sandboxes, Scripts, Container Escapes
  6. 32. CI/CD and Agent Builds in Production

Part 6 — Countermeasures and safe design patterns

Deterministic gates, engineering patterns, evaluation, governance, evidence, and fail-safe design.

  1. 33. Deterministic Execution Gates
  2. 34. Tool Security Engineering Patterns
  3. 35. Retrieval Security Engineering Patterns
  4. 36. Memory Security Engineering Patterns
  5. 37. Evaluation, Red Teaming, and Regression Harnesses
  6. 38. Governance Operating Model and Change Control
  7. 39. The DASTOR Evidence Standard (ExecutionReceipt)
  8. 40. Building AI Systems That Fail Safely

How to use this manual

  1. Orient on the eight-layer execution stack.
  2. Locate the vulnerability class and related chapter overview.
  3. Apply countermeasures and evidence expectations in your environment.
  4. Escalate to assessment when systems can execute consequential actions.

Edition and licensing

Publisher: BlockSiFr LLC. Verified structure: 40 chapters across 6 parts from catalog source pending DOCX seal. Licensing terms: see /licensing. Full manual delivery is commercial/protected and is not shipped in the public static bundle.