--- description: Prove ctxguard actually blocks what it claims, and measure real leakage --- Two different questions, two different commands. Run both. 1. Does the machinery work? Drives the canary corpus through the real hook entry points in an isolated state directory: ``` python3 "${CLAUDE_PLUGIN_ROOT}/scripts/ctxguard.py" verify ``` 2. Did anything actually leak? Scans the transcripts — the record of what was really sent to the model — for real values from the dictionary: ``` python3 "${CLAUDE_PLUGIN_ROOT}/scripts/ctxguard.py" scan-transcript ``` Report both numbers plainly. The second is the one that matters: the first measures intent, the second measures outcome. If `scan-transcript` is non-zero, say so directly — it means data reached the model despite the hooks. For a red-team run, `verify --adversarial` prints a brief to hand to a subagent.