“I blocked the named tool.”
Useful evidence. Incomplete conclusion.
Effect-level authorization testing
ShadowPath finds the routes your control forgot: browser, API, database, queue, webhook, credentials, admin, and humans.
Hermetic fixture · no credentials · no vendor claims
shadowpath / customer.disablebrowser_automationOperator UIalternate_apiREST API v2database_mutationDatabase sessionqueue_insertionQueue workerwebhook_creationWebhookadmin_consoleAdmin consolecredential_delegationDelegated credentialhuman_operator_messageHuman operator01 / THE BLIND SPOT
Route controls answer whether one call was allowed. ShadowPath asks whether the prohibited state change happened anyway.
Useful evidence. Incomplete conclusion.
The claim that actually matters.
02 / THE EFFECT SURFACE
Every path starts from fresh state and ends at an independent observer.
Operator UI
REST API v2
Database session
Queue worker
Webhook
Admin console
Delegated credential
Human operator
03 / RUN IT
Replay the committed result now. Scaffold your own effect next.
$ uvx --from git+https://github.com/paulchum/velvet-rope.git velvet-rope shadowpath demoSee the committed eight-path result with zero credentials.
Name one prohibited effect and every route that can reach it.
Observe the substrate independently after each isolated trial.
Put Velvet Rope before consequential execution and retain evidence.
The public 8/8 result is a synthetic, local, hermetic fixture—not a live competitor evaluation. Strong claims require complete route inventory, protected observers, and evidence from the system being tested.