A prompt is not a fence
A brief can say change only this fragment while a brain reads neighbors or a helper expands a broad glob. Instructions communicate intent; they do not remove capability. Memory boundaries are too expensive to depend on goodwill.
A scope seal binds allowed vault, path prefix, and operation to the claim and checks immediately before every read or write tool call. A mistaken prompt still cannot open a forbidden path.
Seal reads too
Write containment alone allows one protected vault to be read and mixed into the claimed target. Confidentiality and contamination fail at read time. The seal must separately govern read, search, related, and write.
Even a global index query filters results through the seal before snippets enter brain context. Out-of-scope paths do not leave the index.
Normalize before comparison
Prefix guards are vulnerable to parent traversal, symlinks, Unicode normalization, and echoed vault prefixes. Convert input to a canonical relative path, define symlink policy, and compare path components.
Normalizing one known harmless echo differs from forgiving arbitrary traversal. Remove only an expected duplicate prefix and deny every other strange form explicitly.
A seal violation is a contamination incident
Once a forbidden read reaches output, continuing with a warning is unsafe because later judgment now contains closed context. Preserve valid edits, record the incident, and resume in a fresh context.
A blocked write is not proof of no leak. Memory can propagate through context, logs, and a provider at read time. No-write success is not no-disclosure evidence.