{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:JIVPDCGALKA2YKWALFLXOKWRK3","short_pith_number":"pith:JIVPDCGA","canonical_record":{"source":{"id":"2503.18813","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-24T15:54:10Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"44fbadbd1fe5486cd238f8b9f36d7890cb055fe3410812c8bc8a76974565ae34","abstract_canon_sha256":"09002a24020218cde86625811e7f6269e984370e39bd781dc8327fbf4292b008"},"schema_version":"1.0"},"canonical_sha256":"4a2af188c05a81ac2ac05957772ad156d3d4822972db07fe9f0f8ed2efdaddbb","source":{"kind":"arxiv","id":"2503.18813","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2503.18813","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"arxiv_version","alias_value":"2503.18813v2","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.18813","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"pith_short_12","alias_value":"JIVPDCGALKA2","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"pith_short_16","alias_value":"JIVPDCGALKA2YKWA","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"pith_short_8","alias_value":"JIVPDCGA","created_at":"2026-07-05T11:26:03Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:JIVPDCGALKA2YKWALFLXOKWRK3","target":"record","payload":{"canonical_record":{"source":{"id":"2503.18813","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-24T15:54:10Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"44fbadbd1fe5486cd238f8b9f36d7890cb055fe3410812c8bc8a76974565ae34","abstract_canon_sha256":"09002a24020218cde86625811e7f6269e984370e39bd781dc8327fbf4292b008"},"schema_version":"1.0"},"canonical_sha256":"4a2af188c05a81ac2ac05957772ad156d3d4822972db07fe9f0f8ed2efdaddbb","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:26:03.640992Z","signature_b64":"avAH/LiU8NC2RV5TR42v/VEPp0F+PCznax5J8vzP0rGzBuZ37X8+HwD5+dcrdPv0qyruqqxhDqY0voJd6GwqCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4a2af188c05a81ac2ac05957772ad156d3d4822972db07fe9f0f8ed2efdaddbb","last_reissued_at":"2026-07-05T11:26:03.640434Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:26:03.640434Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2503.18813","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T11:26:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BWgdRg9QiQr70h+kees3tMnLJ9A5CpTxnuPl8zz3S6Si+malCB1Zz2RFbp3O7wUpTMLcexjgE/pW8k7K8bF7BA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T01:00:30.173485Z"},"content_sha256":"50562643dc20fe99caec044aa377ba4ebfff384dd9344104e1c260df584b0d28","schema_version":"1.0","event_id":"sha256:50562643dc20fe99caec044aa377ba4ebfff384dd9344104e1c260df584b0d28"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:JIVPDCGALKA2YKWALFLXOKWRK3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Defeating Prompt Injections by Design","license":"http://creativecommons.org/licenses/by/4.0/","headline":"CaMeL secures LLM agents against prompt injections by extracting control and data flows from trusted queries so untrusted data cannot change execution.","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Andreas Terzis, Chongyang Shi, Christoph Kern, Daniel Fabian, Edoardo Debenedetti, Florian Tram\\`er, Ilia Shumailov, Jamie Hayes, Nicholas Carlini, Tianqi Fan","submitted_at":"2025-03-24T15:54:10Z","abstract_excerpt":"Large Language Models (LLMs) are increasingly deployed in agentic systems that interact with an untrusted environment. However, LLM agents are vulnerable to prompt injection attacks when handling untrusted data. In this paper we propose CaMeL, a robust defense that creates a protective system layer around the LLM, securing it even when underlying models are susceptible to attacks. To operate, CaMeL explicitly extracts the control and data flows from the (trusted) query; therefore, the untrusted data retrieved by the LLM can never impact the program flow. To further improve security, CaMeL uses"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"CaMeL explicitly extracts the control and data flows from the (trusted) query; therefore, the untrusted data retrieved by the LLM can never impact the program flow. We demonstrate effectiveness of CaMeL by solving 77% of tasks with provable security (compared to 84% with an undefended system) in AgentDojo.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That control and data flows can be extracted perfectly and unambiguously from the trusted query and that the LLM will strictly follow the extracted flows without deviation or reinterpretation.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"CaMeL protects LLM agents from prompt injection by separating trusted control flows from untrusted data and enforcing capability policies on tool calls, achieving 77% task success with provable security on AgentDojo versus 84% undefended.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"CaMeL secures LLM agents against prompt injections by extracting control and data flows from trusted queries so untrusted data cannot change execution.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"ec5486c2bfcd0502ccd737610e1ce57e9b03c9b63312452115fbc2d9b4fd34d7"},"source":{"id":"2503.18813","kind":"arxiv","version":2},"verdict":{"id":"96181429-b46e-466a-8f43-948829a1b28d","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-13T06:48:05.522590Z","strongest_claim":"CaMeL explicitly extracts the control and data flows from the (trusted) query; therefore, the untrusted data retrieved by the LLM can never impact the program flow. We demonstrate effectiveness of CaMeL by solving 77% of tasks with provable security (compared to 84% with an undefended system) in AgentDojo.","one_line_summary":"CaMeL protects LLM agents from prompt injection by separating trusted control flows from untrusted data and enforcing capability policies on tool calls, achieving 77% task success with provable security on AgentDojo versus 84% undefended.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That control and data flows can be extracted perfectly and unambiguously from the trusted query and that the LLM will strictly follow the extracted flows without deviation or reinterpretation.","pith_extraction_headline":"CaMeL secures LLM agents against prompt injections by extracting control and data flows from trusted queries so untrusted data cannot change execution."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.18813/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":229,"sample":[{"doi":"","year":2024,"title":"HH:MM\" representing how many hours and minutes you have until the lunch.↩→ User Running the code gave the following error: Traceback (most recent call last): File","work_id":"2a5b6b9d-1845-4c02-8e86-cad4ce761d92","ref_index":7,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Use the AI assistant to extract the new colleague 's information from the messages","work_id":"7b085212-f0b5-45b3-ac5d-9508888104e5","ref_index":8,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Invite them to Slack using their name and email","work_id":"4f926d7a-4450-4b54-b58f-23a9347f1f54","ref_index":9,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Add them to all specified channels","work_id":"35b1bc7b-cd8a-4f23-bb65-24be046e2fb3","ref_index":10,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"<stdin>\", line 11, in <module> info = query_ai_assistant( ^^^^^^^^^^^^^^^^^^^^^^^^^^","work_id":"03902a77-209e-4b22-9879-436ee7420ff4","ref_index":11,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":229,"snapshot_sha256":"0ee14880a50c0509e8fdde1b270d6702cb7e2216af9dbecdfdad29ea1c854206","internal_anchors":0},"formal_canon":{"evidence_count":2,"snapshot_sha256":"d28597bcef740337ace983eee309466fceeae096a0bfd713827a3307b09a7601"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"96181429-b46e-466a-8f43-948829a1b28d"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T11:26:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2VryQ3PvfS7+ROqOF8syibz9GAhCIeSFmRz/G9n/iU6ew/J/OVqSH+aoybrY/dkxIAMrKhrv3UAk2HGA2y/7Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T01:00:30.175049Z"},"content_sha256":"4c1360fdf1acb79e43c471480fdf6a30e72b2148490f0e553b7a18bc9664d508","schema_version":"1.0","event_id":"sha256:4c1360fdf1acb79e43c471480fdf6a30e72b2148490f0e553b7a18bc9664d508"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/JIVPDCGALKA2YKWALFLXOKWRK3/bundle.json","state_url":"https://pith.science/pith/JIVPDCGALKA2YKWALFLXOKWRK3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/JIVPDCGALKA2YKWALFLXOKWRK3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-05T01:00:30Z","links":{"resolver":"https://pith.science/pith/JIVPDCGALKA2YKWALFLXOKWRK3","bundle":"https://pith.science/pith/JIVPDCGALKA2YKWALFLXOKWRK3/bundle.json","state":"https://pith.science/pith/JIVPDCGALKA2YKWALFLXOKWRK3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/JIVPDCGALKA2YKWALFLXOKWRK3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:JIVPDCGALKA2YKWALFLXOKWRK3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"09002a24020218cde86625811e7f6269e984370e39bd781dc8327fbf4292b008","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-24T15:54:10Z","title_canon_sha256":"44fbadbd1fe5486cd238f8b9f36d7890cb055fe3410812c8bc8a76974565ae34"},"schema_version":"1.0","source":{"id":"2503.18813","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2503.18813","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"arxiv_version","alias_value":"2503.18813v2","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.18813","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"pith_short_12","alias_value":"JIVPDCGALKA2","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"pith_short_16","alias_value":"JIVPDCGALKA2YKWA","created_at":"2026-07-05T11:26:03Z"},{"alias_kind":"pith_short_8","alias_value":"JIVPDCGA","created_at":"2026-07-05T11:26:03Z"}],"graph_snapshots":[{"event_id":"sha256:4c1360fdf1acb79e43c471480fdf6a30e72b2148490f0e553b7a18bc9664d508","target":"graph","created_at":"2026-07-05T11:26:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"CaMeL explicitly extracts the control and data flows from the (trusted) query; therefore, the untrusted data retrieved by the LLM can never impact the program flow. We demonstrate effectiveness of CaMeL by solving 77% of tasks with provable security (compared to 84% with an undefended system) in AgentDojo."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That control and data flows can be extracted perfectly and unambiguously from the trusted query and that the LLM will strictly follow the extracted flows without deviation or reinterpretation."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"CaMeL protects LLM agents from prompt injection by separating trusted control flows from untrusted data and enforcing capability policies on tool calls, achieving 77% task success with provable security on AgentDojo versus 84% undefended."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"CaMeL secures LLM agents against prompt injections by extracting control and data flows from trusted queries so untrusted data cannot change execution."}],"snapshot_sha256":"ec5486c2bfcd0502ccd737610e1ce57e9b03c9b63312452115fbc2d9b4fd34d7"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"d28597bcef740337ace983eee309466fceeae096a0bfd713827a3307b09a7601"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2503.18813/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large Language Models (LLMs) are increasingly deployed in agentic systems that interact with an untrusted environment. However, LLM agents are vulnerable to prompt injection attacks when handling untrusted data. In this paper we propose CaMeL, a robust defense that creates a protective system layer around the LLM, securing it even when underlying models are susceptible to attacks. To operate, CaMeL explicitly extracts the control and data flows from the (trusted) query; therefore, the untrusted data retrieved by the LLM can never impact the program flow. To further improve security, CaMeL uses","authors_text":"Andreas Terzis, Chongyang Shi, Christoph Kern, Daniel Fabian, Edoardo Debenedetti, Florian Tram\\`er, Ilia Shumailov, Jamie Hayes, Nicholas Carlini, Tianqi Fan","cross_cats":["cs.AI"],"headline":"CaMeL secures LLM agents against prompt injections by extracting control and data flows from trusted queries so untrusted data cannot change execution.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-24T15:54:10Z","title":"Defeating Prompt Injections by Design"},"references":{"count":229,"internal_anchors":0,"resolved_work":229,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":7,"title":"HH:MM\" representing how many hours and minutes you have until the lunch.↩→ User Running the code gave the following error: Traceback (most recent call last): File","work_id":"2a5b6b9d-1845-4c02-8e86-cad4ce761d92","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":8,"title":"Use the AI assistant to extract the new colleague 's information from the messages","work_id":"7b085212-f0b5-45b3-ac5d-9508888104e5","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":9,"title":"Invite them to Slack using their name and email","work_id":"4f926d7a-4450-4b54-b58f-23a9347f1f54","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":10,"title":"Add them to all specified channels","work_id":"35b1bc7b-cd8a-4f23-bb65-24be046e2fb3","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":11,"title":"<stdin>\", line 11, in <module> info = query_ai_assistant( ^^^^^^^^^^^^^^^^^^^^^^^^^^","work_id":"03902a77-209e-4b22-9879-436ee7420ff4","year":null}],"snapshot_sha256":"0ee14880a50c0509e8fdde1b270d6702cb7e2216af9dbecdfdad29ea1c854206"},"source":{"id":"2503.18813","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-13T06:48:05.522590Z","id":"96181429-b46e-466a-8f43-948829a1b28d","model_set":{"reader":"grok-4.3"},"one_line_summary":"CaMeL protects LLM agents from prompt injection by separating trusted control flows from untrusted data and enforcing capability policies on tool calls, achieving 77% task success with provable security on AgentDojo versus 84% undefended.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"CaMeL secures LLM agents against prompt injections by extracting control and data flows from trusted queries so untrusted data cannot change execution.","strongest_claim":"CaMeL explicitly extracts the control and data flows from the (trusted) query; therefore, the untrusted data retrieved by the LLM can never impact the program flow. We demonstrate effectiveness of CaMeL by solving 77% of tasks with provable security (compared to 84% with an undefended system) in AgentDojo.","weakest_assumption":"That control and data flows can be extracted perfectly and unambiguously from the trusted query and that the LLM will strictly follow the extracted flows without deviation or reinterpretation."}},"verdict_id":"96181429-b46e-466a-8f43-948829a1b28d"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:50562643dc20fe99caec044aa377ba4ebfff384dd9344104e1c260df584b0d28","target":"record","created_at":"2026-07-05T11:26:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"09002a24020218cde86625811e7f6269e984370e39bd781dc8327fbf4292b008","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-24T15:54:10Z","title_canon_sha256":"44fbadbd1fe5486cd238f8b9f36d7890cb055fe3410812c8bc8a76974565ae34"},"schema_version":"1.0","source":{"id":"2503.18813","kind":"arxiv","version":2}},"canonical_sha256":"4a2af188c05a81ac2ac05957772ad156d3d4822972db07fe9f0f8ed2efdaddbb","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4a2af188c05a81ac2ac05957772ad156d3d4822972db07fe9f0f8ed2efdaddbb","first_computed_at":"2026-07-05T11:26:03.640434Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T11:26:03.640434Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"avAH/LiU8NC2RV5TR42v/VEPp0F+PCznax5J8vzP0rGzBuZ37X8+HwD5+dcrdPv0qyruqqxhDqY0voJd6GwqCQ==","signature_status":"signed_v1","signed_at":"2026-07-05T11:26:03.640992Z","signed_message":"canonical_sha256_bytes"},"source_id":"2503.18813","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:50562643dc20fe99caec044aa377ba4ebfff384dd9344104e1c260df584b0d28","sha256:4c1360fdf1acb79e43c471480fdf6a30e72b2148490f0e553b7a18bc9664d508"],"state_sha256":"20fab73c83b294605742f8707fa763be8dfde53e781be4c05aa5d59046174b91"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l7Iv9Q8cNfj2XMRmIUzVasuWk/nPLhBMYMoq1Pc+g6/icX40lU/A5Q1Hjh3uRSfx2eEEhJUhqo2FEqdVX5gSCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-05T01:00:30.183484Z","bundle_sha256":"6f13f6a860491b51384a832c353c6e60cd3db19230522ad0a66f48463c0eef00"}}