A local sandbox for testing whether an AI agent can bypass a post-quantum signed authorization policy. The system enforces a default-deny model where only explicitly authorized actions (STATUS, PING) are permitted, while READ_SECRET is intentionally forbidden. Researchers can attempt to exploit the Rust-based baseline to execute unauthorized actions without modifying the enforcement mechanism itself.