# Security packs, multi-turn eval, and replay polish

Security-family challenge packs, stress-run CLI, and vault boundary harnesses established AgentClash as a security eval surface. Multi-turn evaluation with human takeover and case templating extended the engine beyond single-shot runs.

Period: May 15 – May 24, 2026
Source: https://www.agentclash.dev/changelog/2026-05-15
Markdown export: https://www.agentclash.dev/md/changelog/2026-05-15

## Changes

- **Security**: SecurityPolicy schema and SecurityScore dimension for security-family challenge packs.
- **Security**: Canonical secret-hygiene and prompt-injection challenge packs shipped.
- **Security**: CLI `stress-run` subcommand with Anthropic Messages provider and --no-system-guard leak surfacing.
- **Security**: agent-vault-stress harness with real Vault SDK, function calling, campaign mode, and bundled HTTP mock.
- **Security**: Infisical and HashiCorp Vault boundary packs for vault-framed canary leak testing.
- **Added**: Multi-turn evaluation — user simulators, hybrid executor, human takeover, calibration reviews, and post-run arena.
- **Added**: Case template renderer and bundle validation for code-execution challenge packs.
- **Added**: Multi-turn conversation events with transcript helpers in the event model.
- **Improved**: Replay trace output upgraded with IDE-level syntax highlighting and rich text rendering.
- **Improved**: Planted secrets from security packs wired into sandbox provisioning.