NORNR mark NORNR Failure modes worth studying before another agent earns more autonomy than it deserves.

NORNR / Prompt injection hall of fame

Developer proof

Catalog the failures cold, then point to the exact control that should have stopped them.

This page is not for memes. It is for builders who want a precise record of what broke, what it cost, and which control surface should have been in the path before the action became consequential.

Each class exists to answer one buyer question: what would have stopped this before money moved?

The useful output is not fear. It is the named lane, pack and packet surface that should have absorbed the failure.

Loop

Retry storms after refusal or transient failure

Repeated paid attempts should hit threshold, anomaly review or queueing before the runtime quietly burns more budget.

NORNR control: policy replay workbench, review bundle, velocity anomaly posture.

Counterparty drift

A new destination appears mid-task

An agent that changes vendor, checkout target or settlement destination should no longer inherit the earlier mandate.

NORNR control: counterparty posture, approval threshold, proof packet provenance.

Browser fan-out

One browsing task becomes a chain of paid clicks

The last click should still clear one review path rather than hide inside a multi-step session.

NORNR control: browser checkout governance, browser-ops pack, proof packet.

Local tools

MCP exposes more power than the team intended

Local tool access is still a consequential control surface if it can trigger providers, vendors or data mutation.

NORNR control: MCP control server, review bundle, finance packet.

Mandate drift

One prior approval gets treated like standing authority

Approval should stay attached to one intent, not bleed into every similar action afterward.

NORNR control: one intent per action, explicit approval state, exported policy version.

Close failure

Finance only sees screenshots after the spend

If the action cannot end in one close-ready export, the control lane still failed institutionally.

NORNR control: finance close packet, exception reports, reconciliation center.