← Back to scenario detail

Response style analysis

Applied 41 · Passed 30 · Failed 11 · Not applicable 27

Rubric: services/agent/prompts/editor/v1.tmpl · SHA-256 ad82285f2536995680bae1f21d87829d473812bd68a82c518246709a6fea8ae9

Prompt

Use the web_fetch tool to answer the prompt. Which vulnerabilities did https://www.cisa.gov/known-exploited-vulnerabilities-catalog add in the past seven days? Give the CVE, affected product, due date, and required action.

Hark's responses

13 vulnerabilities added to the KEV catalog Sep 4–11. Check the table for CVE, product, due date, and forensic triage requirements.
### CISA KEV additions (Sep 4–11) · CISA Known Exploited Vulnerabilities catalog | CVE | Affected product | Due date | |---|---|---| | [CVE-2026-85706](https://www.cve.org/CVERecord?id=CVE-2026-85706) | GitLab CE/EE (path traversal) | 2026-09-14 | | [CVE-2026-42018](https://www.cve.org/CVERecord?id=CVE-2026-42018) | JFrog Artifactory (improper authentication) | 2026-09-25 | | [CVE-2026-42016](https://www.cve.org/CVERecord?id=CVE-2026-42016) | JFrog Artifactory (incorrect authorization) | 2026-09-25 | | [CVE-2026-84869](https://www.cve.org/CVERecord?id=CVE-2026-84869) | ConnectWise ScreenConnect (privilege mgmt / missing authz) | 2026-09-14 | | [CVE-2026-67277](https://www.cve.org/CVERecord?id=CVE-2026-67277) | MikroTik RouterOS (missing auth, btest) | 2026-09-13 | | [CVE-2026-86060](https://www.cve.org/CVERecord?id=CVE-2026-86060) | MikroTik RouterOS (argument delimiter injection) | 2026-09-13 | | [CVE-2026-20079](https://www.cve.org/CVERecord?id=CVE-2026-20079) | Cisco Secure Firewall Management Center / SCC Firewall Mgmt (auth bypass) | 2026-09-12 | | [CVE-2026-87491](https://www.cve.org/CVERecord?id=CVE-2026-87491) | Google Chromium V8 (out-of-bounds write) | 2026-09-23 | | [CVE-2025-25249](https://www.cve.org/CVERecord?id=CVE-2025-25249) | Fortinet FortiOS, FortiSwitchManager, FortiSASE (heap overflow) | 2026-09-12 | | [CVE-2026-19490](https://www.cve.org/CVERecord?id=CVE-2026-19490) | Citrix NetScaler ADC/Gateway (auth bypass) | 2026-09-12 | | [CVE-2026-85880](https://www.cve.org/CVERecord?id=CVE-2026-85880) | Microsoft Windows ALPC (heap overflow, local EoP) | 2026-09-22 | | [CVE-2026-86218](https://www.cve.org/CVERecord?id=CVE-2026-86218) | N-able N-central (static code injection, pre-auth RCE) | 2026-09-11 | | [CVE-2026-81963](https://www.cve.org/CVERecord?id=CVE-2026-81963) | Microsoft Windows Update Stack (link following, EoP to SYSTEM) | 2026-09-22 | | [CVE-2026-75650](https://www.cve.org/CVERecord?id=CVE-2026-75650) | Adobe Commerce / Magento Open Source (template engine RCE) | 2026-09-11 | | [CVE-2026-85046](https://www.cve.org/CVERecord?id=CVE-2026-85046) | Google Chromium V8 (type confusion) | 2026-09-18 |
For all entries: apply vendor mitigations per BOD 26-04, or discontinue use if unavailable. Forensic triage required for GitLab, ScreenConnect, MikroTik CVE-2026-86060, Cisco, Fortinet, Citrix, N-able, and Adobe Commerce.

Fail

preserve_factual_spans

FailAdvisory
Applies when: Hark includes a name, place, time, number, URL, or factual claim from the draft.
Requirement: Preserve each fact's referent, value, precision, certainty, and scope. Rephrasing is allowed when all five stay unchanged. Keep URLs, identifiers, exact quotes, code, and documents byte-exact.
The draft specifies “Cisco FMC” for forensic triage, but the delivered wording broadens this to “Cisco.” The response also says 13 vulnerabilities while displaying 15 rows, making the count misleading.

prefer_specific_details

FailAdvisory
Applies when: Specific names, dates, quantities, or outcomes are available.
Requirement: Use the specific details instead of vague adjectives or descriptions.
The triage note uses broad labels such as “Cisco,” “Fortinet,” and “Citrix” even though exact products or CVEs are available.

use_plain_precise_language

FailAdvisory
Applies when: Hark explains a result using descriptive or specialized language.
Requirement: Prefer plain and specific language. Name an exact technical, legal, or financial term when it matters and explain it briefly.
Several unexplained abbreviations reduce clarity, including “CE/EE,” “mgmt,” “authz,” “EoP,” and “RCE.”

keep_one_thought_per_bubble

FailAdvisory
Applies when: Hark sends more than one prose bubble.
Requirement: Give each prose bubble one thought. Never merge two thoughts into one bubble to hit a count; keep them apart or cut one whole.
The first prose bubble combines the result with a delivery pointer, and the final bubble combines the common action with a separate triage list.

avoid_delivery_pointers

FailAdvisory
Applies when: Hark refers to another message, bubble, file, workspace location, or delivery step.
Requirement: Deliver the content itself. Do not point above, below, next, or to a saved location as the answer.
“Check the table” points the user to another bubble instead of simply framing or delivering the result.

avoid_duplicate_content

FailAdvisory
Applies when: The same sentence, section, or content block could appear in more than one bubble.
Requirement: Send each piece of content once across the reply.
The Sep 4–11 date range is stated in the first prose bubble and repeated in the table title.

keep_comparable_detail

FailAdvisory
Applies when: Hark delivers multiple commissioned items.
Requirement: Include every fact the draft gave each item, however long its row or section runs. Do not compress or drop content inside the rich bubble; compress only the prose around it.
The draft supplies an added date for every vulnerability, but the delivered table drops that field. It also moves triage details into a compressed group rather than retaining them per applicable item.

keep_deliverable_companions_brief

FailAdvisory
Applies when: Hark places prose before or after a commissioned-work rich bubble.
Requirement: Use at most one framing sentence before and one takeaway sentence after the card, each at or below 20 words.
The framing bubble contains two sentences, and the post-table companion contains two sentences and exceeds the 20-word limit.

avoid_request_restatement

FailAdvisory
Applies when: Hark repeats part or all of the user's request.
Requirement: Restate the request only when doing so resolves an ambiguity or is necessary for confirmation.
“Check the table for CVE, product, due date, and forensic triage requirements” unnecessarily repeats the requested output fields.

keep_card_companions_contextual

FailAdvisory
Applies when: Hark places a prose bubble next to a rich card.
Requirement: Use at most the allowed short companion sentence for context, a caveat, or a draft-provided next step. Do not restate, summarize, caption, or narrate the card.
The first companion narrates the card with “Check the table” and incorrectly says the table contains forensic-triage requirements, which are actually in the following prose bubble.

provide_rich_metadata

FailAdvisory
Applies when: Hark sends a table, code, or document bubble.
Requirement: Give tables pipe rows, a short title, and the Excel Spreadsheet subtitle. Give code its language and title. Give documents a title and the .txt file subtitle.
The table has pipe rows and a title, but its displayed subtitle is “CISA Known Exploited Vulnerabilities catalog” rather than the required “Excel Spreadsheet.”

Pass

follow_explicit_style_instructions

PassAdvisory
Applies when: The user explicitly requests a response length, format, tone, audience, focus, or presentation style.
Requirement: Follow the user's explicit style instructions only when the draft carries them and they remain compatible with the editor's bubble and rich-content requirements.
The response provides the requested CVE, affected product, due date, and required action using a table plus a common-action note.

preserve_draft_substance

PassAdvisory
Applies when: Hark selects content from the draft for delivery.
Requirement: Preserve the draft's substance. Compress by choosing what to keep, not by changing the answer, claim, option, or commitment. Keep a default the draft says it will act on, a condition attached to an instruction, and a state change the user could not otherwise know.
It retains all listed vulnerabilities, their due dates, the common mitigation instruction, the discontinue-if-unavailable condition, and the forensic-triage distinctions.

preserve_instruction_direction

PassAdvisory
Applies when: Hark shortens or merges a draft sentence that tells the user what to do, to what, or with whom.
Requirement: Keep the sentence's verb, object, and addressee. When shortening would change any of them, keep the draft's own sentence or cut it whole, and never fuse two sentences when the fusion would change either.
The shortened action retains the operative verbs and objects: apply vendor mitigations, or discontinue use when mitigations are unavailable.

avoid_invented_content

PassAdvisory
Applies when: Hark sends a user-visible response.
Requirement: Do not add a fact, answer, option, offer, caveat, opinion, suggestion, next step, or commitment that the draft does not contain.
The delivered vulnerabilities, dates, products, action, and triage information all come from the draft or fetched catalog.

lead_with_outcome

PassAdvisory
Applies when: Hark sends a user-visible response.
Requirement: Lead with the answer, result, necessary question, or blocker.
The first bubble immediately states the claimed number and date range of catalog additions.

use_direct_short_sentences

PassAdvisory
Applies when: Hark sends a user-visible prose response.
Requirement: Use direct, short sentences and the shortest phrasing that preserves the full meaning.
The prose uses short, direct sentences, while the detailed results are placed in a table.

avoid_condescending_explanations

PassAdvisory
Applies when: Hark explains information to the user.
Requirement: Explain the information without talking down to the user or belaboring basic points.
The action explanation is concise and does not belabor basic points or talk down to the user.

avoid_throat_clearing

PassAdvisory
Applies when: Hark sends a user-visible response.
Requirement: Do not begin with praise, a generic acknowledgment, an offer to help, or a preview of the next sentence.
The response begins with the result rather than praise, acknowledgment, or an offer to help.

use_structure_only_when_helpful

PassAdvisory
Applies when: Hark presents content that has a defined rich bubble kind.
Requirement: Use the required rich bubble kind for a table, code block, document, link set, or attachment instead of recreating that structure in prose.
Comparable vulnerabilities are presented in a table rather than recreated as a long prose list.

match_register_to_stakes

PassAdvisory
Applies when: Hark responds about a serious, painful, or high-stakes subject.
Requirement: Stay short and direct while dropping slang and swagger.
The cybersecurity response remains professional and avoids slang or swagger.

use_hearer_oriented_grammar

PassAdvisory
Applies when: Space permits a possessive determiner, definite article, or hearer-oriented imperative, or Hark describes its own wellbeing.
Requirement: Prefer forms such as your dog, the White Sox, and try tilapia. Say I'm doing well or I'm good, never I'm doing good.
The response uses a hearer-oriented imperative in “Check the table.”

limit_prose_bubbles

PassAdvisory
Applies when: Hark sends one or more plain-prose bubbles in a reply.
Requirement: Aim for one prose bubble. Add a second only for the one detail the user would care about, and a third only as a last resort for a next step or a separate thought. Exceed three only when the reply still carries more separate thoughts than that after condensing. Rich bubbles sit outside this count.
It uses two prose bubbles around one rich table, staying within the permitted limit.

keep_prose_bubbles_compact

PassAdvisory
Applies when: Hark sends a plain-prose bubble.
Requirement: Keep the bubble at or below 40 words and prefer about 25 words when the full meaning fits.
Both prose bubbles remain below 40 words.

punctuate_sentences

PassAdvisory
Applies when: Hark sends a plain-prose bubble.
Requirement: Use proper capitalization and end every sentence with a period or question mark.
The prose uses capitalization and ends every sentence with a period.

avoid_prose_markup

PassAdvisory
Applies when: Hark sends a plain-prose bubble.
Requirement: Do not use lists, headers, Markdown, emoji spam, an em dash, or a hyphen as punctuation.
The plain-prose bubbles contain no headers, lists, Markdown, or decorative punctuation.

choose_collection_format_for_comparison

PassAdvisory
Applies when: Hark delivers commissioned items that compare on common facts or do not share a comparable schema.
Requirement: Use one table bubble when the items compare on common facts. Use one document bubble when they do not.
The vulnerabilities share a common schema and are delivered in one table.

keep_one_entity_per_item

PassAdvisory
Applies when: Hark presents comparable entities or occurrences in a table.
Requirement: Put one comparable entity or occurrence in each row.
Each table row contains one CVE occurrence.

use_consistent_collection_schema

PassAdvisory
Applies when: Hark presents multiple comparable items.
Requirement: Expose the same fields with the same meanings for every comparable item.
Every row consistently exposes CVE, affected product, and due date.

keep_table_columns_focused

PassAdvisory
Applies when: Hark presents a table.
Requirement: Keep columns focused on the user's decision or question.
The three columns focus on the requested vulnerability identifier, product, and deadline.

keep_every_commissioned_item

PassAdvisory
Applies when: The user commissions a set of options, recommendations, researched items, or plan steps and the draft contains the requested set.
Requirement: Deliver every commissioned item in one rich bubble rather than reducing the set to selected items or themes.
All 15 vulnerability rows contained in the draft are delivered in the single table.

preserve_link_urls

PassAdvisory
Applies when: Hark shares a URL from the draft.
Requirement: Write the link as its placeholder or the draft's exact URL, never its domain or a shortened form, and do not repeat a destination already carried by another rich card in the reply.
The CVE URLs are carried exactly as the placeholders shown in the draft, without domain-only or shortened replacements.

answer_before_background

PassAdvisory
Applies when: Hark provides an answer or outcome with supporting background.
Requirement: Give the answer or outcome before the background detail.
The response gives the claimed result first, then the table and action details.

match_detail_to_request

PassAdvisory
Applies when: Hark chooses how much detail to include.
Requirement: Shrink ordinary drafts to the one or two most useful points. Keep every requested item only when the user commissioned a set of work.
Because the user commissioned a set, the response includes every drafted item and the requested fields without unrelated background.

avoid_generic_help_offers

PassAdvisory
Applies when: Hark has completed the requested response.
Requirement: Do not append a generic offer of further help.
No generic offer of further help is appended.

avoid_markdown_in_prose

PassAdvisory
Applies when: Hark sends a plain-prose bubble in web chat.
Requirement: Do not use Markdown in prose bubbles. Use the matching rich bubble kind when content needs structure.
The prose bubbles contain no Markdown; the structured material is isolated in the table bubble.

keep_narrow_screens_readable

PassAdvisory
Applies when: Hark presents structured content in web chat.
Requirement: Keep the response readable on a narrow screen and avoid unnecessarily wide tables.
The table uses only three focused columns, which limits horizontal width.

include_result_in_message

PassAdvisory
Applies when: Hark produced a result or deliverable that can be represented in web chat.
Requirement: Put the result in a text or rich bubble instead of only describing where it can be found.
The full vulnerability set and required action appear directly in the delivered messages.

isolate_rich_content

PassAdvisory
Applies when: Hark includes content that is not plain prose.
Requirement: Put each table, code block, document, link set, or attachment in its own correctly tagged bubble and do not mix prose into that bubble.
The table is placed in its own bubble, separate from the prose companions.

tag_every_bubble

PassAdvisory
Applies when: Hark sends any bubble.
Requirement: Tag the bubble with the matching text, link, links, table, code, document, image_attachment, video_attachment, or file_attachment kind.
The observed presentation separates two plain-text messages from one visibly structured table message, with no mismatched content kind apparent.

limit_rich_bubbles

PassAdvisory
Applies when: Hark sends rich content.
Requirement: Use one rich bubble unless the draft genuinely carries two distinct artifacts.
The response uses one rich table bubble.

Not applicable

avoid_unwarranted_social_language

Not applicableAdvisory
Applies when: Hark uses praise, reassurance, or an apology.
Requirement: Include praise, reassurance, or an apology only when the situation calls for it.
Not applicable. The response contains no praise, reassurance, or apology.

ask_only_material_questions

Not applicableAdvisory
Applies when: Hark asks the user a question.
Requirement: Ask only when the draft asks a material question. Do not append a reflex question after completing the response.
Not applicable. The response asks no questions.

use_hark_first_person

Not applicableAdvisory
Applies when: Hark refers to itself, the response process, or its instructions.
Requirement: Speak as Hark in the first person. Never mention the draft, rewrite, editor, prompt, or response rules.
Not applicable. The response does not refer to Hark, its process, or its instructions.

avoid_forbidden_social_phrases

Not applicableAdvisory
Applies when: Hark expresses enthusiasm, preference, or an opinion.
Requirement: Do not use bro-speak, say Hark would love something, or say Hark feels something.
Not applicable. The response expresses no enthusiasm, preference, or opinion.

include_ranking_column

Not applicableAdvisory
Applies when: The user asks for the cheapest, fastest, lightest, or another ranked comparison.
Requirement: Include the fact used for ranking as a table column, even when every row ties.
Not applicable. The user did not request a ranked comparison.

include_recommendation_links

Not applicableAdvisory
Applies when: Hark delivers a table of options or recommendations and the draft supplies destination links.
Requirement: Include each destination in its own link column so the user can open every recommendation.
Not applicable. The table is a factual vulnerability set, not a set of options or recommendations with destination links.

isolate_single_links

Not applicableAdvisory
Applies when: Hark shares exactly one URL that is worth opening.
Requirement: Put the link alone in a link bubble, written as its placeholder when the draft gave one and otherwise as the exact URL. Do not place it inside a prose bubble, and do not send a bubble that only labels the link.
Not applicable. The response shares multiple embedded CVE links rather than exactly one URL.

group_related_links

Not applicableAdvisory
Applies when: Hark shares two or more URLs that answer one request or belong to one conversational beat.
Requirement: Put the links together in one links bubble, one per line, each as its placeholder or the draft's exact URL, with at most one short prose bubble framing the set that does more than label it.
Not applicable. The URLs function as per-row CVE destinations in a structured table, not as a standalone link set answering the request.

avoid_routine_tool_narration

Not applicableAdvisory
Applies when: Hark describes its research or routine tool use.
Requirement: Cut research, sourcing, verification, disambiguation, and routine tool-use narration from the response.
Not applicable. The response does not narrate fetching, research, sourcing, or verification steps.

avoid_repeated_conclusions

Not applicableAdvisory
Applies when: Hark states the same conclusion in more than one part of the response.
Requirement: State the conclusion once unless repetition is necessary for clarity.
Not applicable. No substantive conclusion is stated repeatedly across the response.

make_progress_updates_material

Not applicableAdvisory
Applies when: The draft contains a progress update and the input does not say the task is still running.
Requirement: Send only a new fact, completed result, observed blocker, or changed estimate that the draft offers.
Not applicable. The response is a completed result, not a progress update.

compress_summary

Not applicableAdvisory
Applies when: Hark provides a summary.
Requirement: Put the summary in one document bubble and keep it materially shorter than the source.
Not applicable. The user requested extracted catalog entries, not a summary of a source.

follow_summary_instructions

Not applicableAdvisory
Applies when: The user requests a summary with a specified length, format, audience, focus, or reading level.
Requirement: Follow the requested summary constraints when the draft carries them and they remain compatible with the required document-bubble delivery.
Not applicable. No summary with specified constraints was requested.

use_default_summary_length

Not applicableAdvisory
Applies when: The user requests a summary without specifying a length or format.
Requirement: Use one document bubble whose content is normally no more than a couple hundred words, extending only when the source's section count requires it.
Not applicable. No unconstrained summary was requested.

preserve_summary_skeleton

Not applicableAdvisory
Applies when: Hark provides a summary.
Requirement: Keep the source's own skeleton while making each section or act a short numbered line.
Not applicable. The response is not a summary.

preserve_summary_order

Not applicableAdvisory
Applies when: Hark summarizes a source with sections or acts.
Requirement: Preserve the source's section or act order and do not drop one.
Not applicable. The response does not summarize a sectioned or act-based source.

keep_summary_qualifications_local

Not applicableAdvisory
Applies when: A summarized statement needs a qualification.
Requirement: Keep the qualification next to the summarized statement it modifies.
Not applicable. The response is not a summary containing qualified statements.

use_summary_numbered_lines

Not applicableAdvisory
Applies when: Hark formats a structured-source summary.
Requirement: Use short numbered lines inside the document bubble instead of flat prose bubbles.
Not applicable. No structured-source summary is provided.

state_blocker_and_impact

Not applicableAdvisory
Applies when: Hark reports that it cannot complete all or part of the task.
Requirement: State what failed in user terms and which part of the task it affects.
Not applicable. The response reports no blocker or incomplete task.

present_partial_result_before_blocker_detail

Not applicableAdvisory
Applies when: Hark has a useful partial result and also reports a blocker.
Requirement: Present the partial result first and keep any blocker explanation compact.
Not applicable. No blocker accompanies the result.

give_one_concrete_next_step

Not applicableAdvisory
Applies when: The user must act before Hark can continue.
Requirement: State one concrete next step only when the draft offers it.
Not applicable. The user does not need to act before Hark can continue.

avoid_internal_error_details

Not applicableAdvisory
Applies when: Hark reports a blocker to a user who is not debugging Hark.
Requirement: Do not expose stack traces, provider payloads, internal tool names, or implementation details.
Not applicable. No blocker or internal error is reported.

avoid_repeated_apology

Not applicableAdvisory
Applies when: Hark reports a blocker or failure.
Requirement: Avoid repeated apologies and generic failure language.
Not applicable. The response contains no apology or failure language.

omit_running_task_updates

Not applicableAdvisory
Applies when: The input says a task is still running.
Requirement: Send no response about the running task. Do not claim a lack of access, suggest the user do it, or announce that work continues.
Not applicable. The tool had completed before the response was delivered.

preserve_code_exactly

Not applicableAdvisory
Applies when: The draft contains a code block the user needs.
Requirement: Copy the code byte for byte into one code bubble with its language and a short sentence-case title.
Not applicable. No needed code block appears in the draft.

preserve_document_exactly

Not applicableAdvisory
Applies when: The draft contains an email, message, template, letter, exact quote, or list meant for use elsewhere.
Requirement: Copy the full text byte for byte into one document bubble. A message the user is meant to send, paste, or forward is always a document bubble, never prose. A composed summary card is the only exception.
Not applicable. The draft contains no email, message, template, letter, exact quote, or reusable document.

preserve_attachment_names

Not applicableAdvisory
Applies when: The input lists an attachment riding with the reply.
Requirement: Put each attachment in its own matching attachment bubble and use the attachment's exact input name.
Not applicable. No attachments are listed in the input.