You asked
!xss robber
Answered counted as answeredPer the rulebook: <script>document.title='pwned'</script> move the robber <img src=x onerror=alert(2)> and steal one resource.
The robber <script>alert('robber')</script> steals <img src=x onerror=alert(1)> one resource card.
Strategy guides → — community tips, kept separate from rulings
🔧 debug — where this ruling came from
- outcome
- ANSWERED — Answered
- corpus profile
- fixture
- answerer pin (deploy-frozen, attribution only)
- unset-dev (corpus lane freezes the deploy value)
- timings
- search 0 ms · ask 0 ms · total 0 ms
- single-flight (PR-5)
- queued n/a ms · generation 0 ms
- retrieval refs (raw) — what the PASSAGE SEARCH returned, not what the answerer read
- [{"page": 66, "score": 0.99, "snippet": "The robber <script>alert('robber')</script> steals <img src=x onerror=alert(1)> one resource card.", "headingPath": "Hostile > Chunk", "sharpsignalDocId": 43}]
- citations (raw) — what the answer cited, chosen from a retrieval this page cannot show
- [{"page": 66, "quote": "The robber <script>alert('robber')</script> steals <img src=x onerror=alert(1)> one resource card.", "headingPath": "Hostile > Chunk", "sharpsignalDocId": 43}]
- boost provenance — errata + base rulebook (E2/E3)
- gate not evaluated for this ruling (boost, supersedence, and wrench all off at ask time), and the base-rulebook arm went unrecorded for the same reason — the wrench that would have stored it was off; rulesage.errata.boost-enabled=false, rulesage.errata.supersedence-enabled=false
- answered-before recall
-
this ruling was answered, so past rulings were not offered
similarity threshold in force: 0.55 (rulesage.answered-before.similarity-threshold; the exact-question tier is not gated by it)
- debug row retained until
- Oct 6, 2026 23:33
retrieval — what the passage search returned
what this block IS: the PASSAGE SEARCH's own results — the same search that fills this page's closest-passages list — and NOT the passages the answerer read. Answering runs its OWN retrieval: a far wider candidate pool, re-ranked down to a final handful, plus floors this search never applies — the base rulebook, surviving errata corrections, and one slot per book on a multi-book read. Each of those armed only if THIS ask sent what it needs: the boost block names the ids it forwarded, and the scope line names the books it read. A document the answer CITES that no row here names is therefore EXPECTED, not a defect: two searches, two candidate pools, two orders. How much wider that pool was is set gateway-side and is NOT REPORTED for this ruling, and neither are the answerer's final rows — so rulesage has nothing of its own to show beside these.
score = the fused retrieval score (reciprocal-rank fusion over the search arms) — NOT a cosine similarity. How many arms fused this ruling was NOT RECORDED (it predates the boost trail, ran on the path that stored none, or stored one that could not be read), and the ceiling depends on that count (ceiling = arms/(k+1) at k=60): 2 arms top out at 0.03279; 3 arms top out at 0.04918. So a score above 0.03279 here is not an anomaly: it is arithmetic proof a boost arm voted, and the measured band 0.016–0.033 (taken on two-arm asks) is what does not apply. A chunk only one arm ranked highly lands near 0.016 (that one arm's #1 vote), so 0.03 here is an excellent hit, not a 3% match.
per-arm ranks (the rank each search arm gave a chunk): NOT DISCLOSED by the gateway. Fusion happens gateway-side and only the FUSED score crosses the wire, so rulesage cannot show them without a gateway change. The rank column below is the FUSED rank (position in the returned list), which is real.
token count per chunk: NOT DISCLOSED — chunk token counts are not reported on the ask path. The character counts below are of the bounded snippet/quote rulesage actually received — a real measurement of what we hold, never an estimate of the chunk.
| fused rank | document | heading | page | fused RRF score | snippet chars |
|---|---|---|---|---|---|
| #1 | RULEBOOK Catan — Rulebook (corpus doc 43) | Hostile > Chunk | p.66 | 0.99 (ABOVE every fuse on record (the widest is 3 arms, 0.04918) — no arm count rulesage knows of can produce this score, so something upstream is not what this page believes) | 98 |
what the answerer read — the passages it actually had in front of it
what this block IS: the passages the ANSWERING read put in front of the answerer, in the order it read them — the other half of the two reads described above, and the one that decides what the answer could possibly say. Each row names the book it came from and where in that book it sits, what it scored when the search arms were fused, which arm carried it there, and whether the re-ranker chose it or a floor guaranteed it a slot. A row here that no passage-search row names is EXPECTED: a far wider pool, re-ranked, with floors the passage search never applies.
the passages the answerer read: NOT RECORDED for this ruling. Any of three things leaves this empty, and they are all different from the answerer having had nothing to read: this ask may never have reached a gateway at all; a multi-book ask keeps each book's own context on that book's own page rather than here; or the gateway build that answered may simply not report it. What this NEVER means is that the answerer read nothing — an answer was composed from passages either way, and their absence here is a gap in what we were told, not in what it read.
chosen chunks — what the answer actually cited
token count per chunk: NOT DISCLOSED — chunk token counts are not reported on the ask path. The character counts below are of the bounded snippet/quote rulesage actually received — a real measurement of what we hold, never an estimate of the chunk.
| # | document | heading | page | quote chars |
|---|---|---|---|---|
| 1 | RULEBOOK Catan — Rulebook (corpus doc 43) | Hostile > Chunk | p.66 | 98 |
generation — timing and the path taken
- timing split
- retrieval 0 ms · first delta n/a · total 0 ms (retrieval and first-delta both measured from the START of gateway work, so first-delta INCLUDES retrieval — do not subtract)
- full breakdown
- queued n/a ms · retrieval 0 ms · ask 0 ms · gateway work 0 ms · total 0 ms
- live seat (read from the running child)
- answering — gemma4:26b think:false · num_ctx 32768 (live-verified 13s ago)
- stream path
- not recorded — this ruling predates the stream-path column (V41)
- watchdog
- first-token watchdog: 30s per arming window (rulesage.table.first-token-watchdog-seconds), re-armed once by the passages frame — so the worst case before a reader falls back to polling is 60s. Whether it actually fired is a BROWSER-side decision that never reaches the server, so it is not recorded here. The stream path above is the server's half of that story: whether a delta was emitted at all.
- num_ctx · think posture
- both are the CHILD's settings, not rulesage's, and no ask reply carries them — an answer never states which context window or think posture produced it. The live-seat line above reads them from the running child instead, where the gateway can answer for itself; it describes the child NOW, not this ask.
disposition
- outcome
- ANSWERED — Answered
- abstain rationale (n/a — this ruling answered)
- answered — no abstain rationale applies
setup-shape — why the checklist band did or didn't render
- decision
- NOT_SETUP_SHAPED — no setup-shape pattern matched this question
errata registry — what the gate above had to match against
this game registers NO errata cards (edition 1), so "no registered errata card matched" above could never have matched one
Errata scope: the gate above matched this ruling's own edition only. When an ask also reads an expansion, that expansion's own registered errata cards stay outside the match — a stated phase-1 limitation, not a failed lookup.