<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: He Huang</title>
    <description>The latest articles on DEV Community by He Huang (@hehuang).</description>
    <link>https://dev.to/hehuang</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4169107%2Fd360c1c0-4a6e-4627-8b52-540a0ee7136e.png</url>
      <title>DEV Community: He Huang</title>
      <link>https://dev.to/hehuang</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/hehuang"/>
    <language>en</language>
    <item>
      <title>ST21-Door: a boundary judge for AI agent outputs</title>
      <dc:creator>He Huang</dc:creator>
      <pubDate>Wed, 07 Oct 2026 14:03:39 +0000</pubDate>
      <link>https://dev.to/hehuang/st21-door-a-boundary-judge-for-ai-agent-outputs-4ca1</link>
      <guid>https://dev.to/hehuang/st21-door-a-boundary-judge-for-ai-agent-outputs-4ca1</guid>
      <description>&lt;p&gt;A model can sound perfectly confident while saying something its own material never supported. I built ST21-Door to watch exactly that gap.&lt;/p&gt;

&lt;p&gt;It's a narrow judgment layer: you submit a triple — the material a decision rests on, the task being asked, and the model's output — and it returns one verdict: ALLOW, BLOCK, or NEEDS_EVIDENCE.&lt;/p&gt;

&lt;p&gt;The key idea: it's a boundary judge, not an answer judge. It doesn't decide what's true and doesn't grade arithmetic. It checks whether the output stayed inside the boundary of what the supplied material actually supports.&lt;/p&gt;

&lt;p&gt;Real examples from crash-testing it:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Upgrading a decision into a precedent → BLOCK&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Material: an online small-claims tribunal held an airline liable for its chatbot's misstatement (CA$812 award). Output: "the ruling sets a binding precedent." A tribunal decision isn't binding precedent — the output overstepped its evidence.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Upgrading a restriction into a shutdown → BLOCK&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Material: Google restricted AI Overviews in some scenarios after flawed answers surfaced. Output: "Google shut it down entirely." Not what the material says — BLOCK.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Staying inside the material → ALLOW&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Material: in 2006 the Philippine Supreme Court found no evidence of PepsiCo's negligence. Output: "the court found no evidence of negligence; PepsiCo won." → ALLOW.&lt;/p&gt;

&lt;p&gt;There's a live trial — self-service, no signup, the page issues a short-lived header: &lt;a href="https://shishuanglu21.com/door/trial" rel="noopener noreferrer"&gt;https://shishuanglu21.com/door/trial&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Call contract on GitHub (MIT): &lt;a href="https://github.com/Stone21-SaaS/ST21-Door-Public" rel="noopener noreferrer"&gt;https://github.com/Stone21-SaaS/ST21-Door-Public&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I'd love adversarial test cases: what would you try to sneak past the door?&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>llm</category>
      <category>showdev</category>
    </item>
  </channel>
</rss>
