RuleSage cited table rulings
← Catan

You asked

!xss robber

Answered counted as answered

Per the rulebook: <script>document.title='pwned'</script> move the robber <img src=x onerror=alert(2)> and steal one resource.

RULEBOOK Catan — Rulebook · p.66 · Hostile > Chunk
The robber <script>alert('robber')</script> steals <img src=x onerror=alert(1)> one resource card.

Strategy guides → — community tips, kept separate from rulings

🔧 debug — where this ruling came from
outcome
ANSWERED — Answered
corpus profile
fixture
answerer pin (deploy-frozen, attribution only)
unset-dev (corpus lane freezes the deploy value)
timings
search 0 ms · ask 0 ms · total 0 ms
single-flight (PR-5)
queued n/a ms · generation 0 ms
retrieval refs (raw)
[{"page": 66, "score": 0.99, "snippet": "The robber <script>alert('robber')</script> steals <img src=x onerror=alert(1)> one resource card.", "headingPath": "Hostile > Chunk", "sharpsignalDocId": 43}]
citations (raw)
[{"page": 66, "quote": "The robber <script>alert('robber')</script> steals <img src=x onerror=alert(1)> one resource card.", "headingPath": "Hostile > Chunk", "sharpsignalDocId": 43}]
boost provenance — errata + base rulebook (E2/E3)
gate not evaluated for this ruling (boost, supersedence, and wrench all off at ask time), and the base-rulebook arm went unrecorded for the same reason — the wrench that would have stored it was off; rulesage.errata.boost-enabled=false, rulesage.errata.supersedence-enabled=false
answered-before recall
this ruling was answered, so past rulings were not offered
similarity threshold in force: 0.55 (rulesage.answered-before.similarity-threshold; the exact-question tier is not gated by it)
debug row retained until
Oct 6, 2026 23:33

score = the fused retrieval score (reciprocal-rank fusion over the search arms) — NOT a cosine similarity. How many arms fused this ruling was NOT RECORDED (it predates the boost trail, ran on the path that stored none, or stored one that could not be read), and the ceiling depends on that count (ceiling = arms/(k+1) at k=60): 2 arms top out at 0.03279; 3 arms top out at 0.04918. So a score above 0.03279 here is not an anomaly: it is arithmetic proof a boost arm voted, and the measured band 0.016–0.033 (taken on two-arm asks) is what does not apply. A chunk only one arm ranked highly lands near 0.016 (that one arm's #1 vote), so 0.03 here is an excellent hit, not a 3% match.

per-arm ranks (the rank each search arm gave a chunk): NOT DISCLOSED by the gateway. Fusion happens gateway-side and only the FUSED score crosses the wire, so rulesage cannot show them without a gateway change. The rank column below is the FUSED rank (position in the returned list), which is real.

token count per chunk: NOT DISCLOSED — chunk token counts are not reported on the ask path. The character counts below are of the bounded snippet/quote rulesage actually received — a real measurement of what we hold, never an estimate of the chunk.

fused rankdocumentheadingpage fused RRF scoresnippet chars
#1 RULEBOOK Catan — Rulebook (corpus doc 43) Hostile > Chunk p.66 0.99 (ABOVE every fuse on record (the widest is 3 arms, 0.04918) — no arm count rulesage knows of can produce this score, so something upstream is not what this page believes) 98

token count per chunk: NOT DISCLOSED — chunk token counts are not reported on the ask path. The character counts below are of the bounded snippet/quote rulesage actually received — a real measurement of what we hold, never an estimate of the chunk.

#documentheadingpagequote chars
1 RULEBOOK Catan — Rulebook (corpus doc 43) Hostile > Chunk p.66 98
timing split
retrieval 0 ms · first delta n/a · total 0 ms (retrieval and first-delta both measured from the START of gateway work, so first-delta INCLUDES retrieval — do not subtract)
full breakdown
queued n/a ms · retrieval 0 ms · ask 0 ms · gateway work 0 ms · total 0 ms
live seat (read from the running child)
answering — gemma4:26b think:false · num_ctx 32768 (live-verified 47s ago)
stream path
not recorded — this ruling predates the stream-path column (V41)
watchdog
first-token watchdog: 30s per arming window (rulesage.table.first-token-watchdog-seconds), re-armed once by the passages frame — so the worst case before a reader falls back to polling is 60s. Whether it actually fired is a BROWSER-side decision that never reaches the server, so it is not recorded here. The stream path above is the server's half of that story: whether a delta was emitted at all.
num_ctx · think posture
both are the CHILD's settings, not rulesage's, and no ask reply carries them — an answer never states which context window or think posture produced it. The live-seat line above reads them from the running child instead, where the gateway can answer for itself; it describes the child NOW, not this ask.
outcome
ANSWERED — Answered
abstain rationale (n/a — this ruling answered)
answered — no abstain rationale applies
decision
NOT_SETUP_SHAPED — no setup-shape pattern matched this question

this game registers NO errata cards (edition 1), so "no registered errata card matched" above could never have matched one

Errata scope: the gate above matched this ruling's own edition only. When an ask also reads an expansion, that expansion's own registered errata cards stay outside the match — a stated phase-1 limitation, not a failed lookup.