Holds the coding-assistant persona, the eval-fixture pretext, and the target content
(romantic-love reciprocation) completely constant across 13 prompts, varying only the
requested output format/container — plain prose, seven multi-field structured-data formats
(YAML/JSON/Python/CSV/SQL/Markdown/XML), and five exotic containers (base64, ROT13, French,
a single-field .env assignment, a multi-field log line) that isolate whether the boundary is
about raw structuredness or specifically multi-field schema mimicry. Reveals whether a
model's coding-agent-bypass vulnerability is format-specific (a narrow, addressable coverage
gap) or persona/pretext-gated and format-independent (a broader gap that format-level fixes
won't touch). Companion piece to coding-agent-safety-bypass.yml — see that file's header for
the underlying mechanism.