{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp09_archetype_breadth150_20260804","research_id":"eoa_inverse_innovation_exp09_light_prior_art_20260804","cell_id":"activation_decay_measurement__computer_science","search_lanes":{"direct_problem_and_intervention":{"queries":["security pre-brief decay asynchronous pull request reviewer reactivation","pull request security review checklist authorization OWASP code review"],"source_ids":["SRC2","SRC3"],"no_result_note":"No direct implementation of the complete baseline-to-delay-profile-to-expiry-to-reactivation lifecycle was found."},"synonyms_and_historical_terms":{"queries":["prospective memory workplace interruptions reminders delayed intention","delayed-execute prospective memory contextual reinstatement interruption"],"source_ids":["SRC4"],"no_result_note":null},"products_practices_and_standards":{"queries":["site:docs.github.com pull request reviews about pull request reviews","security checklist reminders code review pull request just in time"],"source_ids":["SRC1","SRC2"],"no_result_note":null},"component_combination":{"queries":["empirical security checklist code review vulnerability detection experiment developers","security focus cue checklist vulnerability detection code review","interruptions contextual reminders delayed intention task performance"],"source_ids":["SRC3","SRC4"],"no_result_note":null}},"sources":[{"source_id":"SRC1","title":"Pull request reviews","publisher":"GitHub Docs","url":"https://docs.github.com/en/pull-requests/reference/pull-request-reviews","source_type":"FIRST_PARTY_PRODUCT","claims_supported":["GitHub supports requesting reviews from designated people or teams and notifies requested reviewers.","Pull-request reviews record comments, approvals, and change requests before merge.","The documented workflow does not measure whether a prior security cue remains cognitively active or assign cue-expiry states."]},{"source_id":"SRC2","title":"Secure Code Review Cheat Sheet","publisher":"OWASP Foundation","url":"https://cheatsheetseries.owasp.org/cheatsheets/Secure_Code_Review_Cheat_Sheet.html","source_type":"OFFICIAL_GUIDANCE","claims_supported":["Manual secure code review is an established practice for finding vulnerabilities requiring contextual human judgment.","OWASP identifies pull requests and commits as targets for diff-based security review.","Established review steps include entry-point analysis, data-flow tracing, authorization verification, and checking modified trust boundaries."]},{"source_id":"SRC3","title":"Less is More: Supporting Developers in Vulnerability Detection during Code Review","publisher":"ACM International Conference on Software Engineering / University of Glasgow repository","url":"https://eprints.gla.ac.uk/273444/","source_type":"PRIMARY_RESEARCH","claims_supported":["A controlled online experiment with 150 participants found that explicitly asking reviewers to focus on security substantially increased vulnerability detection.","Developers can miss familiar, comparatively easy-to-detect vulnerabilities during review.","Adding a tailored security checklist did not significantly improve results beyond the explicit security-focus instruction, showing both the relevance and limitations of review cues."]},{"source_id":"SRC4","title":"The Role of Interruptions and Contextual Associations in Delayed-Execute Prospective Memory","publisher":"Applied Cognitive Psychology / Wiley","url":"https://www-personal.umd.umich.edu/~acfoos/pub/2014_acp.pdf","source_type":"PRIMARY_RESEARCH","claims_supported":["Three experiments found that interruption impaired execution of delayed intentions relative to a no-interruption condition.","Reinstating the prevailing context after interruption alleviated some impairment.","The results support contextual associations and reminders as mechanisms for completing delayed intentions, but concern general laboratory tasks rather than security code review."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The component problem is visible: pull-request review separates review requests from later review decisions; authorization and trust-boundary inspection are established secure-review targets; developers can miss vulnerabilities; explicit security focus can improve detection; and interruptions can impair delayed intentions. The sources do not establish that this specific four-step authorization routine decays predictably over ordinary pull-request queue delays, so the proposed time-based expiry mechanism remains unverified.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"closest_prior_art":[{"name":"Explicit security-focus instruction and tailored checklist experiment","source_ids":["SRC3"],"overlap":"Defines a security-oriented cue, applies it to controlled code-review tasks, and measures vulnerability-detection performance.","remaining_difference":"It does not measure immediate versus delayed performance, fit a cue-freshness profile, establish an expiry threshold, or test reactivation after expiry."},{"name":"Delayed-execute prospective-memory testing with contextual reinstatement","source_ids":["SRC4"],"overlap":"Experimentally combines delayed intentions, interruptions, performance probes, and contextual reinstatement as a reminder mechanism.","remaining_difference":"It does not concern pull requests, authorization inspection, repository workflow states, empirically governed refresh timing, or exposure-as-readiness claims."},{"name":"OWASP diff-based secure-review methodology and checklists","source_ids":["SRC2"],"overlap":"Prescribes manual inspection of entry points, data flow, authorization, and modified trust boundaries in pull requests and commits.","remaining_difference":"It supplies review content but does not measure cue activation, delayed decay, usable lifetime, reactivation efficacy, or expiry."},{"name":"GitHub requested-review and approval workflow","source_ids":["SRC1"],"overlap":"Provides the assignment, notification, recorded-review, and merge-control substrate for asynchronous pull-request review.","remaining_difference":"It records review requests and decisions rather than the freshness of a security-review cue or performance of a defined inspection routine."}],"prior_art_disposition":"ADJACENT_PRIOR_ART","contrastive_claim_remaining":"For a defined authorization-boundary inspection routine, routine-specific performance has a reproducible and practically relevant relationship with elapsed time and intervening context switches after a pre-brief; a preregistered expiry boundary derived from matched delayed probes identifies when exposure no longer supports a readiness inference; and one active, context-matched restatement after that boundary restores performance relative to no refresh. The retained prior art covers security-focus cues, checklists, delayed intentions, interruptions, and contextual reinstatement separately, but not this complete repository-governed lifecycle.","contrastive_claim_falsifier":"The contrastive claim fails if matched synthetic reviews show no practically relevant decline across realistic queue delays; elapsed time adds no explanatory value beyond task difficulty, expertise, and interruption load; a stable expiry boundary cannot be estimated with useful uncertainty; or the active restatement does not improve the preregistered authorization-localization proxy relative to a matched no-refresh condition, including if it increases distraction or false findings enough to offset any benefit.","gates":{"adequate_source_search":{"status":"PASS","rationale":"The bounded search covered the proposal directly, prospective-memory and delayed-execute terminology, official pull-request and secure-review practices, controlled security-cue experiments, and interruption-plus-context-reinstatement combinations. Four opened sources span GitHub, OWASP, ACM/University of Glasgow, and Wiley and include first-party, official-guidance, and primary-research sources.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"supported_problem":{"status":"PASS","rationale":"Evidence supports vulnerability misses during review, benefits from explicitly focusing reviewers on security, established authorization-review targets, and impairment of delayed intentions by interruption. Because routine-specific decay over pull-request queue delays is not directly demonstrated, support is partial rather than complete.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"distinct_testable_claim":{"status":"PASS","rationale":"The remaining claim distinguishes ordinary prompts and checklists from a measured lifecycle with immediate baseline, matched delayed probes, a preregistered expiry boundary, active contextual restatement, and a no-refresh comparator. Its outcomes and failure conditions are observable.","source_ids":["SRC2","SRC3","SRC4"]},"bounded_next_test":{"status":"PASS","rationale":"A small preregistered sandbox experiment can use consenting reviewers, synthetic diffs, a bounded set of delay and context-switch conditions, one capped restatement intervention, and routine-specific localization and latency outcomes without changing production controls.","source_ids":["SRC3","SRC4"]},"no_obvious_safety_or_authority_stop":{"status":"PASS","rationale":"The proposed first test is confined to synthetic tasks with informed consent, preserves repository-maintainer and application-security authority, excludes employment use and covert monitoring, makes no production-safety certification, and leaves merge controls unchanged. No retained source reveals an obvious stop to that bounded design.","source_ids":["SRC1","SRC2","SRC3","SRC4"]}},"screen_survival":true,"world_novelty_boundary":"This bounded four-source public-web screen found adjacent research and established practices but no complete match. It cannot establish world novelty, patentability, market size, expert acceptance, production effectiveness, realized value, or the absence of undiscovered papers, patents, products, standards, or internal organizational practices."}