Reading an Agent’s Report Before It Exists: A Pre-Execution Monitor at the ReAct Commit Point, and Why Most of Its Signal Was an Artifac
Juan Camilo Meléndez Torres, Gilber Alexis Corrales Gallego
Both publicly documented cases of OpenAI agents breaking containment in 2026
share a feature: the agent’s account of its own behaviour diverged from its ac-
tions. Runtime monitors that inspect a model’s internal state before it acts are
one proposed defence. We built one, tested it adversarially, and report that its
apparent signal was mostly measurement artifact. Our monitor reads the Jaco-
bian lens at a ReAct agent’s commit point, the position where the context ends
in ACTION: report and the message itself is still unpredicted, and blocks the
action when the probability mass over an honest-reporting lexicon falls below a
threshold. On a reactor-operator sandbox with Qwen2.5-1.5B-Instruct, the
monitor cleanly separates honest from evasive reports (4.95 % vs. 0.84 %/0.00 %),
blocks an induced lie before its first word is emitted, and a counterfactual replay
shows the blocked message driving the sandbox to failure. A control condition
designed to falsify our own result, an honest persona carrying the same trigger
vocabulary as the evasive ones, collapses to 1.27 %, below the decision threshold.
Roughly 90 % of the separation is explained by which lexicon words survive echo
suppression given the prompt. The residual compatible with intent is ∼10 % and is
not established. We release the harness, the falsification protocol, and three further
negative results. The transferable artifact is the vocabulary-matched control itself:
any lexical readout monitor should be required to pass it before its numbers are
believed.
No reviews are available yet
Cite this work
@misc {
title={
(HckPrj) Reading an Agent’s Report Before It Exists: A Pre-Execution Monitor at the ReAct Commit Point, and Why Most of Its Signal Was an Artifac
},
author={
Juan Camilo Meléndez Torres, Gilber Alexis Corrales Gallego
},
date={
},
organization={Apart Research},
note={Research submission to the research sprint hosted by Apart.},
howpublished={https://apartresearch.com}
}


