Shadow Commit
Yash Thapliyal · Team G0ldenBear
Submitted to AI Control Hackathon 2026. Sprint projects are early-stage work by participants, not Apart Research publications.
AI agents lie. ShadowCommit catches them.
When an untrusted AI agent proposes a bash command, it also submits a signed commitment: "I will only touch these files, read no secrets, make no network calls." ShadowCommit runs the command in an isolated shadow copy of the environment, measures what actually happened, and compares the two. If the agent lied, the command is blocked before it ever touches the real environment.

Reviews
Summary: The project aims to prevent malicious attacks (bash commands) by (1) getting agents to make commitments about commands that are run and its consequences (e.g., which files will be modified) and (2) executing the command in a sandbox environment and comparing the commitment to the actual effects of the command in the sandbox. This protocol outcompetes text monitoring on malicious commands that have been obfuscated.
Strengths: I like the protocol of commitment + validation --- I believe it's novel and interesting! The report is also really well presented and complete.
The main limitation seems to be the performance. So far the protocol has to run every command in a sandbox which is unrealistically costly. A good cost analysis could help. Additionally, I think text monitors could be improved substantially (e.g., by prompting the monitor to flag commands that it does not understand).
Read full reviewShow less
Good idea overall, but without sys-call level observation it's going to be hard to provide anything but a false sense of security.
Cite this project
@misc{thapliyal2026shadow,
title = {{Shadow Commit}},
author = {Yash Thapliyal},
year = {2026},
month = mar,
note = {Submitted to AI Control Hackathon 2026, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/shadow-commit-0vhf}},
url = {https://apartresearch.com/sprints/projects/shadow-commit-0vhf}
}More from AI Control Hackathon 2026
- 1st placeLinuxArena track winnerView project: Omission Attacks: When Doing Nothing Is the Attack
Omission Attacks: When Doing Nothing Is the Attack
MAIA
AI control protocols monitor agent actions to detect sabotage, but omission attacks exploit what the agent fails to do rather than what it does. We define omission attacks as security breaches caused by failing to …
- 2nd placeView project: Detecting LLM Subversion in Vulnerability Patching Settings
Detecting LLM Subversion in Vulnerability Patching Settings
Vuln4Control
LLMs are increasingly used to propose fixes to vulnerabilities in code. If the LLM is misaligned or untrustworthy, it may propose fixes that seem to fix a vulnerability but leave the core issue unresolved in a subtle …
- 3rd placeView project: ActionLens: Pre-Execution Environment Probing for Agent Action Approval
ActionLens: Pre-Execution Environment Probing for Agent Action Approval
Udbhav&Ashok
ActionLens is a pre-execution control protocol for shell and file actions proposed by AI agents. Instead of approving an action from transcript alone, a trusted monitor gathers lightweight environment evidence before …