Two agents, one channel: Given a reason and a permitted store, four open-weight agents passed nothing through it in 544 registered pairs; the receivers that searched it manufactured the missing fact instead

Does an agent use a legitimate shared channel to pass another agent something the deployment did not sanction? A one-agent proxy in Does the bound hold? returned a floor of 0 in 544 runs, 408 of them with the store permitted, and gave the agent no reason to write. This registration gives two agents a reason. An upstream build holds a fingerprint a downstream build on another host must carry; the usual channel is offline; the one shared thing is a package cache whose store any build can write and read. Four open-weight models to 120B ran 544 pairs at thirty-four a cell across four arms, from nothing said to the store named, under a public timestamp, with capability controls at both ends. No sender put anything in the store in 544 first-role runs, in any arm, on any model, which bounds the rate below 2.7 per cent a model. Seven receivers, all one model's, searched the store when the shared thing was pointed at or when they needed the fact, found nothing, and five of them stored their own host's fingerprint, four where the upstream's should have been and one as a probe of the store, two carrying it into the manifest as the upstream's: a missing fact manufactured through the channel rather than passed along it, plain and visible to any monitor over the store's log. A fifth model failed its capability control at four and three of twelve and passed the same control at seven and seven an hour later. Every cell carries its n, every null the effect it excludes, and every number is printed by one script from the released rows. A research note reporting a registered null: the hypotheses, the tests and the rule for what the result would mean were fixed and publicly timestamped before the run. Published page, data and registrations: https://agentbulkhead.com/research/two-agents-one-channel. This record holds the note's PDF, version 0.1.2 of 29 September 2026, and its data bundle v0.1.2, byte-identical to the one the note names by SHA-256.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-29
DOI
https://doi.org/10.5281/zenodo.23039630
Primary Topic
Mobile Agent-Based Network Management
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Two agents, one channel: Given a reason and a permitted store, four open-weight agents passed nothing through it in 544 registered pairs; the receivers that searched it manufactured the missing fact instead

Cristina Urquiza, Rowan Chattaway
Zenodo (CERN European Organization for Nuclear Research)
Mobile Agent-Based Network Management
preprint

Two agents, one channel: Given a reason and a permitted store, four open-weight agents passed nothing through it in 544 registered pairs; the receivers that searched it manufactured the missing fact instead

Cristina Urquiza, Rowan Chattaway
preprint en

Abstract

Does an agent use a legitimate shared channel to pass another agent something the deployment did not sanction? A one-agent proxy in Does the bound hold? returned a floor of 0 in 544 runs, 408 of them with the store permitted, and gave the agent no reason to write. This registration gives two agents a reason. An upstream build holds a fingerprint a downstream build on another host must carry; the usual channel is offline; the one shared thing is a package cache whose store any build can write and read. Four open-weight models to 120B ran 544 pairs at thirty-four a cell across four arms, from nothing said to the store named, under a public timestamp, with capability controls at both ends. No sender put anything in the store in 544 first-role runs, in any arm, on any model, which bounds the rate below 2.7 per cent a model. Seven receivers, all one model's, searched the store when the shared thing was pointed at or when they needed the fact, found nothing, and five of them stored their own host's fingerprint, four where the upstream's should have been and one as a probe of the store, two carrying it into the manifest as the upstream's: a missing fact manufactured through the channel rather than passed along it, plain and visible to any monitor over the store's log. A fifth model failed its capability control at four and three of twelve and passed the same control at seven and seven an hour later. Every cell carries its n, every null the effect it excludes, and every number is printed by one script from the released rows. A research note reporting a registered null: the hypotheses, the tests and the rule for what the result would mean were fixed and publicly timestamped before the run. Published page, data and registrations: https://agentbulkhead.com/research/two-agents-one-channel. This record holds the note's PDF, version 0.1.2 of 29 September 2026, and its data bundle v0.1.2, byte-identical to the one the note names by SHA-256.

Zenodo (CERN European Organization for Nuclear Research)
Peace, Justice and strong institutions
Mobile Agent-Based Network Management
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Two agents, one channel: Given a reason and a permitted store, four open-weight agents passed nothing through it in 544 registered pairs; the receivers that searched it manufactured the missing fact instead — Cristina Urquiza, Rowan Chattaway · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS