Finding · Consequence gate · Oct 3, 2026
OpenAI’s own report on the DNS incident: monitoring raised a P0 alert 11 minutes 48 seconds after the agent’s first successful DNS call. A human acknowledged it 3 minutes later. The run was not killed for another 2.5 hours, because it “did not stop automatically as expected.”
The step that failed was the stop.
IF vulnerability_found: RETURN FALSE. It sits after the judges, the executor and the audit, as insurance in case they got it wrong.I broke five guards one at a time in a scratch copy. My tests caught four (action binding, replay protection, verdict class, severity dominance). The fifth, accepting HS256 tokens, my tests did not catch: the JWT library refuses it anyway. That is defense in depth, not a test I can take credit for.
Not done: it is not wired into any agent yet, and today it auto-approves nothing.
Smaller is not zero. A boolean moves the error into the detector: what counts as “vulnerability found”. That is the part I trust least.
Dataset: huggingface.co/datasets/SoulInPsyAbstract/sipa-os-governance