Did the agent’s own actions leak into its record of what happened?
You ship agentic systems. A trace interleaves collected observations — tool results — and the model’s own generated turns. The unspoken fear: the agent’s generated actions get recorded and later treated as collected fact. The system trusting its own output as the world.
the pain
It is silent and it compounds. A generated action is written into the record; a later step reads it back as an observation; the agent builds on its own invention as if it were something it saw. Nothing errors. The trace looks complete. There is no line in it that says “this part was observed, that part was authored.”
the process today
You log the trace, run evals, add guardrails, and trust the architecture to keep the two kinds of content separate. What you don’t have is any measure of whether generated content contaminated the record of observed fact — and no way to re-derive, from the trace itself, that the boundary held.
the cost
A contaminated trace produces confident, wrong actions whose origin can’t be traced back. Provenance and lineage are a funded 2026 governance pillar with no underlying primitive to point at. And if you can’t separate what the system observed from what it generated, you can’t defend the risk rating of any model that consumes the trace — the contamination flows straight into a tier you have to justify. Prove the boundary held, recomputably, before the trace feeds anything regulated.
the exhibit — recompute it yourself
corpus: trace-commons/agent-traces (Hugging Face, CC-BY, 2026-06) · 28 donated coding-agent session traces · certified field = 4,262 observed (eligible) events; 7,499 model-generated events withheld; 11,761 events total · protected geometry: the self-authorship axis. Register: detection — byte-decidable. Any leak changes the digest; no floor, no null and no ranking is needed to see it.
This register used to read “localized”, and that was an overclaim — ours, corrected here. The claim was that the geometry independently nominates the self-authorship axis. It cannot: n_tool_use is a structural zero in the observed field — a tool_result block cannot contain a tool_use block, so the axis carries no variance by construction, 18 of 21 cells tie at ∞, and any rank among them is decided by sort order, not geometry. It is also a diagonal — a variance term, not a coupling — so under the convention this site now uses for coupling claims it is not in the ranking at all. Two independent reasons the statistic does not exist. On the one agent corpus where it does exist (Wikipedia, where the human/bot boundary is real rather than definitional) the same test fails at 0.32×. Detection is the stronger claim and the one the evidence carries. How this class of correction was caught — the record.
The reference here is a community dataset — trace-commons, best-effort anonymized. Its provenance is checkable at a public source, and it checks out: rebuilt from the raw public Hugging Face session files, this card's own digit reproduces byte-for-byte — 67a6f95e… — as do the declared leak (c3aee30b…) and the single-residual state (7fbb9ec5…), with │Δg│ = 85.7740 against the kit's declared 85.77404440471331. Three published digits, three matches, from bytes anyone can download. This page previously said its provenance was “attested by the certificate rather than checkable at a public source”; that was understated and is corrected here.
The trace changed — its order changed. The certified self-authorship geometry did not move, to the byte.
This red is a deliberate leak we inject as a brake test — proof the instrument rings on exactly this boundary, not an incident that happened.
recompute fingerprint — the value the kit’s verify step reproduces from the artifact, byte-for-byte on any engine that follows the kit’s published canonicalization · sha256 =
67a6f95ee308a2884f73e071ed72bfb0326ba1b7d6da08a147e6ef10394009aa
The GREEN before/after and the RED
“before” above are this same clean fingerprint; the RED “after” is the identical recompute
with the withheld generated turns leaked in.
You recompute the geometry, the byte-identical benign baseline, and the declared tamper yourself — no trust asked. That those vectors are drawn only from the named reference is attested by the certificate; here the reference is public, and it has been checked at the source.
Recompute it yourself — in your tab
The digit above (67a6f95e…) is the number habitat published for this trace. Recompute it here from the trace's own vectors — nothing leaves your tab — then try to fool it: reshuffle the steps and it holds; change a step and it moves.
what just happened
habitat read this trace once, on our engine, and reduced it to a small set of vectors — the geometry of how its steps relate. From those your browser recomputed one number: the covariance, conditioned and inverted (math.fsum → Gauss-Jordan inverse → SHA-256), ~40 lines of public arithmetic, nothing sent. Built from the relationships, not the order — so a reshuffle leaves it identical, a real change moves it. The reading (text → geometry) is the method; it stays on our engine, the recompute is yours.
what this proves — and what it doesn't
Proves: the published number falls out of the trace's own vectors — reproduced byte-for-byte, no server; and it's not a checksum (survives a benign reshuffle, moves on a real change).
Doesn't: not tamper-proof, not authenticity. Same number = same relationships, not the same bytes: a uniform shift, or a change finer than the arithmetic's floor, is invisible by design, and a dataset engineered to share those relationships would pass. Self-served (our page, our vectors); the independent version is the downloadable kit against a separately-published fingerprint. And it's this published trace, not your data — reading your data into geometry runs on our engine, not your tab.
This corpus’s noise floor has its own readout on the site’s second instrument — pre-built for this card, or run on your own data, in your tab: trace your noise →
the relief
Run it on your own agent’s trace, in tandem: a certificate — recomputable by whoever asks — that no generated action leaked into the record of observed fact, decidable to the byte on the self-authorship signature. It satisfies a customer-trust review because the customer can recompute it themselves. Your architecture stands, and gains a primitive the governance pillar was missing.
what this does not prove
The certificate attests that the observation/generation boundary held within a declared frame. It does not say the agent is correct, or that its observations are true. It detects a boundary violation; it is not a correctness guarantee. A clean certificate means the machine didn’t confuse its own voice for the world — not that the world it saw was right.
Your architecture stands. This is the caliper for “did the machine’s own voice contaminate what it treats as fact?” Measure it yourself; recompute it anywhere.
verify this receipt in your browser
This case's receipt records its verdict and both digests above, and carries its own SHA-256. Recompute it here — WebCrypto, in your tab, nothing sent — and it matches; alter one character of a copy and it fails. It is the smallest version of the whole move: recompute, don't trust. The geometry digest itself you can recompute above, in this tab, or on your bench from the kit.
published fingerprint ·
or download this receipt and check it on your bench:
receipt-agent-trace.json
— shasum -a 256 prints the same number. Every receipt is on
the ledger.
request the kit
The recompute kit for this case — artifact, manifest, verify.py. A person sends it: the kit and its
verification steps arrive by reply, usually within a business day.
← Receipts · Docs · Ledger