This is a scoped research dossier, not a completed systematic review or an independently tested result. It identifies methods, questions and source trails for future reporting.
Working context
A model sees selected instructions, recent turns and retrieved material. Omitted context and excess context can cause different classes of error.
Durable memory
A stored note is not automatically verified fact. A responsible design records its origin, freshness, sensitivity and deletion lifecycle.
Context crossing trust boundaries
Retrieved pages, code comments and tool results may contain instructions. The system must distinguish content from authority.
What would count as evidence?
Run contamination tests and track which retrieved item influenced each action.
Documents to examine
- OpenAI Agents SDK — Sessions
- OWASP — Excessive Agency
These are starting points, not claims that every document has been independently reproduced.
Read our cited field note →Edition 1.0 · 09 October 2026
Initial research brief published. No earlier revisions or submitted public corrections are claimed.
Suggest a documented correction ↗