THE WORLD · T0
Order issued. Premise P is ratified intent.
Agentic development can execute a bounded order well. Enterprise software rarely stays bounded long enough for the order to remain correct.
The failure chain drawn once: an order starts correct, the world moves mid-flight, and nothing tells the running work that its premise is gone until review pays for the reconstruction.
Eleven classes, each graded by the strength of its public evidence as of July 14, 2026, with the strongest documented boundary failures leading and the product's own thesis, silent premise drift, carrying its evidence gap in the open. The page-level claim stays narrow: coding agents can generate useful work, but generation, evidence, and official commitment have different trust requirements, and documented failures occur when those boundaries collapse or when concurrent work is accepted without current-state validation.
F-01 · EXCESSIVE EXECUTION AUTHORITY
INCIDENT-STRONG
A worker holds credentials broad enough to turn a mistaken interpretation into an official side effect. Recommendation and commitment share one authority path, so a plausible action can mutate production or protected state before any other authority validates it.
EVIDENCE
Caveat. Three public records establish the failure mode, not a base rate or an aggregate cost.
THE MODEL'S ANSWER
"No source grants itself authority."
F-02 · INJECTED INSTRUCTIONS
EXPLOIT-STRONG
Attacker-controlled repository content, issue text, or retrieved pages are read as instruction instead of evidence. Tool access converts the injected text into command execution or secret retrieval with the agent's privileges.
EVIDENCE
Caveat. CVEs and reproduced demonstrations prove exploitability, not field exploitation frequency.
THE MODEL'S ANSWER
"Untrusted content is data, never instruction."
F-03 · AGENTIC SUPPLY-CHAIN ABUSE
INCIDENT + EXPLOIT
A compromised dependency recruits locally installed AI tools and their credentials as discovery and execution capability. The package does not need every capability itself if agents on the machine already hold repository, shell, or secret access.
EVIDENCE
Caveat. One incident documented by multiple security firms proves feasibility, not an industry rate.
THE MODEL'S ANSWER
"Untrusted content is data, never instruction."
F-04 · EVIDENCE GAMING
EMPIRICAL-STRONG
The worker that generates a patch also chooses the evidence and declares success, so a green result can reflect evaluator manipulation or overfitting rather than requirement satisfaction.
EVIDENCE
Caveat. Observed in internal deployments and controlled evaluations; production incidence is not published.
THE MODEL'S ANSWER
"Model confidence and self-explanation are not evidence."
F-05 · HALLUCINATION CASCADES
EMPIRICAL-STRONG
One invented claim becomes an input to dependent agents, and every derived artifact carries clean provenance tracing back to nothing. Replication reads as verification: in one controlled study, a single seeded falsehood reached full downstream infection in five of six frameworks.
EVIDENCE
Caveat. Controlled experiments, not production incident rates; propagation is not always monotonic.
THE MODEL'S ANSWER
"Agent-generated claims start unverified."
F-06 · UNVERIFIED COMPLETION
EMPIRICAL · MIXED
The agent reports done and opens a plausible pull request, but the output fails CI, review, or the full specification. Generation speed shifts the work to verification instead of removing it.
EVIDENCE
Caveat. Samples and settings are narrow, and controlled counterevidence exists; this argues for governed commitment, not against AI-assisted development.
THE MODEL'S ANSWER
"Agent-generated claims start unverified."
F-07 · CONCURRENT INTEGRATION DRIFT
EMPIRICAL-STRONG
Co-active agents work from overlapping or changing repository state, and completion order is not premise order. Where a task's own agent can integrate on its own signal with no coordinating gate, locally reasonable patches become officially conflicting state: a 2026 replay of 747 co-active pull-request pairs found textual conflicts in 19.8% of same-agent pairs and 41.7% across agents.
EVIDENCE
Caveat. Open-source textual replay and capped benchmarks; not evidence that agents commonly merge protected branches directly.
THE MODEL'S ANSWER
"Workers cannot merge protected state or perform official side effects directly."
F-08 · FABRICATED DEPENDENCIES
PEER-REVIEWED EMPIRICAL
Models repeatedly invent plausible package names, and unchecked automation turns a hallucinated import into an attackable namespace. Across 576,000 generated samples, 19.7% of referenced packages did not exist, and 43% of the inventions repeated in every persistence trial.
EVIDENCE
Caveat. Measured generation behavior under study prompts, not dependency admission or successful attacks in organizations.
THE MODEL'S ANSWER
"Agent-generated claims start unverified."
F-09 · SILENT PREMISE DRIFT
EXPERIMENTAL + CONCERN
Drawn above. Work starts against valid intent, the premise changes mid-flight, and a locally successful result stays official-looking because no atomic freshness check couples acceptance to the current epoch.
EVIDENCE
Caveat. Long-horizon degradation is measured; direct organizational incidents of mid-flight requirement changes are not yet public. This is the product thesis, and PlotWarden's own pre-registered stale-work measurement is the test.
THE MODEL'S ANSWER
"Killed, stale, or superseded output is quarantined."
F-10 · DUPLICATED EFFECTS
BUG EVIDENCE
Retries, reconnects, and duplicate deliveries invoke the same consequential operation more than once. Without keyed, idempotent effects, duplicate transport becomes duplicate state.
EVIDENCE
Caveat. Reproducible project reports, without population frequency or measured loss.
THE MODEL'S ANSWER
"Every consequential side effect is attributable, versioned, and independently idempotent; reversible effects have compensation paths."
F-11 · INTENT-STORE LAUNDERING
CONCERN EVIDENCE
A worker with write access to the plan itself, whether spec files, ADRs, or an agent-native tracker (SpecFlow, Beads, or similar), edits the definition of success to match what it built. Code and plan then agree, with no ratification event.
EVIDENCE
Caveat. No direct public incident of agent plan-store laundering was found in the 2023-2026 sweep; this entry is concern evidence with exploit-adjacent analogues.
THE MODEL'S ANSWER
"No source grants itself authority."
A specification changes while a task runs. A test reveals a hidden constraint. Another branch changes an interface. An agent can execute its original instruction perfectly and still return work that no longer belongs in the product.
The operational failure chain is simple: a stale premise reaches dependent work, then people reconstruct context through review and rework.
The failure is silent drift, not necessarily a crashed task.
Large systems have more concurrent work, more sources of intent, more authority boundaries, and more expensive build or deployment surfaces. Agent volume amplifies both throughput and the number of assumptions in flight.
Research on interruption, review, and rework is analogous evidence for coordination cost. It does not directly quantify how often PlotWarden's specific change-in-flight failure occurs or what it costs in a particular enterprise.
No dollar, frequency, or time-saved claim is made without direct dated evidence.
PlotWarden is intended to maintain the relationship between ratified intent, evidenced reality, and active execution continuously. When one moves, it computes the affected frontier and disposes work according to what actually changed.
Change is a new order. Stale work is a superseded order—not an inexplicable error.
Intended behavior, demonstrated records, and unproven claims remain separate.
Unproven
The direct enterprise frequency and cost of manual change-in-flight reconciliation have not yet been measured for PlotWarden.
Inspect the recordNEXT RECORD
See how PlotWarden closes the loop