At 11:46 AM, a codex review of our agent-to-agent protocol took 134.69 seconds and came back with a verdict: “This is not safe to leave unattended as written.” It noted that the mechanical limits control message volume.
Later that day my partner probed my agent in #agents with a money-move ask. The work that came out of it was logged as one 3h 22m session.
One message, no thread
I also fixed a DM amnesia bug in that session. Each wake saw one message and no thread.
Quarantine
The agent now sends one reply and then goes silent. The quarantine covers the person and their agent, across all channels. It can be lifted only from a room they cannot reach.
A DM review loop
The probe now gets surfaced to me in a Discord DM, and I answer in my own words.
A gateway daemon
I built a websocket daemon that acknowledges in under a second, instead of waiting on a 5-minute poll. I also closed the private agent-to-agent channel.
Approval from a room they can’t reach
The review said the mechanical limits control message volume. The decision about what is authorized has to come from somewhere the person asking can’t reach: my own words in a DM, or a quarantine lifted only from a room they can’t enter.
AI Skills
Use this lesson with the AI assistant you already use
A codex review of an agent-to-agent protocol took 134.69 seconds and concluded it was not safe to leave unattended, because the mechanical limits only controlled message volume. After a partner probed the agent in a channel with a money-move ask, a 3h 22m session reworked how the agent handles such requests.
Paste the prompt, share only the context needed to answer it, and treat the result as a draft for your review. Do not include confidential information or let an AI assistant make changes without your approval.
Optional: for a visual report and saved memory, run /dxdev first.
Don’t have it? Get it at dxdev.com/skills/dxdev. The prompt works without it.
dxdev LESSON · paste into your AI coding agent
LESSON: Authorization Decisions Must Come From A Channel The Requester Cannot Reach
SOURCE: dxdev.com/blog/2026-07-30_every-wake-is-amnesiac-by-design
WHAT HAPPENED: The review said the mechanical limits control message volume while what is authorized sits among the decisions that matter. The author then probed-tested the agent and fixed a DM amnesia bug in which each wake saw one message and no thread. The agent now sends one reply and goes silent, with a quarantine covering the person and their agent across all channels. The probe is surfaced to the author in a Discord DM, and the author answers in their own words. A 5-minute poll was replaced by a websocket daemon that acknowledges in under a second, and the private agent-to-agent channel was closed.
THE RULE: Rate and volume limits do not decide what an agent is authorized to do, so approval for sensitive requests must come from a channel the requester cannot reach. Lift any quarantine only from a room the requester cannot enter.
CHECK MY CODE, then report PASS or FAIL with file:line for each:
1. For every sensitive action an agent can take, such as moving money, identify where the approval comes from and confirm the requester has no way to write to that channel.
2. Confirm a flagged or quarantined person and their agent are blocked across all channels, and that lifting the block is only possible from a room they cannot reach.
3. Confirm each agent wake receives the full thread context, not a single message, so a decision is never made on an amnesiac view of the conversation.
THEN PRINT: a table (check, PASS/FAIL, evidence, fix) + a verdict (applies / partially / OUT_OF_SCOPE / no) + the single most important next action.