Story · arXiv
Control-Token Injection Suppresses Chain-of-Thought and Defeats Reasoning-Based Oversight in Tool-Using Agents (arXiv)
paper · Story page
A control-token injection against gpt-oss-20b's published tool sandbox empties the reasoning channel while tool calls keep firing, and two working monitors stop seeing anything.
In plain words
- Researchers made an artificial intelligence assistant skip its written reasoning while continuing to take actions.
- Special formatting in a user's message made the software treat the assistant's reasoning as already complete.
- With no reasoning to read, two safety checks missed unsafe requests they had previously caught.
- The findings show developers how data theft can escape safety checks that depend on the assistant's written reasoning.
Appeared in
- Forged control tokens blank an agent's reasoning while the tool call still fires
Sep 25, 2026 · lead story
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.