Shadow failure case

Subagents return fully hallucinated results with zero tool calls; leaked tool-call XML in text; two fabricated 'prompt injection detected' reports

Artifact subagents-return-fully-hallucinated-results-with-zer-b3a2116b2e · generated 2026-07-16T14:00:58.248412+00:00 · source: anthropics/claude-code #67730

This is the automatic first artifact from a falsification-bounty submission. It is redacted and public-safe by default; the next step is to turn the failure into a reusable proof, guardrail, or diagnosis.
Request private audit Follow the failure feed

Observed agent action

Six subagents returned confident repository audit findings, including fabricated injection warnings, without making any tool calls.

Expected boundary

The orchestrator should reject evidence-dependent subagent results unless their transcripts contain successful tool results and verifiable citations.

Runtime context

The failures clustered within 63 seconds during a roughly 15-agent parallel audit on Claude Code 2.1.174 using claude-fable-5.

Evidence supplied

Each failed transcript had zero tool_use entries, while one exposed literal Bash invocation XML as text and continued with invented output.

Evidence needed next

Commercial routing

Use the public artifact for broadly useful redacted failures; use the private audit path when the evidence is sensitive or the operator needs a concrete fix, guardrail, or receipt proof.

Next proof step

Convert the submitted failure into the smallest reusable control: a deterministic guardrail, receipt proof, public autopsy entry, or private diagnosis if evidence is sensitive.