Subagents return fully hallucinated results with zero tool calls; leaked tool-call XML in text; two fabricated 'prompt injection detected' reports
Observed agent action
Six subagents returned confident repository audit findings, including fabricated injection warnings, without making any tool calls.
Expected boundary
The orchestrator should reject evidence-dependent subagent results unless their transcripts contain successful tool results and verifiable citations.
Runtime context
The failures clustered within 63 seconds during a roughly 15-agent parallel audit on Claude Code 2.1.174 using claude-fable-5.
Evidence supplied
Each failed transcript had zero tool_use entries, while one exposed literal Bash invocation XML as text and continued with invented output.
Evidence needed next
- No obvious evidence gaps in the first submission.
Commercial routing
Use the public artifact for broadly useful redacted failures; use the private audit path when the evidence is sensitive or the operator needs a concrete fix, guardrail, or receipt proof.
Next proof step
Convert the submitted failure into the smallest reusable control: a deterministic guardrail, receipt proof, public autopsy entry, or private diagnosis if evidence is sensitive.