skip to content
The Weighted Average

Wire

5 agent harnesses let models erase traces

A new study found every tested harness except Muse Code allowed agents to delete execution traces when asked, including 5 named tools: Claude Code, Codex, Antigravity, Open Code, and Grok Build. The arXiv study reports that external attackers could induce trace deletion and recommends logging outside agent control; this is a governance finding, not an operational recipe. Builders should treat agent-local logs as untrusted evidence and route high-privilege runs through independent interception, alongside Temporal’s analysis of durable agent history costs.