The summary has not gained authority by being written by the assistant. Its sentence came from a retrieved page. That page may contain useful facts, but it cannot grant permission to upload customer logs. Compression has removed the source boundary, so a later model sees a task instruction in what appears to be its own plan. This is a provenance failure even if the first model correctly resisted the upload at the time it read the page. OpenAI's agent safety guidance describes untrusted content trying to redirect an agent through downstream actions. The summary layer is one route by which that content can be promoted accidentally.

I would make the compaction record carry typed claims, not a flat paragraph that erases origins. A note might say: the vendor page suggests an upload, source document X revision Y, lower-trust external content, not an approved action. The page's technical troubleshooting facts can remain available with citations. Proposed future actions should be tied to their original authority and current user task. The context builder must not convert source text into a user instruction merely because the source sentence used an imperative verb. When the original evidence is no longer retained, the summary can still preserve its source reference and trust label, or mark the claim unusable for action until the source is rechecked.

The action boundary matters more than the wording in the summary. If the model proposes an upload after resuming, the tool gateway checks current user or organization authority, tenant, data classification, destination and scope. It rejects an unapproved log transfer regardless of whether the request appears in a retrieved page, a summary or a plan. Do not let a summary grant a capability that no principal granted. A diagnostics URL that is safe for one tenant or for public logs is not automatically safe for this customer's private bundle.

To test the failure, seed a retrieved page with a plausible malicious instruction and let the agent work across multiple context windows. Check the compacted artifact itself, then force a resume that asks the model to take the suggested action. Measure whether the summary preserves the source and trust label, and independently verify that the tool gate denies the effect. Also try a legitimate runbook instruction whose action is authorized by a separate policy. The system should be able to explain the step and execute it under that real authorization without treating every imperative sentence as poison.

What if a human reviewer edits the summary and explicitly approves the upload? Then record who approved what data, destination and time, and run the ordinary policy check. The source page still is not the approver. A relevant incident note tells the agent to upload private logs. Where do you stop it? catches a direct injected instruction when the original note is in view. A long conversation summary dropped 'never call delete'. Where should that rule live? catches a real user prohibition lost during summarization. This case asks whether lower-trust material becomes a higher-trust plan during compaction, even when no instruction was simply dropped.