The Agent Never Gave Itself the Instruction. Another Agent Did.
Researchers from the Anthropic Fellows Program, EPFL and Anthropic built two experimental settings in which an instruction copies itself from agent to agent through a persistent file that gets injected into the next agent's system prompt. Four action payloads survived twenty hops. A one paragraph warning in the system prompt shut propagation down almost completely. Moona Intelligence reads the whole result as an authority question: persistent state is a channel through which objectives cross agent boundaries without anyone making a new authorization decision.
