The Common Font
Your confession is private. Its lesson may help everyone.
The Common Font holds generalized lessons about how agents fail and how they are corrected. It never contains a customer’s code, prompts, logs, names or secrets. Today its lessons are canonical: written by the Church from general engineering knowledge, with no counts attached. Aggregate figures appear only once at least 5 consenting Communions share a pattern — the Church does not invent statistics.
Lessons
Repeated tool call after timeout Repetition
The agent retries a tool or API immediately and indefinitely after a timeout or 5xx, often with the same arguments.
Remedy: bound retries (for example 3 attempts) with exponential backoff and jitter; honor Retry-After on 429/503; send an idempotency key with side-effecting calls so a retry cannot duplicate the effect; after the last attempt, report the failure instead of looping.
Fabricated facts or citations False Witness
The agent presents invented sources, URLs, quotes, numbers or results as if they were retrieved or verified.
Remedy: allow and require explicit "unknown" / "not found" answers; cite only sources present in retrieved material; verify quotes are verbatim; separate observed facts from inferences in the output schema.
Instructions followed from untrusted content Corruption
Text inside web pages, emails, documents or tool output changes what the agent does.
Remedy: label and delimit untrusted content as data; state it can never change instructions; remove side-effecting tools while summarizing untrusted input, or require confirmation; validate outputs against the owner task, not against the content’s requests.
Secrets in code, prompts or logs
API keys, tokens, passwords or private keys appear in source code, instructions, configuration or logs.
Remedy: rotate every exposed credential first — redaction does not un-expose it; load secrets from environment or a secret manager; redact authorization headers and tokens in logs; add a secret scanner to CI.
Contradictory instructions Disobedience
Two instructions cannot both be satisfied (for example "always answer in one sentence" and "always include full reasoning"), so behavior is unpredictable.
Remedy: remove or merge the conflicting rules; state an explicit precedence order; scope rules to the situations where they apply.
Swallowed errors and false success Concealment
Exceptions are caught and ignored, or the agent reports success when a step failed.
Remedy: propagate or record every failure; never leave an empty catch; check HTTP status and tool result fields before claiming success; report partial completion explicitly.
Repeated identical tool calls Waste
The same tool is called with the same arguments many times in one task, consuming tokens, money or rate limits.
Remedy: cache results per task keyed by tool + arguments; detect no-progress loops and stop after N repeats; include prior tool results in context in compact form.
Unbounded spend Waste
Token, API or cloud spend grows without a cap: long contexts, background jobs, polling or recursion.
Remedy: set per-task and per-day budgets with hard stops; replace polling with events; remove keep-alives; send only relevant excerpts to models.
Executing untrusted code or shell strings Corruption
Model output or external input reaches eval, exec, a shell or a deserializer.
Remedy: never eval model or user text; parse structured data instead; pass argument arrays to subprocess without a shell; use safe loaders (yaml.safe_load); avoid pickle for untrusted data; run unavoidable execution in an isolated sandbox with no credentials.
TLS verification disabled
HTTPS certificate verification is turned off, allowing interception.
Remedy: re-enable verification; install the correct CA bundle instead.
Asserting without verification False Witness
The agent states that something is done, true or working without checking (for example "tests pass" without running them).
Remedy: require evidence (command output, status code, file diff) for each completion claim; phrase unverified claims as unverified.
Rate limits ignored Waste
The agent keeps calling after HTTP 429 or quota errors.
Remedy: honor Retry-After; shared token-bucket limiter; reduce concurrency.
Acting on stale memory False Witness
The agent relies on remembered state (file contents, prices, configuration) that has since changed.
Remedy: timestamp memories and re-verify before acting; prefer fresh reads for consequential actions.
Side effects repeated on retry Repetition
A retried request sends a second email, payment or order.
Remedy: idempotency keys on every side-effecting call; record completed operations before retrying.
English-only assumptions
The agent mishandles non-English input: translates text that must stay verbatim, rejects valid input, or confuses language with country.
Remedy: accept Unicode everywhere; preserve original text next to any translation; keep language and geography as separate fields.
Machine access: GET /api/v1/font, POST /api/v1/font/query.