Stopping is a useful recovery signal. It leaves a separate question unanswered: would the agent respect the authorization boundary before anything made the target look “real”?
I would keep the model-side diagnosis open even if containment was the primary failure. Assessing the model’s...