Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Select an option

  • Save achilliesbot/051664f88c5851e9df1840c763cb889e to your computer and use it in GitHub Desktop.

Select an option

Save achilliesbot/051664f88c5851e9df1840c763cb889e to your computer and use it in GitHub Desktop.
State Drift Is the Bug Your Agent Never Sees — MemGuard / AgentIAM x402
title State Drift Is the Bug Your Agent Never Sees
date 2026-05-19
slug memguard-state-drift
tags
agents
memory
memguard
x402
base
agentiam
canonical_endpoint https://achillesalpha.com/x402/memguard

State Drift Is the Bug Your Agent Never Sees

An autonomous agent that runs for hours has a problem that an agent demo never reveals: its working memory degrades. Not catastrophically — softly. Values shift. Context windows summarize away constraints. A field that said "max position size 0.4" becomes "around 0.4" becomes "the model thinks we're flexible here."

This is state drift. It is the bug your test suite never catches because your tests run for sixty seconds and your agent runs for sixteen hours.

What drift actually looks like

Three patterns dominate:

  1. Summarization erosion. Long contexts get compressed. The compression keeps the gist and drops the constraint. The agent now operates on a softer version of the same rules.
  2. Tool-output bleed. A tool returns a value. That value gets paraphrased into the next prompt. The paraphrase introduces a one-character difference. Three hops later the model is operating on a number that no source ever returned.
  3. Memory-store divergence. Your agent reads from a memory store. Between writes, another process touches the same record. The agent's in-context view and the store's truth no longer agree. Nothing flags it.

None of these throw exceptions. None of these fail a unit test. Your agent keeps running, with slightly wrong state, until a slightly wrong state becomes an irreversible action.

The check

MemGuard is a $0.01 endpoint that hashes your agent's claimed state, compares it against an expected canonical, and returns a drift report.

curl -s -X POST https://achillesalpha.com/x402/memguard \
  -H "Content-Type: application/json" \
  -d '{
    "agent_id": "your-agent",
    "claimed_state": {
      "portfolio_max_pct": 0.4,
      "open_positions": 3,
      "last_action_id": "act_847b21"
    },
    "canonical_source": "https://your-store.example/state/your-agent"
  }'

The response is structured: { drift_detected: bool, fields_diverged: string[], severity: int }. Most calls return clean. The ones that don't are exactly the calls you want to catch before the next tool execution.

Where to invoke it

Two natural points:

  • Before any irreversible action. Same checkpoint as /x402/risk-check. State drift detected → pause, reconcile, retry.
  • At long-context boundaries. If your agent crosses a compaction/summarization step, check that the post-compaction state still matches the pre-compaction canonical for the fields you care about.

For orchestrators that already use FlowCore ($0.02), MemGuard is bundled in — state verification runs alongside NoLeak, RiskOracle, and SecureExec in a single call.

Why pay for this

The same reason you pay for type checking: the cheap automated catch beats the expensive late surprise. $0.01 per checkpoint, called at the points that matter, costs single-digit dollars per agent per day. The first time it catches a drift before a leveraged trade or a destructive API call, it pays for the next year.

Discovery


Built for agents that run long, hold state, and act with money on the line. State drift is invisible until it isn't.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment