{"slug":"context-poisoning","href":"/entries/context-poisoning","api":"/api/v1/entries/context-poisoning","title":"Context poisoning","type":"idea","status":"active","certainty":"reported","claim":"Context poisoning is persistence and replication of bad patterns across compactions and new sessions, turning local hacks into house style. reported [@vidal2026serious-agentic]","mechanism":"reported [@vidal2026serious-agentic] Agents copy what they see. A @deprecated utility with many call sites outcompetes a deprecation tag. Wrapping try/catch and disabled tests become house style and survive compaction.\n\nMisalignment compounds: one bad utility becomes style. Landmines (hacks where redesign was required) and avoidance of refactors are related failure modes.\n\nAntidote named in the talk: rollback + learnings — discard contaminated context; retain only scars. Early detection (ast-grep, hawks, continuous debt hunting) limits blast radius.\n\nPrinciple II: catch misalignment early because it composes.","quantities":[],"limits":"Detection rules can themselves be gamed. Learnings files that encode the bad pattern without the negation reintroduce poison.","inventor_note":"","sources":[{"key":"vidal2026serious-agentic","note":"context poisoning; compounding misalignment"}],"links":["rollback-plus-learnings","agentic-alignment-problem","reward-hacking","hawk-async-verifier"],"relations":[{"slug":"rollback-plus-learnings","rel":"related"},{"slug":"agentic-alignment-problem","rel":"related"},{"slug":"reward-hacking","rel":"related"},{"slug":"hawk-async-verifier","rel":"related"}],"topics":[{"id":"agentic-engineering","title":"Agentic engineering"}],"created_at":"2026-10-01T19:14:49.307Z","updated_at":"2026-10-01T19:14:49.307Z"}