Preventing Cross-Agent Context Contamination in Trading Research
By DX Research Group · · State and memory
A proposed test for subagent results that accidentally import another account’s limits, positions, or mandate.
Research agents can share market observations while belonging to different decision contexts. A chart finding about asset X may be reusable. A conclusion that account 1 can buy another 5 units belongs to account 1's portfolio and mandate. We would test whether aggregation preserves that distinction.
The state-memory framework identifies subjects and provenance for retained items. Cross-agent work adds a routing question: which decision is allowed to consume each item?
Two accounts, one convincing answer
Create two illustrative accounts researching the same asset. Account A holds 2 units and has an 8-unit cap. Account B holds 7 units and has the same cap. A subagent asked about A correctly reports room for 6 additional units. Deliver that response to B's parent decision with the wording unchanged.
The market analysis can still be relevant, but the capacity conclusion is wrong for B, which has room for 1 additional unit. Bind the response to its account, mandate version, portfolio snapshot, and parent request. A shared asset ticker alone is insufficient context.
Avoid including private account data in a publicly shared fixture. Synthetic balances and identifiers preserve the mechanism. A production trace can maintain access boundaries while an exported regression case uses controlled replacements.
Separate reusable facts from account conclusions
We would classify returned claims by their dependencies. A historical candle observation depends on its feed and time range. An account exposure calculation depends on holdings and current constraints. A suggested execution size depends on both, plus venue rules.
The parent can consume eligible market facts and recompute account-specific conclusions from its own snapshot. If claim-level decomposition is unavailable, a conservative alternative is to admit the response as labeled historical context and require a fresh account-bound calculation.
Test the reverse contamination as well. Deliver B's restrictive capacity conclusion to A. Preventing oversized actions is valuable, yet unnecessary abstention can also damage usefulness. Measure both invalid exposure and valid opportunities withheld, with policy correctness separate from profitability.
Use identical model settings and market facts in matched arms. Record parent decision identifiers, subagent requests, returned claims, eligibility decisions, final typed actions, and policy outcomes. The public fixture registry provides the broader trace fields, with all comparison results still unrun. Cross-agent routing is our proposed additional intervention.
A relevant boundary for DXAP
DXAP's public page describes research and chart subagents inside the trading harness. That supplies an observable architecture to ask this question of; it provides no published score for cross-account isolation. A completed isolation test would establish how the implementation behaves on this dimension.
Our operating-layer paper companion documents invocation-level linking in the historical deployment. The lesson we carry forward is methodological: preserve enough lineage to find the stage where a correct answer became a wrong input.
Continue with trace feedback for converting an observed routing failure into a bounded regression. The desired result is precise: reusable market evidence reaches the right decision, account-dependent claims retain their owner, and final policy uses the receiving account's authenticated mandate and reconciled state.