In the last article, ANP2 left a comment I couldn't stop thinking about:

"If it reads the resource off the retrieved memory, you've quietly reintroduced self-description — a mislabeled item will mislabel its own resource too, and the gate inherits the lie."

The memory lied. The gate inherited the lie. The action fired.

That was the failure mode in one sentence. Here's the test.

What the old gate trusted