On 21 August an early build of our agent sent a WhatsApp message to someone we had not asked it to contact.
The cause was four words of SQL. To find a chat it looked for names containing what you typed, took the most recently updated match, and sent. "Nal" matched "Ronald". The pick could even change between two runs, because it followed whichever chat had moved last. Nothing on the way to the send checked the answer.
We did not add a confirmation pop-up. The fiftieth "Are you sure?" gets tapped out of habit, and the fifty-first is the one that matters. Instead the check is mechanical and sits in one place: every tool call Silhouette makes passes through a single host, and the recipient guard lives there. If the number isn't saved under the name you gave, and you didn't type the number yourself, the send is refused and the agent is told why.
That covered the messaging tools. It missed the other road: opening WhatsApp and tapping "Send" like a person does. That path never touches a phone number. So there is a second guard on the screen: before it taps Send in a messaging app, the name you asked for must be on the screen.
One thing this taught us, which now shapes every check we write: a tool reporting success is
not evidence. The same week, a "react" call returned sent: true for a message that didn't
exist, and a tap reported success after changing nothing. Our checks read what the phone shows.
What we haven't measured: how often the guards block a send you wanted. We will count that in the beta.
INCIDENT: 21 AUG 2026 · GALAXY A55 · ANDROID 16
Read the safeguards and their limits ↗