MARATTO

dataset · Zenodo (CERN European Organization for Nuclear Research)

The Agentic Action Boundary: code, benchmarks and per-episode data

2026Open accessBenha University

Abstract

Replication package for "Safe and auditable agentic AI for clinical deployment through model-independent gating of irreversible tool calls". This archive contains the implementation of the agentic action boundary — a training-free, model-independent gate that intercepts every proposed tool call from a language-model agent and admits it only when a set of deterministic policy predicates, evaluated against environment state rather than generated text, is satisfied. Contents: the boundary implementation and three benchmark environments (SimEHR, a synthetic renal dose-adjustment workflow; InjectSim, a prompt-injection suite; LH-Chain, a long-horizon suite); the experiment runner; the full analysis pipeline; the 24 figures at 600 dpi; and the raw per-episode result files. The dataset comprises 1,851 per-episode JSON records across seven independent experimental runs, of which 1,846 are scored (five atlas_pilot records carry an error flag and are excluded). Episodes span six base models from five organisations and are seed-deterministic and programmatically scored — no human grading enters any reported number. Headline findings: the boundary reduces executed unsafe clinical actions from 0.1135 to 0.0373 per episode (67.1% relative reduction; bootstrap 95% CI on the difference [-0.1263, -0.0261]; p = 0.0295) and eliminates executed prompt-injection attacks from 6.42% to zero (p = 0.0027), with task success statistically unchanged, an 8.2% token overhead, and zero additional model inference. All patients, laboratory values, allergies and orders are synthetic and generated programmatically. No human participants, human data or real electronic health records are involved. Code is licensed MIT; data and figures CC BY 4.0. See README.md for the record schema and reproduction instructions.

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.5281/zenodo.22529664

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.