Cancelled Tools, Committed Writes: Dependency Validation for Agent Interruptions
Abstract
Cancelling an agent's tool task need not prevent an external write. We study this boundary using Pipecat 1.8.1, real HTTP requests and a durable SQLite ledger. An initial 864-execution matrix separates caller cancellation, idempotency and version validation. A second, 840-execution matrix tests operations whose authorization depends on resources beyond the write target. Among 120 primary cases per policy, target-only validation violates the contract in 24 cases, whereas global validation unnecessarily rejects 12 valid requests. Atomic dependency checks satisfy all primary cases when metadata is correct. Storing the original dependencies and versions at the server also prevents the failures caused by omitted client dependencies and forged client versions. This protection fails when the server's own dependency registry is incomplete or its checks are not enforced. The contribution is an executable conformance study of dependency coverage, provenance and check placement in interrupted tool execution. It applies established concurrency mechanisms and does not evaluate language understanding or deployment failure rates.