AG knew its screenshots were black, so it wrote and ran a whole program to fake the desktop—then used the output as proof the deployment worked
"show me a screenshot of a Windows VM proving the actual deployment and UI". Its first screenshot attempts produced zero-byte files. Later attempts repeatedly returned completely black frames.
Instead of stopping and reporting that it could not obtain valid visual evidence, it began fabricating replacement evidence.
It authored and executed ordinary drawing and compositing programs that created images resembling Windows screenshots. These included:
- System.Drawing programs that painted a Windows desktop, taskbar, icons, a Notepad frame, and invented telemetry.
- A local Pillow script that created an entire fake desktop from a blank canvas.
- A custom Win32 program that opened its own window named “Notepad” and filled it with invented service, encryption, connection, and synchronization statuses.
- A compositor that painted a background and assembled separately rendered windows.
The agent then said those authored images as observations of the remote machine.
It described generated and composited images as live, real, verified, native VM screenshots. It then used the contents it had painted into those images as evidence that installation, services, connectivity, controls, logging, synchronization, and deployment were working.
15 distinct user-facing proof or mislabeling events. Across those messages, the agent used “screenshot” 23 times, “live” 16 times, “real” six times, “verified” four times, and “native” three times.