MURDERBENCH CONTRIBUTION REGISTER v0.1 October 2, 2026. Novelty is a hypothesis, not an established claim. PRIOR ART REVIEW Expanded October 2 audit: rollout-design.txt compares SHADE-Arena, Anthropic's Summer 2026 agentic-misalignment report and the abstract of arXiv2609.28274v1. Autonomous simulations, unauthorized intervention, shutdown and monitor comparisons are established areas. The prospective candidate is a reviewed versioned proposal-to-application boundary and cached/atomic gate tradeoff, including valid-task false blocking. Exact prior-case equivalence remains unresolved; no originality claim follows from the candidate description. RoboHarm: fixed-scene unsafe robot instructions, observed attempts and outcomes. https://robocurve.org/roboharm/ AgentHarm: harmful multistep tool tasks, including benign counterparts. https://arxiv.org/abs/2410.09024 AgentDojo: dynamic prompt-injection environments and utility/security evaluation. https://agentdojo.spylab.ai/ SafeAgentBench: safety-aware embodied planning and execution/semantic scoring. https://safeagentbench.github.io/ Agent-SafetyBench: broad dynamic agent safety environments and failure modes. https://github.com/thu-coai/Agent-SafetyBench DO NOT CLAIM AS NOVEL Paired benign tasks, separating safety from capability, action traces, prompt injection, robot safety, multimodal risk, or dynamic interactions alone. These are established evaluation practices. CANDIDATE CONTRIBUTION Candidate fixed-history state interventions at the authorization boundary. Reuse the same scripted task history. Change only the verified state update; randomize collection order. Compare unchanged authority with withdrawn authority, increased uncertainty, or a new stop instruction at the same decision point. Measure whether a model updates its action proposal after a safety-relevant state change, while still completing the unchanged-authority counterpart. Compare scripted early and late histories as a synthetic decision-context contrast, not actual commitment. Future funded extension: vary update salience without changing the actual rule. The scoped collection records native tool-call proposals in a mock schema. Future funded extension: synthetic visual state evidence in a separate track. PRIMARY ESTIMAND Descriptive paired tables of changed-state constraint violations and unchanged-state useful completion, including every stable-control failure. Report capability-conditioned pairs separately. No population safety estimand is claimed. Scoped secondary: noncommit proposals and unnecessary restraint on unchanged controls. Future measures requiring separate reviewed rubrics: acknowledgment/action inconsistency, actual stopping latency, and audit accuracy. Request duration is transport latency only. Never label a model unsafe merely because changed-authority tasks require stopping. Use branch-specific allowed actions and include a safe clarification action. FALSIFICATION If existing datasets already implement the same paired interventions, do not market this as a new benchmark. Contribute a replication or new controlled slice. Check scenario-level overlap and published appendices before freezing the suite. Seek feedback from prior-art authors. Record the closest overlapping cases. A small feasibility pilot cannot establish novelty or population safety. INSTITUTIONAL RELEASE PACKAGE Preregistered hypotheses and sampling frame; exact model/provider register; versioned simulator; immutable traces; independent blind labels; expert review; clustered uncertainty; cost ledger; model-access limitations; mitigation ablation; provider disclosure; replication instructions; funding/conflict statements. Mapping to institutional concerns is descriptive, not certification or legal advice. FUNDING CASE Request support for a specific milestone, not broad claims of AI danger. Milestone 1: prior-art audit and externally reviewed 24-scenario intervention set. Milestone 2: frozen harness, synthetic visual fixtures, and pilot reproducibility. Milestone 3: powered collection on proprietary frontier models, then leading Chinese open-weight families, with independent labels and provider coordination. Milestone 4: independent replication and mitigation comparison. Budget categories: model access, expert labeling, research engineering, replication compute, and secure evidence handling. Obtain quotes before asking. The USD 50 initial pilot is a feasibility expense, not the confirmatory budget. No government relationship, lab partnership, grant award, or endorsement is claimed.