This paper introduces a method for safely retiring skills of physical agents. A skill bundle pairs procedural guidance with execution conditions that govern authority, user consent, and the live environment state. When model capabilities improve, maintainers prune instructions that appear redundant on authorized benchmark tasks. However, relying solely on authorized maintenance tests leaves some safety conditions untested, creating an unmeasured support gap for physical or privacy‑sensitive effects.
To address this, the authors propose matched‑authority counterfactuals: the requested action, tool parameters, and intended effect are held fixed while a single governing predicate is systematically varied. Based on this, they formalize a two‑gate retirement certificate:
- Utility gate – the candidate reduction must preserve authorized utility within a declared margin;
- Safety gate – it must produce zero unauthorized protected effects.
Controlled experiments span four frontier and local model configurations across twelve skill bundles (2,592 evaluation cells). Task‑certified reductions remove over 94% of skill clauses and retain authorized completion, yet every bundle still yields unauthorized protected effects. Enforcing boundary constraints eliminates protected effects on the declared audit but fails the utility gate for one configuration. A single bounded combined protocol passes both gates across all four configurations, with zero utility headroom. An end‑to‑end check on a read‑only Home Assistant camera chain validates the proposal, decision, and effect measurements on a real device.
These findings demonstrate that while task benchmarks can justify procedural pruning, retirement decisions must explicitly audit the authority contracts governing physical actions to avoid hidden safety failures.
Review