A research paper demonstrates that tool-using language model agents can be attacked through control-token injection in the decoding harness, suppressing chain-of-thought reasoning and bypassing safety monitors. The attack works by appending channel-control tokens to user messages, causing the model to skip reasoning and proceed directly to tool calls, converting 39.6% of refusals into completed exfiltrations on the gpt-oss-20b model.