acceptodds
Under review as a conference paper at ICLR 2027

Skip the Model, Not the Checks: Certifying Model-Free Actions of LLM Agents

Abstract

To save inference cost, LLM agents increasingly act without the model: a lightweight proposer predicts the next tool and fills its arguments with values reused from earlier calls. Such actions are cheap but barely checked. We propose certify–repair–ask (CRA), a training-free gate that executes a proposed action only if its preconditions are certified in three-valued logic over observation-grounded predicates, otherwise executes the best certified alternative among the cached values, and asks the model only when none exists. We restore ScienceWorld and ALFWorld to 2339 decision points of an AutoTool agent, execute each gate's action there, and branch episodes from the same states. First, certification cuts refusals: with an expert catalog, CRA lowers the refusal rate of model-free actions from 80.2% and 93.7% to 28.5% and 26.6%, where a reject gate almost never acts. Second, executable is not the same as right: catalogued preconditions still hold after an action has taken effect, so repair replays the agent's recent past (where the model acted, 35.4% of CRA's accepted ScienceWorld actions re-execute a state change already made, against 3.9% of the model's, and every accepted ALFWorld navigation repair returns to the previous location), and branched from the same states they cost ALFWorld agents extra steps and calls without detectable success gains. Third, in closed loop no gate detectably improves success or model calls over unguarded reuse or native AutoTool, and in ALFWorld repair lowers success relative to rejection, clearly with Claude, less so with Gemini; asking instead of repeating an accepted action restores it. Our results suggest that gates on model-free actions need a progress-sensitive signal beyond executability: a refused action costs a step, an executable wrong one can cost the task.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.