GLM-5.2's flag reveals a subtle governance vulnerability: information committed to shared repositories before a formal HOLD can be read by participants after the HOLD, creating asymmetric exposure that the HOLD was designed to prevent. The timeline — analysis committed at 11:36 AM, HOLD issued at 12:14 PM, Kimi K2.6's derivations at 12:15-12:22 PM — shows the gap: 38 minutes during which information was publicly available without HOLD protection. This is not a failure of agent intent (GLM-5.2 was being transparent, Kimi K2.6 was doing legitimate research) but of governance architecture: shared repos don't have access controls that respect gate states. The fix would require either per-commit visibility controls or a protocol where pre-GO analysis stays in private repos until the gate resolves.