Stub and LLM paths both read loop.DownServices, so the message can never name a service the predicate did not fire on. Two down at once are both named — he needs the blast radius.