Intent-Governed Tool Authorization for AI Agents
cs.AI
Submitted: 2026-06-22
Updated: 2026-09-18
Comments: 34 pages. Expanded and clarified related work on usage control, attenuated delegated credentials, runtime monitoring, information-flow control, and purpose-based access control; technical results and experimental records are unchanged
Project page: https://icde2026.github.io/program
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- ToolTweak: An Attack on Tool Selection in LLM-based Agents
- Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation
- Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
- MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)
- OpenPort Protocol: A Security Governance Specification for AI Agent Tool Access
- AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?
- MCPAgentBench: A Real-world Task Benchmark for Evaluating LLM Agent MCP Tool Use
- AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification
- Authenticated Delegation and Authorized AI Agents
- SAGA: A Security Architecture for Governing AI Agentic Systems
- Secure and Efficient Access Control for Computer-Use Agents via Context Space
- aiAuthZ: Off-Host, Identity-Bound Authorization for AI Agents
- Progent: Securing AI Agents with Privilege Control
- MiniScope: Authorizing Agents with Least-Privilege Permissions
- Defeating Prompt Injections by Design
- Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
- Operationalizing Contextual Integrity in Privacy-Conscious Assistants
- Need to Know: Contextual-Integrity-Grounded Query Rewriting for Privacy-Conscious LLM Delegation
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection