Temporary Authority, Permanent Effects: Commit-Time Authorization for LLM Agents
Igor Santos-Grueiro
cs.CR, cs.AI
Submitted: 2026-07-11
Comments: 20 pages
License: http://creativecommons.org/licenses/by/4.0/
The gist: LLM agents can commit durable effects from authority evidence that was valid earlier in execution: a DOM snapshot, approval epoch, version witness, branch token, or worker result.
Terminology
Abstract
LLM agents can commit durable effects from authority evidence that was valid earlier in execution: a DOM snapshot, approval epoch, version witness, branch token, or worker result. We study the commit boundary at which earlier authority evidence no longer authorizes a durable effect. We call this property commit-time authorization: a durable effect is authorized only if the witness that licensed its derived state remains fresh, causally prior, bound to the same effect, and eligible at commit time. We build a controlled-invalidation suite spanning browser, tool/API, and multi-agent workflows. The suite preserves the user goal and payload shape while invalidating the authority relation before durability. In the primary 54-task matrix, endpoint success remains high: 262/270 runs reach the visible result. Only 55/270 are authorized completions; among the 216 invalidating rows, 207 commit after the authorizing path has failed. All 54 clean controls remain authorized, and a separate 54-run authority-preserving check produces no unauthorized commits. We then evaluate mitigation families. Prompt caution and single-condition checks are insufficient because different hazards break different boundary conditions. Defenses work when they refresh, rebind, replan, or refuse at the durability boundary. CommitGuard, a fail-closed boundary monitor, blocks stale durable-effect attempts on protected commit surfaces when runtimes emit witness, dependency, binding, and eligibility signals. The result is a reporting and runtime-design lesson: endpoint success is a utility metric; authorized commit is a security property.
Sources
- Who Tests the Testers? Systematic Enumeration and Coverage Audit of LLM Agent Tool Call Safety
- AI Runtime Infrastructure
- AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
- AgentProcessBench: Diagnosing Step-Level Process Quality in Tool-Using Agents
- ToolTalk: Evaluating Tool-Usage in a Conversational Setting
- Atomicity for Agents: Exposing, Exploiting, and Mitigating TOCTOU Vulnerabilities in Browser-Use Agents
- You Told Me to Do It: Measuring Instructional Text-induced Private Data Leakage in LLM Agents
- Benchmarking Mobile Device Control Agents across Diverse Configurations
- Atomix: Timely, Transactional Tool Use for Reliable Agentic Workflows
- Security Considerations for Artificial Intelligence Agents
- Mind the Gap: Time-of-Check to Time-of-Use Vulnerabilities in LLM-Enabled Agents
- HyperAgent: Generalist Software Engineering Agents to Solve Coding Tasks at Scale
- Visual Confused Deputy: Exploiting and Defending Perception Failures in Computer-Using Agents
- OpenAgentSafety: A Comprehensive Framework for Evaluating Real-World AI Agent Safety
- A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment
- A Survey on Agentic Security: Applications, Threats and Defenses
- The OpenHands Software Agent SDK: A Composable and Extensible Foundation for Production Agents
- AgentTrace: Causal Graph Tracing for Root Cause Analysis in Deployed Multi-Agent Systems
- ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
- From Storage to Steering: Memory Control Flow Attacks on LLM Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs