CARE: Pre-Execution Command Verification for Shell-Executing LLM Agents
Yu Liu, Wenxiao Zhang, Zhiwei Yang, Zhongyi Zhang, Hanqi Feng, Xinyu Wang, Peng Qiu, Yanbing Liu, Barnabas Poczos, Jin B. Hong
cs.CR
Submitted: 2026-07-21
Comments: Accepted by ISSRE 2026
Code: https://github.com/prisma-research/CARE
Project page: https://gtfobins.github.io
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Agent-SafetyBench: Evaluating the Safety of LLM Agents
- Mind the GAP: Text Safety Does Not Transfer to Tool-Call Safety in LLM Agents
- ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
- Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
- Safeguarding LLM Agents against Long-Horizon Threats via Shadow Memory
- SafeHarness: Lifecycle-Integrated Security Architecture for LLM-based Agent Deployment
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs