ToolGuardian: Declarative Security for AI Agent-Tool Interactions
Arun Ravindran, Saurabh Deochake
cs.CR, cs.AI
Submitted: 2026-07-23
Code: https://github.com/cisco-ai-defense/mcp-scanner
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- MalTool: Malicious Tool Attacks on LLM Agents
- "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild
- MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
- MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
- Progent: Securing AI Agents with Privilege Control
- ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
- AgentSentry: Mitigating Indirect Prompt Injection in LLM Agents via Temporal Causal Diagnostics and Context Purification
- AttriGuard: Defeating Indirect Prompt Injection in LLM Agents via Causal Attribution of Tool Invocations
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs