Authorization Architectures for Tool-Using AI Agents
cs.CR
Submitted: 2026-09-14
Updated: 2026-09-14
Comments: 70 pages, 8 figures, 10 tables
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- MRKL Systems: A modular, neuro-symbolic architecture that combines large language models, external knowledge sources and discrete reasoning
- ReAct: Synergizing Reasoning and Acting in Language Models
- How are AI agents used? Evidence from 177,000 MCP tools
- A Survey of AI Agent Protocols
- Security Risks in Tool-Enabled AI Agents: A Systematic Analysis of Privileged Execution Environments
- An AI Agent Execution Environment to Safeguard User Data
- LLM Agents can Autonomously Hack Websites
- Prompt Injection attack against LLM-integrated Applications
- A Comparative Study of Software Secrets Reporting by Secret Detection Tools
- Pushed by Accident: A Mixed-Methods Study on Strategies of Handling Secret Information in Source Code Repositories
- A Comprehensive Formal Security Analysis of OAuth 2.0
- The Web SSO Standard OpenID Connect: In-Depth Formal Security Analysis and Security Guidelines
- Self-Sovereign Identity: A Systematic Review, Mapping and Taxonomy
- Zero Trust Architecture: A Systematic Literature Review
- Authenticated Delegation and Authorized AI Agents
- Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure
- Intelligent AI Delegation
- AIP: Agent Identity Protocol for Verifiable Delegation Across MCP and A2A
- AgenTRIM: Tool Risk Mitigation for Agentic AI
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs