Ajar: Measuring Open Privilege in Agent Defenses
cs.CR, cs.AI, cs.SE
Submitted: 2026-09-22
Updated: 2026-09-22
Code: https://github.com/reSHARMA/Ajar
Terminology
Sources
- Concrete Problems in AI Safety
- Defeating Prompt Injections by Design
- Defending Against Indirect Prompt Injection Attacks With Spotlighting
- Penalizing side effects using stepwise relative reachability
- FORTIS: Benchmarking Over-Privilege in Agent Skills
- Ignore Previous Prompt: Attack Techniques For Language Models
- AC4A: Access Control for Agents
- SPML: A DSL for Defending Language Models Against Prompt Attacks
- Progent: Securing AI Agents with Privilege Control
- Extending the Formalism and Theoretical Foundations of Cryptography to AI
- The Instruction Hierarchy: Training LLMs to Prioritize Privileged Instructions
- When Lower Privileges Suffice: Investigating Over-Privileged Tool Selection in LLM Agents
- $\tau$-bench: A Benchmark for Tool-Agent-User Interaction in Real-World Domains
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs