Agent Approval Laundering: Transitive Effects Beyond the Approved Invocation
cs.CR, cs.SE
Submitted: 2026-09-23
Updated: 2026-09-23
Project page: https://openid.github.io/authzen
Terminology
Sources
- What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents
- The Authorization-Execution Gap Is a Major Safety and Security Problem in Open-World Agents
- Do Coding Agents Understand Least-Privilege Authorization?
- How Agents Ask for Permission: User Permissions for AI Agents, from Interfaces to Enforcement
- Proof-Carrying Agent Actions: Model-Agnostic Runtime Governance for Heterogeneous Agent Systems
- CAVA: Canonical Action Verification and Attestation for Runtime Governance of Agentic AI Systems
- ToolGuardian: Declarative Security for AI Agent-Tool Interactions
- Measuring the Permission Gate: A Stress-Test Evaluation of Claude Code's Auto Mode
- Reframing LLM Agent Security as an Agent-Human Interaction Problem
- Overlaying Governance: A Compositional Authorization Framework for Delegation and Scope in Agentic AI
- Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks
- Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections
- Operational Reframing and Approval-Framed Delegation in Multi-Agent LLM Safety
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs