When Valid Tool Calls Change Meaning: Formation-Consistent Dispatch for LLM Agents
cs.AI, cs.CR, cs.SE
Submitted: 2026-09-28
Updated: 2026-09-28
Code: https://github.com/github/github-
Project page: https://yonghwi-kwon.github.io/data/racedb_sp25.pdf
Terminology
Sources
- Parasites in the Toolchain: A Large-Scale Analysis of Attacks on the MCP Ecosystem
- ETDI: Mitigating Tool Squatting and Rug Pull Attacks in Model Context Protocol (MCP) by using OAuth-Enhanced Tool Definitions and Policy-Based Access Control
- Attested Tool-Server Admission: A Security Extension to the Model Context Protocol
- Tool Forge: A Validation-Carrying Toolchain for Governed Agentic Execution
- Cordon: Semantic Transactions for Tool-Using LLM Agents
- It's a Feature, Not a Bug: Secure and Auditable State Rollback for Confidential Cloud Applications
- MCPSecBench: A Systematic Security Benchmark and Playground for Testing Model Context Protocols
- Semantic Attacks on Tool-Augmented LLMs: Securing the Model Context Protocol Against Descriptor-Level Manipulation
- Progent: Securing AI Agents with Privilege Control
- Defeating Prompt Injections by Design
- From Tool Connection to Execution Control: Benchmarking Security Invariants in MCP-Style Agent Runtimes
- CAVA: Canonical Action Verification and Attestation for Runtime Governance of Agentic AI Systems
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection