SINGED: Correct Outputs Do Not Certify Safe Execution in LLM Agents
cs.CR, cs.AI
Submitted: 2026-09-27
Updated: 2026-09-27
Code: https://github.com/OpenHands/software-agent-sdk
Terminology
Sources
- Evaluating Position Bias in Large Language Model Recommendations
- A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models
- MalTool: Malicious Tool Attacks on LLM Agents
- Kimi K2.5: Visual Agentic Intelligence
- Kimi K3: Open Frontier Intelligence
- AgentDyn: Are Your Agent Security Defenses Deployable in Real-World Dynamic Environments?
- CAITLYN: Can LLM Agents Autonomously Synthesize Defenses against Emerging Injection Attacks?
- Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
- Trust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills
- Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
- Prompt Injection Attack to Tool Selection in LLM Agents
- ToolTweak: An Attack on Tool Selection in LLM-based Agents
- MCPTox: A Benchmark for Tool Poisoning Attack on Real-World MCP Servers
- When Routine Chats Turn Toxic: Unintended Long-Term State Poisoning in Personalized Agents
- SafeAgentBench: A Benchmark for Safe Task Planning of Embodied LLM Agents
- Ranked by Position: Order Sensitivity as an Exploitable Attack Surface in LLM Listwise Recommenders
- MemMorph: Tool Hijacking in LLM Agents via Memory Poisoning
- Agent-SafetyBench: Evaluating the Safety of LLM Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs