Approval Laundering: Systematizing Approval--Execution Binding Failures in AI Coding-Agent Harnesses
cs.CR, cs.AI, cs.SE
Submitted: 2026-09-30
Updated: 2026-09-30
Terminology
Sources
- Loopjacking: Hijacking Human-in-the-Loop Approval
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- Measuring the Permission Gate: A Stress-Test Evaluation of Claude Code's Auto Mode
- Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks
- What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents
- From Review to Authorization: Key-Isolated Threshold Signing for LLM Agents
- The Verifiable Action Card: Trustworthy Human-in-the-Loop Control for Secure Autonomous Agents
- Defeating Prompt Injections by Design
- Contextual Agent Security: A Policy for Every Purpose
- SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
- LLM Agent Capabilities Should Follow Task Intent and Context Source
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs