arXiv AI By Igor Santos-Grueiro

Lingering Authority: Revocable Resource-and-Effect Capabilities for Coding Agents

Read the original on arXiv AI →

arXiv:2606. 22504v1 Announce Type: cross Abstract: Coding agents often receive broad tool access for an entire task, even when a resource is needed only for one subgoal.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Sep 10

Versioned Transitive Dependency-Closure Binding and Operation-Time Effect Governance for Agent Skills: ClosureBound

ClosureBound is a reference monitor that enforces authorization boundaries for agent skills by binding each grant to an exact dependency closure, effect ceiling, purpose, validity, and epochs. It resolves typed graph nodes, normalizes operations into an external‑effect IR, and admits actions only when a joint witness satisfies all bounds, ensuring metadata non‑authority, closure determinism, and other security properties. Empirical evaluation on 549 public skills shows many lack proper dependency declarations, underscoring the need for conservative closure discovery and broader runtime validation.

By Genliang Zhu (Accentrust, Georgia Institute of Technology), Chu Wang (Accentrust, University of Illinois Urbana-Champaign)
arXiv AI
Sep 25

Stale Does Not Mean Unsafe: Guard Precision for Tool-Using LLM Agents under Infrastructure State Races

The paper investigates how tool‑using language‑model agents can safely commit changes to infrastructure when external state may change between read and commit. By distinguishing invalidating races from predicate‑preserving and irrelevant ones, the authors evaluate three commit‑time guard granularities—global epoch, read‑set version, and semantic commit predicate—using a deterministic simulator and three quantized model families. The study finds that only the complete predicate guard consistently eliminates unsafe commits, while freshness‑based guards block a large proportion of benign races and model‑side signals fail to replace precise semantic enforcement.

By Zihao Zheng, Jiayu Long, Baichuan Li, Junyi Yao