MiniScope: Authorizing Agents with Least-Privilege Permissions
Read the original on arXiv AI →The Flow has not summarised this story yet — read it at arXiv AI.
The Flow has not summarised this story yet — read it at arXiv AI.
arXiv:2607. 01510v1 Announce Type: new Abstract: AI agents that autonomously execute tool calls on a user's behalf raise pressing questions about permission management: what role could users play, and what role should they play?
arXiv:2607. 13718v1 Announce Type: cross Abstract: As AI agents gain prevalance, users are increasingly exposed to the risks such systems entail.
The paper evaluates a task-based permission scoping architecture for AI agents, comparing a fine‑tuned RoBERTa‑large encoder to few‑shot Claude Haiku 4.5 on a 600‑prompt dataset. It shows the new system achieves comparable macro‑F1 (0.881 vs. 0.886) and higher precision (0.897 vs. 0.842), while reducing severity‑weighted residual risk from 1.12 to 0.63. The study also introduces an attack‑surface elimination metric, demonstrating that task‑granular control can close 84.4% of the severity‑weighted surface, far surpassing role‑based ceilings alone.
arXiv:2601.12449v2 Announce Type: replace-cross Abstract: AI agents are autonomous systems that combine LLMs with external tools to solve complex tasks. While such tools extend capability, improper t...
The paper introduces skilder, a framework that organizes LLM agent capabilities into role‑scoped bundles of skills, tools, and instructions, with explicit limits. Agents start with a minimal role catalog, discover the roles needed for a task, and receive the associated tools only through a single MCP server, ensuring deterministic enforcement of scope. Experiments on 13 tasks with six models show that skilder’s authorization layer prevents unauthorized tool calls and parameter violations while maintaining flexibility through dynamic cross‑role capability acquisition.
arXiv:2606. 20023v1 Announce Type: cross Abstract: As LLM agents increasingly select tools autonomously, their choices among tools with different privileges become safety-relevant.