One foothold, many permissions: the transitive authority problem for AI agents
A benign goal does not grant every intermediate permission needed to complete it. Connected tools make that distinction operational rather than philosophical.
AI security research / articles
Analysis across cases.
19 Articles · Page 2 of 4
5 matching records on this page
From the archive
A benign goal does not grant every intermediate permission needed to complete it. Connected tools make that distinction operational rather than philosophical.
A technical reconstruction of PhantomRaven, the npm supply-chain campaign that combined plausible package names, remote URL dependencies and install-time execution, with separate evidence for slopsquatting and likely LLM-assisted malware development.
DG-VDT reports strong zero-shot results for classifying three Ethereum vulnerability types from EVM execution traces, but the headline latency measures model inference after trace generation, not end-to-end auditing. The strongest result is promising benchmark evidence rather than an independently reproduced production capability.
Long-running agents inherit state. The security question is who wrote that state, why the next agent trusts it, and whether shared memory can silently become an instruction channel.
Recent agent incidents make the near-term control problem concrete: permissions, egress, supervision, dependency and incident accountability are already under strain, even though the strongest futurist loss-of-control scenario remains unobserved.
No matches on this page.