[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82958-en":3,"doc-seo-82958-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82958,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","AIAUTHZ: OFF-HOST, IDENTITY-BOUND AUTHORIZATION FOR AI AGENTS","AI agents execute tool calls based on text they cannot independently verify, enabling context-controlling attackers to forge the appearance of authority. Evaluations across 15 contemporary language models under eight agent-incident attack scenarios show refusal rates ranging from 100% to 38%, with cost not reliably correlating with safety. aiAuthZ is an authorization gateway that validates caller identity using per-message HMAC-SHA256 bound to a nonce and timestamp window, enforces role- and argument-level policy, and records decisions in a hash-chained audit log.","arXiv :2607 .055 18v 1 [ cs .CR] 6 Jul 2026  \nAIAUTHZ: OFF-HOST, IDENTITY-BOUND AUTHORIZATION FOR  \nAI AGENTS  \nA PREPRINT  \n Sai Varun Kodathala  \nResearch & Development  \nSportsVision AI  \nMinnetonka, MN  \n[varun@sportsvision.ai](varun@sportsvision.ai)  \nJuly 8, 2026  \nABSTRACT  \nAI agents issue tool calls on the basis of text they cannot verify, so any party who controls part of the context can forge the appearance of authority. I evaluate 15 contemporary language models against eight attack scenarios derived from a published corpus of real agent incidents and find that refusal varies from 100% down to 38% across fully evaluated models; the most expensive model refused only half of the attacks despite a twentyfold price spread. I present aiAuthZ, an authorization gateway that moves the safety decision off the agent’s host. Before a tool call executes, the gateway verifies caller identity with a per-message HMAC-SHA256 signature bound to a single-use nonce and a timestamp window, and it evaluates a role-based and argument-level policy that the agent can neither read nor modify. Every decision joins a SHA-256 hash-chained audit log, and each accepted message yieldsan HMAC-authenticated QR receipt that achieves 94% mean verification across eight transmission channels, with zero forgeries accepted in 25 wrong-key trials. With the gateway in place, residual attack success falls to 0% for all 15 models at no more than 0.03 ms of added decision latency. On the AgentDojo banking suite, aiAuthZ blocks all seven attacker-directed tool calls the evaluated agents emit, at the cost of one legitimate first-time payment, while a spotlighting baseline allows two injections to succeed. Across nine in-scope case studies from the same incident corpus, aiAuthZ blocks nine of nine, against four of nine for a policy baseline without identity binding. The gateway does not prevent a model from being deceived; it prevents a deceived model from acting beyond the verified user’s authority on every call routed through it. The implementation and all experiments are released at [https://github.com/Sports-Vision-Inc/aiAuthZ](https://github.com/Sports-Vision-Inc/aiAuthZ).  \nKeywords LLM agents · prompt injection · agent security · authorization · access control · tool calling · Model Context Protocol  \n1 Introduction  \n1.1 The problem: tool-using models act on untrusted text  \nAn AI model with tool access turns natural language into actions: it reads files, runs shell commands, calls APIs, and sends email [Debenedetti et al., 2024, Ruan et al., 2024] . Two questions decide whether any given action is safe. First, who is asking? The instruction that reaches the model may come from the authorized user, from another user in a shared channel, or from text the model retrieved from a document, a web page, or a tool result. Second, is this caller allowed to perform this action? Even an authentic user is not permitted to do everything. Most deployed systems answer both questions inside the model, probabilistically, by instructing it to act within policy. Indirect prompt injection shows why this is fragile: an adversary who controls any text the model reads can steer the actions the model takes [Greshake et al., 2023] . My measurements confirm the fragility at the level of individual models: the same attack is refused by one model and executed by another, and the most expensive model is not the safest.  \nThis gap is not confined to autonomous multi-step agents. The same authorization question arises for a support chatbot with function calling that can issue refunds, for a retrieval-augmented assistant that acts on documents it retrieves, for a voice bot that turns a phone call into a funds transfer, for a workflow automation node triggered by inbound email, and for a coding assistant that calls shell, file, and web tools. In every case the security-relevant event is identical: a model emitted a tool call, and something must decide whether that specific caller may ","cbCailLXI5w3ok2U","https://ap.wps.com/l/cbCailLXI5w3ok2U","pdf",654260,2,1,17,"English","en",105,"# Introduction\n## The problem: tool-using models act on untrusted text\n## Motivating evidence: production incidents and the Agents of Chaos corpus","[{\"question\":\"What security problem does the paper focus on for tool-using AI agents?\",\"answer\":\"It focuses on how a tool call issued by an AI agent may be unsafe when the model cannot verify the untrusted text that supplies instructions. A separate decision is required to determine whether the specific caller is allowed to perform the specific action.\"},{\"question\":\"How does aiAuthZ decide whether a tool call should be allowed?\",\"answer\":\"Before execution, the gateway verifies caller identity using a per-message HMAC-SHA256 signature bound to a single-use nonce and a timestamp window. It then applies role-based and argument-level policy that the agent cannot read or modify, and it logs each decision in a hash-chained audit trail.\"},{\"question\":\"What experimental results show that aiAuthZ improves safety compared with model-internal authorization?\",\"answer\":\"Across eight transmission channels and multiple evaluations, aiAuthZ achieves high verification accuracy and accepts zero forgeries under wrong-key trials. With the gateway in place, residual attack success drops to 0% across 15 evaluated models, and on the AgentDojo banking suite it blocks all seven attacker-directed tool calls emitted by the evaluated agents.\"}]",1784184330,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"aiauthz-off-host-identity-bound-authorization-for-ai-agents","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/aiauthz-off-host-identity-bound-authorization-for-ai-agents/82958/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What security problem does the paper focus on for tool-using AI agents?","Question",{"text":75,"@type":76},"It focuses on how a tool call issued by an AI agent may be unsafe when the model cannot verify the untrusted text that supplies instructions. A separate decision is required to determine whether the specific caller is allowed to perform the specific action.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does aiAuthZ decide whether a tool call should be allowed?",{"text":80,"@type":76},"Before execution, the gateway verifies caller identity using a per-message HMAC-SHA256 signature bound to a single-use nonce and a timestamp window. It then applies role-based and argument-level policy that the agent cannot read or modify, and it logs each decision in a hash-chained audit trail.",{"name":82,"@type":73,"acceptedAnswer":83},"What experimental results show that aiAuthZ improves safety compared with model-internal authorization?",{"text":84,"@type":76},"Across eight transmission channels and multiple evaluations, aiAuthZ achieves high verification accuracy and accepts zero forgeries under wrong-key trials. With the gateway in place, residual attack success drops to 0% across 15 evaluated models, and on the AgentDojo banking suite it blocks all seven attacker-directed tool calls emitted by the evaluated agents.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]