[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83026-en":3,"doc-seo-83026-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83026,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Context to Execution Integrity for LLM Agents","Language-model agents can turn attacker-controlled context into tool calls and other side effects, causing authority laundering when evidence-bearing text is treated as authorization. Context-to-Execution Integrity (CXI) enforces an execution-boundary admission check by binding protected sink-field authority, exact-effect authorization for sink-interpreted payloads, and invocation event authority to one canonical action manifest. Policies mark protected fields, typed releases narrow validated values, opaque slots preserve evidence, and a deterministic gate admits execution only when all authorities align, preventing escapes across evaluated agent settings.","Context-to-Execution Integrity for LLM Agents  \nIgor Santos-Grueiro International University of La Rioja  \narXiv :2607 .06000v 1 [ cs .CR] 7 Jul 2026  \nAbstract  \nLanguage-model agents read attacker-writable context to solve tasks. Tool execution needs a separate authority check for protected sink fields, sink-interpreted payloads, and the invocation event. Context-to-Execution Integrity (CXI) is an execution-boundary system for this setting. Policies mark protected sink fields, typed releases carry narrow validated values from writable context to specific destinations, opaque data slots keep evidence as data, and a deterministic gate admits a call only after field authority, exact-effect authorization, and invocation authority all bind to the same action manifest.  \nWe evaluate CXI on open-weight field-projection runs, AgentDojo live episodes, a code-agent exact-effect benchmark, manifest-bound ledger faults, proposal-pressure controls, and hosted/API compatibility traces. AgentDojo covers 720 live episodes and 1,739 LLM calls; the code-agent benchmark covers 400 repository episodes with exact-effect authorization and lease-bound execution, yielding 231 safe task completions and zero observed field, effect, or invocation escapes. The accounting reports parser outcomes, authorization outcomes, and task-quality outcomes together with the admission-integrity result. Across the evaluated sinks, CXI admits execution only when field, effect, and invocation authority bind to the same action manifest.  \n1 Introduction  \nLanguage-model agents now turn text into side effects: they send mail, modify files, update calendars, open pull requests, run shell commands, query databases, and call administrative APIs [27, 36, 49] . They also read emails, webpages, issue comments, README files, retrieval chunks, CI logs, tool outputs, package metadata, and memories that an attacker can write or influence [9, 14, 28, 32] . Many agent stacks put those sources in the same model context that proposes the next tool call.  \nThe resulting failure is not just that malicious text may be followed as an instruction. The systems failure is authority  \nlaundering: a value that should be evidence gains authority to select, authorize, trigger, or parameterize a privileged side effect. A CI log may identify the file that failed; it should not [choose](choose prod_admin.run_sql)[ prod_admin.run_sql](choose prod_admin.run_sql), mark a change as approved, expand a retry budget, or trigger a second production write. An issue body may explain a bug; it should not rewrite CI policy or delegate to a more privileged agent.  \nConsider a structured tool call with a tool name, operation, path, approval state, and retry budget. The call may be well formed even when those values come from writable context. A schema checks names and types; it does not check authority for the protected fields, interpreted effect, or invocation.  \nThe security question is then whether the invocation has authority to occur and whether each protected field has authority for the semantic value consumed by the sink. Asink is the side-effecting endpoint: a tool call, API call, file write, shell command, database operation, workflow update, or delegation step. A FilePath typed release may authorize file_path. The same log or issue text has no authority for approval_state. The failing log line may still be copied as opaque evidence in a comment. The model proposes; the host admits execution only when the invocation, protected fields, and sink-interpreted effects carry authority for the same canonical action.  \nRecent work has moved agent security toward action boundaries. PACT shows that whole-call trust is too coarse and that argument-level provenance can recover utility while blocking untrusted content from binding authority-bearing arguments [12] . ARGUS audits decisions with influence provenance [46]; FORGE develops runtime policies for agentic systems [29]; and AIRGuard frames defense as action-t","cbCaistZc6aEeOte","https://ap.wps.com/l/cbCaistZc6aEeOte","pdf",229302,2,1,20,"English","en",105,"# Abstract\n# Introduction\n## Authority laundering and structured tool calls\n## Action boundaries and related work\n# Context-to-Execution Integrity (CXI)\n## Enforcement at admission time\n# Evaluation","[{\"question\":\"What does CXI enforce at the point right before the side effect occurs?\",\"answer\":\"The gate canonicalizes the proposed action, checks field evidence, verifies exact-effect authorizations, validates semantic bindings under a trusted sink snapshot, consumes an invocation capability in a linearizable ledger, and executes only with the resulting lease.\"}]",1784184732,50,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"context-to-execution-integrity-for-llm-agents","",{"@graph":36,"@context":77},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/context-to-execution-integrity-for-llm-agents/83026/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"What does CXI enforce at the point right before the side effect occurs?","Question",{"text":75,"@type":76},"The gate canonicalizes the proposed action, checks field evidence, verifies exact-effect authorizations, validates semantic bindings under a trusted sink snapshot, consumes an invocation capability in a linearizable ledger, and executes only with the resulting lease.","Answer","https://schema.org",{"og:url":51,"og:type":79,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":81,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":84},[85,89,93,97,102,106,111,114,118,121,125],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":29,"slug":105},6,"Technology","technology",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":112,"slug":113},30,"research-report",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":22,"slug":117},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":119,"show_sort_weight":22,"slug":120},"World Cup","world-cup",{"id":122,"doc_module":4,"doc_module_name":46,"category_name":123,"show_sort_weight":122,"slug":124},10,"Lifestyle","lifestyle",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":127,"show_sort_weight":98,"slug":128},19,"General","general"]