arXiv:2609.38248v1 Announce Type: new Abstract: Large language model agents can execute commands, create subprocesses, and directly access files and networks, allowing prompt injection or planning errors to become operating-system side effects. We present ContractWarden, a Linux reference monitor that enforces a human-authorized damage boundary without trusting the agent or its policy suggestions.

Read the full article at arXiv cs.CR →