arXiv:2609.27542v1 Announce Type: new Abstract: The safety of a tool-using language model agent is usually treated as a property of the model alone. We give controlled, full-precision evidence that it is instead a joint property of the model and the software that renders its chat template and parses its tool calls, the decoding harness, and that both halves are attackable from untrusted input.

Read the full article at arXiv cs.CR →