arXiv:2609.22573v1 Announce Type: new Abstract: LLM agents translate natural-language context, which may include attacker-controlled text, into privileged tool calls, so authorization must remain effective even when an agent is prompt-injected or adversarially steered.

Read the full article at arXiv cs.CR →