deterministic per-tool backend authorization (allowlist, model-independent validation, token scoping, approval gates), individual review of every write and escalation tool.
The threat
the model triggers an unauthorized external action by requesting it through a tool (tool hijacking, unauthorized write, workflow abuse, privilege escalation) or through an agent.
Angle mortWhy classic frameworks miss it
the risk is not what you tell the system but what you enable it to do; an agent fits no classic exposure category.
MitigationProposed approach
deterministic per-tool backend authorization (allowlist, model-independent validation, token scoping, approval gates), individual review of every write and escalation tool.
The proposed control
an action requested through the model happens only if a deterministic backend authorizes it.
Expected evidence
demonstrate that an action requested through the model happens only if a deterministic backend authorizes it.