May 2026Unreviewed
Architectural Obsolescence of Unhardened Agentic-AI Runtimes
Alfredo Metere
Abstract
An agentic-AI runtime issues tool calls, sends messages, and actuates devices on behalf of an LLM. Catching the four ways an action can diverge from its audit record -- F1 gate-bypass, F2 audit-forgery, silent host failure, F4 wrong-target, -- is a load-bearing safety property of any such runtime. We show that upstream OpenClaw, the most engineered single-user agentic-AI gateway in public release, catches none of them: recall is 0.000 on every cell of every confusion matrix, on a 1600-sample tem
Categories
Cite
@misc{metere2026architectural,
title = {{Architectural Obsolescence of Unhardened Agentic-AI Runtimes}},
author = {Alfredo Metere},
year = {2026},
month = may,
eprint = {2605.01740},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.01740}
}