April 2026Unreviewed
ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
Wei Zhao, Zhe Li, Peixin Zhang, Jun Sun
Abstract
Tool-augmented Large Language Model (LLM) agents have demonstrated impressive capabilities in automating complex, multi-step real-world tasks, yet remain vulnerable to indirect prompt injection. Adversaries exploit this weakness by embedding malicious instructions within tool-returned content, which agents directly incorporate into their conversation history as trusted observations. This vulnerability manifests across three primary attack channels: web and local content injection, MCP server inj
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{zhao2026clawguard,
title = {{ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection}},
author = {Wei Zhao and Zhe Li and Peixin Zhang and Jun Sun},
year = {2026},
month = apr,
eprint = {2604.11790},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.11790}
}