April 2026Unreviewed
SUDP: Secret-Use Delegation Protocol for Agentic Systems
Xiaohang Yu, Hejia Geng, Xinmeng Zeng, William Knottenbelt
Abstract
Agentic systems increasingly act with user secrets for APIs, messaging platforms, and cloud services. Today's bearer-secret interfaces implement authorization by exposure: enabling action often means placing a reusable secret, or a reusable artifact derived from it, within a model-steerable boundary, so a transient prompt-injection or tool-side compromise becomes durable account compromise. Existing defenses cover adjacent pieces such as secret storage, scoped delegation, sender-constrained toke
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{yu2026sudp,
title = {{SUDP: Secret-Use Delegation Protocol for Agentic Systems}},
author = {Xiaohang Yu and Hejia Geng and Xinmeng Zeng and William Knottenbelt},
year = {2026},
month = apr,
eprint = {2604.24920},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2604.24920}
}