Skip to content
Search
paperAugust 2026Unreviewed

Bounded Agents: Delegation Security for Multi-Agent AI Systems

Xabier Muruaga

Abstract

LLM-based agents can act on behalf of a user to access cloud services, call tools, or invoke agents. At session start, the agent's permissions are set but remain static, and each request is evaluated independently, without considering prior actions. Within its permissions, an agent may act contrary to the delegated task, combine individually permitted actions into a prohibited outcome, or delegate authority to a sub-agent without limiting it. A prompt injection poses a risk only if the agent has

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{muruaga2026bounded,
  title = {{Bounded Agents: Delegation Security for Multi-Agent AI Systems}},
  author = {Xabier Muruaga},
  year = {2026},
  month = aug,
  eprint = {2608.15888},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.15888}
}