August 2026Unreviewed
TraceGrant: A Contract-Governed Security Framework for the Task-Effect Lifecycle of Networked LLM Agents
Bohao Liao, Jingchao Wang, Qipeng Song, Jin Cao, Jieling Wang, Boyu Deng
Abstract
Networked large language model (LLM) agents retrieve information from email, cloud storage, calendars, transaction platforms, and Web services to complete multistep tasks that produce persistent external effects. The same content needed for legitimate execution may also contain indirect prompt injections that redirect tool use, alter sensitive arguments, or disrupt task completion. Existing defenses mainly constrain untrusted content or individual tool calls, leaving user intent, runtime evidenc
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
OWASP Top 10 for Agentic Applications
- ASI02Tool Misuse & Exploitation
MITRE ATLAS
- AML.T0051LLM Prompt Injection
- AML.T0053AI Agent Tool Invocation
Suggested from the entry's categories.
Cite
@misc{liao2026tracegrant,
title = {{TraceGrant: A Contract-Governed Security Framework for the Task-Effect Lifecycle of Networked LLM Agents}},
author = {Bohao Liao and Jingchao Wang and Qipeng Song and Jin Cao and Jieling Wang and Boyu Deng},
year = {2026},
month = aug,
eprint = {2608.21126},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.21126}
}