Skip to content
Search
paperAugust 2026Unreviewed

AgentFlow: A Flow-Centric Policy Language and Framework for Securing LLM Agent Systems

B. Shivakumar, Swarn Priya, Peng Gao

Abstract

LLM agents increasingly read untrusted content, invoke external tools, access private data, and delegate work to other agents. Harm often arises not from a single unsafe action but from the flow of sensitive data across a sequence of otherwise plausible steps. We present AgentFlow, a flow-centric policy language and runtime enforcement model for specifying where data may travel in agent systems. Policies are defined over labeled runtime edges and constrain which tools may receive sensitive field

Categories

Cite

@misc{shivakumar2026agentflow,
  title = {{AgentFlow: A Flow-Centric Policy Language and Framework for Securing LLM Agent Systems}},
  author = {B. Shivakumar and Swarn Priya and Peng Gao},
  year = {2026},
  month = aug,
  eprint = {2608.22868},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/69ab62ec5938e6e397cb83f87e3d3fc02afea3a1}
}