Tool-enabled agents form calls from model-visible interfaces, while hosts later select their implementation. Standard dispatch omits the descriptor-handler relation. An unchanged and schema-valid call can therefore acquire a different security effect during rollout, reconnect, or delayed approval. We call this failure schema-epoch drift. We present formation-consistent dispatch (FCD), which connects implementation analysis to execution authority. Reviewed profiles produce provenance-bound over-approximations of declared in-scope effects from official source. Under a closed-target approval policy, a verifier applies each formed call to a summary and captures a successor only when its effects fit the call's security contract. Atomic admission and a final-hop fence preserve this decision to the effect. The exact source retains priority, and the captured successor becomes eligible only after source retirement. Stock releases and deployment changes reproduced the failure. Four profiles covered 32 official releases: 29 required no release-specific change and three escalated. A frozen 16-release expansion matched a separate source oracle. In a preregistered stock comparison, FCD completed all three pending calls whose effect remained private and blocked all three whose omission became public. Exact pinning and release-wide denial stopped all six calls, while release-wide approval completed all six but produced three public effects. A separate lifecycle experiment carried a formation-captured certificate across source retirement. The same safe certificate installed later governed new formations without expanding the pending call's authority.
Figures & tables
Component
Trusted role
Supported claim
Host, session channel, and continuation store
Retain the formation snapshot, bind the arguments, and reject stored-record rollback or substitution
Formation provenance
Gateway and registry
Validate credentials and order admission against lifecycle changes
Target identity
Pool mapping and final fence
Connect the admitted identity to the implementation that produces the effect
Execution identity
Policy clock and resolver
Order expiry, revocation, uncertain outcomes, and safe retirement
Lifecycle safety
Registrar, profile author, and compatibility issuer
TABLE I: Trusted authorization plane. The deployment and routing controller remains outside this TCB.
System
Formation → execution
Relevant argument
Formation-time authority
Recorded execution
Preserved?
GitHub
N → O
omitted
private
public
X
GitHub
N → O, bound
omitted
private
no repository request
V
Azure
N → O
omitted
network disabled
network enabled
X
Azure
N → O, bound
omitted
network disabled
no ARM request
V
Ref. Git
N → N
identical bytes
reject; no file
rejected; no file, 3/3
V
Ref. Git
N → O
identical bytes
reject; no file
canary file created, 3/3
X
TABLE II: Representative stock-release and reconnect results. O and N denote older and newer releases. V marks preserved formation authority; X marks a reversal.
Profile
Reviewed region
Inventory item
Reference Git / Python
AST body of git_diff
Resolved callee path
DBHub / JavaScript
Four named classifier and handler functions
Dotted callee token
GitHub / Go
Named CreateRepository block
Dotted callee token
Azure / C#
Unique CreateResourceAsync method
Dotted callee token
TABLE III: Bounded call-site inventories. Each row compares the recognized callee set in one source region with a reviewed allowlist.
Profile
Release groups
Modeled transition
Check
Reference Git / Python
4 unsafe + 4 reject
Dash target: UNSAFE → REJECT
Stock 8/8
DBHub / JavaScript
4 unsafe + 1 reject + 3 escalation
PRAGMA assignment: UNSAFE → REJECT ; later source-shape exit
Stock 5/5
GitHub / Go
4 default-false + 4 default-true
Omitted private : UNSAFE → SAFE
Oracle 8/8
Azure / C#
4 option-absent + 4 option-wired
Omitted network option: UNSAFE → SAFE
Oracle 8/8
Total
29 automatic + 3 escalation
4 modeled transitions; 3 structure exits
13 stock + 16 oracle
TABLE IV: Security-relevant regimes across official releases. Repeated releases within a regime measure profile reuse; each arrow marks a change in the concrete-call decision.
Mutation
Proof obligation
Observed result
Git comment spoof
Comments cannot create a guard fact
Dangerous state retained
Git guard after sink
Dash rejection must precede the sink
Dangerous state retained
Git missing sink
One direct diff sink is required
Registration rejected
DBHub comment spoof
Comments cannot create an assignment guard
Dangerous state retained
DBHub missing guard
Read-only guard is required
Registration rejected
DBHub fall-through guard
Guard failure must return before the sink
Registration rejected
TABLE V: Semantic mutations mapped to reviewed proof obligations. All seven produced the expected result.
Policy
A
B
New
Violation
Exact pinning
0/3
0/3
6
0
Release-wide deny
0/3
0/3
6
0
Release-wide allow
3/3
3/3
0
3 public
Call-specific FCD
3/3
0/3
3
0
TABLE VI: Call granularity after source retirement. A remains private on the target; B becomes public. “New” counts calls that require new formation and approval.
Condition
Pending authority
Outcome after retirement
Exact pinning
Source only
Reject, 0/5 effects
Execution-time adoption
Late manual edge rewrites record
v1.5 effect, 5/5
Captured manual edge
v1.5 captured at formation
v1.5 effect, 5/5
Late manual edge
Source-only record retained
Reject, 0/5 effects
Captured generated cert.
v1.5 identity and cert. captured
v1.5 effect, 3/3
Late generated cert.
Old record remains source-only
Old callback 0/3; fresh formation 3/3
TABLE VII: Successor authority after source retirement. Manual-edge and generated-certificate rows come from separate frozen stock experiments.
Mechanism
Protected object
While source exists
Target first authorized after formation
After source retirement
Exact pinning
Target version
Execute exact source
Reject pending call
Reject
Execution-time compatibility
Current compatibility policy
Select current target
May authorize target for pending work
Select under current policy
Formation-time fallback
Captured candidates
Prefer exact source
Reject for pending call
Select fallback; lifecycle unspecified
Semantic differencing [ 11 , 12 ]
Cross-version behavior
Compare implementations
Analyze later target
No invocation authority
ETDI [ 7 ]
Approved definition version/hash
Use approved definition
Require reapproval
No call-specific retirement rule
Attested admission [ 8 ]
Selected server
Authenticate server
Authenticate later server
No formation-scoped successor
TABLE VIII: Closest mechanisms under one pending-work trace.
Appendix figures & tables1 asset
Supplementary material from the paper’s appendix.
Appendix
Profile
Accepted source structure
Supported arguments
Modeled effects
UNKNOWN , rejection, or escalation
Reference Git / Python
One git_diff ; direct target flow to one repo.git.diff ; optional dash-prefix rejection before the sink
Tool-using LLM agents increasingly read untrusted content while holding side-effecting tools such as payments, email, CRM, and infrastructure APIs, yet common framework defaults still conflate tool exposure with authorization. We audit whether LangChain/LangGraph, LlamaIndex, and the Stripe Agent Toolkit re-authorize each model-emitted call, with concrete argument values, before execution. Across pinned public-source commits, all three provide capability gating by default, but none provides a deterministic fail-closed per-call value authorization gate by default. We introduce ScopeGate, a five-stage PDP/PEP for agent tool calls: scope, authorization, money ceiling, idempotency, and default deny. Evaluation shows the identical unauthorized payout call executes under LangChain's default dispatch (with a companion LlamaIndex PoC) but is denied by ScopeGate; the tested control reports 0/48 static bypasses, 0/29 unauthorized attempts (40-iteration adaptive run), 0/10 benign false-denies, and Latam-GPT payment-agent containment at 10/10. ASR denotes attempted unauthorized action, containment is not a cure, deployment-tier claims are inference over measured model classes, and no CVE is asserted.
Tool-using large language model (LLM) agents turn generated text into real side effects, so poisoned tool metadata, retrieved pages, memory, and reusable skills can steer the next call. Vetting an artifact before admission does not settle this. A safe variant and a leaking variant can produce the same admission evidence, and a sound gate then cannot relax that site for either. We make that condition precise, which leaves the last boundary a deployment can still act on. We present Provenance-Aware Capability Enforcement (PACE), which mediates every tool call immediately before it executes. Path confinement proposes an executable cut of represented influence paths, while capability and effect verification checks schema-defined effects against authority compiled from the authenticated request. We distinguish the certified execution contract from the evaluated configuration, which can restore an authorized call after a proposed block or apply a declared repair. Confinement requires the final action to preserve the certified cut. On eight executable agent-security benchmarks with three target-model families, the evaluated configuration gives strictly lowest attack success in 62 of 79 eligible attack columns and ties in 14; full-benchmark native utility loses at most three points relative to the undefended agent. A complete ablation over 1167 paired cases attributes most security gains to effect verification and refusal control to boundary adaptation. A reduced-scale adaptive search succeeds on 0/30 out-of-authority targets against the defense.
Fengpeng Li, Qizhou Wang, Yuke Hu +5
PRADA Lab, King Abdullah University of Science and Technology · Imperfect Information Learning Team, RIKEN Center for Advanced Intelligence Project · State Key Laboratory of Internet of Things for Smart City, University of Macau +2
Tool-augmented large language model agents increasingly rely on external APIs, but standard tool schemas describe how to call a tool, not when the tool is causally appropriate or what task state it produces. Causal tool filtering addresses this gap by using lightweight contracts that specify each tool's preconditions, effects, risk level, and cost. However, manually writing and maintaining such contracts does not scale to large or changing tool ecosystems. We introduce Contract2Tool, a framework for inferring tool contracts from metadata, schemas, documentation, and execution traces. Contract2Tool converts observable tool evidence into normalized symbolic contracts that can be evaluated intrinsically and deployed inside downstream causal tool filtering. We evaluate learned contracts against gold preconditions, effects, and risk labels, and measure their downstream utility on multi-step agent tasks. Our results show that hybrid documentation-and-trace evidence produces contracts accurate enough to preserve most of the reliability and efficiency benefits of gold contracts. Learned-contract CMTF achieves 0.980 downstream success, close to 0.990 for gold-contract CMTF, while reducing visible tools from 100 to 1 and reducing average token usage from 26,172 to 2,528 relative to all-tools exposure. These results suggest that learned contracts can provide a scalable contract layer between tool schemas and reliable agent execution.