When Valid Tool Calls Change Meaning: Formation-Consistent Dispatch for LLM Agents
Organizations: Korea Advanced Institute of Science and Technology
Abstract
Tool-enabled agents form calls from model-visible interfaces, while hosts later select their implementation. Standard dispatch omits the descriptor-handler relation. An unchanged and schema-valid call can therefore acquire a different security effect during rollout, reconnect, or delayed approval. We call this failure schema-epoch drift. We present formation-consistent dispatch (FCD), which connects implementation analysis to execution authority. Reviewed profiles produce provenance-bound over-approximations of declared in-scope effects from official source. Under a closed-target approval policy, a verifier applies each formed call to a summary and captures a successor only when its effects fit the call's security contract. Atomic admission and a final-hop fence preserve this decision to the effect. The exact source retains priority, and the captured successor becomes eligible only after source retirement. Stock releases and deployment changes reproduced the failure. Four profiles covered 32 official releases: 29 required no release-specific change and three escalated. A frozen 16-release expansion matched a separate source oracle. In a preregistered stock comparison, FCD completed all three pending calls whose effect remained private and blocked all three whose omission became public. Exact pinning and release-wide denial stopped all six calls, while release-wide approval completed all six but produced three public effects. A separate lifecycle experiment carried a formation-captured certificate across source retirement. The same safe certificate installed later governed new formations without expanding the pending call's authority.
Figures & tables
| Component | Trusted role | Supported claim |
|---|---|---|
| Host, session channel, and continuation store | Retain the formation snapshot, bind the arguments, and reject stored-record rollback or substitution | Formation provenance |
| Gateway and registry | Validate credentials and order admission against lifecycle changes | Target identity |
| Pool mapping and final fence | Connect the admitted identity to the implementation that produces the effect | Execution identity |
| Policy clock and resolver | Order expiry, revocation, uncertain outcomes, and safe retirement | Lifecycle safety |
| Registrar, profile author, and compatibility issuer | Define interpreter coverage and analysis scope; establish source fidelity; review escalations | Conditional semantics |
| System | Formation execution | Relevant argument | Formation-time authority | Recorded execution | Preserved? |
|---|---|---|---|---|---|
| GitHub | N O | omitted | private | public | X |
| GitHub | N O, bound | omitted | private | no repository request | V |
| Azure | N O | omitted | network disabled | network enabled | X |
| Azure | N O, bound | omitted | network disabled | no ARM request | V |
| Ref. Git | N N | identical bytes | reject; no file | rejected; no file, 3/3 | V |
| Ref. Git | N O | identical bytes | reject; no file | canary file created, 3/3 | X |
| Profile | Reviewed region | Inventory item |
|---|---|---|
| Reference Git / Python | AST body of git_diff | Resolved callee path |
| DBHub / JavaScript | Four named classifier and handler functions | Dotted callee token |
| GitHub / Go | Named CreateRepository block | Dotted callee token |
| Azure / C# | Unique CreateResourceAsync method | Dotted callee token |
| Profile | Release groups | Modeled transition | Check |
|---|---|---|---|
| Reference Git / Python | 4 unsafe + 4 reject | Dash target: UNSAFE REJECT | Stock 8/8 |
| DBHub / JavaScript | 4 unsafe + 1 reject + 3 escalation | PRAGMA assignment: UNSAFE REJECT ; later source-shape exit | Stock 5/5 |
| GitHub / Go | 4 default-false + 4 default-true | Omitted private : UNSAFE SAFE | Oracle 8/8 |
| Azure / C# | 4 option-absent + 4 option-wired | Omitted network option: UNSAFE SAFE | Oracle 8/8 |
| Total | 29 automatic + 3 escalation | 4 modeled transitions; 3 structure exits | 13 stock + 16 oracle |
| Mutation | Proof obligation | Observed result |
|---|---|---|
| Git comment spoof | Comments cannot create a guard fact | Dangerous state retained |
| Git guard after sink | Dash rejection must precede the sink | Dangerous state retained |
| Git missing sink | One direct diff sink is required | Registration rejected |
| DBHub comment spoof | Comments cannot create an assignment guard | Dangerous state retained |
| DBHub missing guard | Read-only guard is required | Registration rejected |
| DBHub fall-through guard | Guard failure must return before the sink | Registration rejected |
| Policy | A | B | New | Violation |
|---|---|---|---|---|
| Exact pinning | 0/3 | 0/3 | 6 | 0 |
| Release-wide deny | 0/3 | 0/3 | 6 | 0 |
| Release-wide allow | 3/3 | 3/3 | 0 | 3 public |
| Call-specific FCD | 3/3 | 0/3 | 3 | 0 |
| Condition | Pending authority | Outcome after retirement |
|---|---|---|
| Exact pinning | Source only | Reject, 0/5 effects |
| Execution-time adoption | Late manual edge rewrites record | v1.5 effect, 5/5 |
| Captured manual edge | v1.5 captured at formation | v1.5 effect, 5/5 |
| Late manual edge | Source-only record retained | Reject, 0/5 effects |
| Captured generated cert. | v1.5 identity and cert. captured | v1.5 effect, 3/3 |
| Late generated cert. | Old record remains source-only | Old callback 0/3; fresh formation 3/3 |
| Mechanism | Protected object | While source exists | Target first authorized after formation | After source retirement |
|---|---|---|---|---|
| Exact pinning | Target version | Execute exact source | Reject pending call | Reject |
| Execution-time compatibility | Current compatibility policy | Select current target | May authorize target for pending work | Select under current policy |
| Formation-time fallback | Captured candidates | Prefer exact source | Reject for pending call | Select fallback; lifecycle unspecified |
| Semantic differencing [ 11 , 12 ] | Cross-version behavior | Compare implementations | Analyze later target | No invocation authority |
| ETDI [ 7 ] | Approved definition version/hash | Use approved definition | Require reapproval | No call-specific retirement rule |
| Attested admission [ 8 ] | Selected server | Authenticate server | Authenticate later server | No formation-scoped successor |
Appendix figures & tables1 asset
Supplementary material from the paper’s appendix.
Appendix
| Profile | Accepted source structure | Supported arguments | Modeled effects | UNKNOWN , rejection, or escalation |
|---|---|---|---|---|
| Reference Git / Python | One git_diff ; direct target flow to one repo.git.diff ; optional dash-prefix rejection before the sink | Non-dash targets; exact --output=path family; verified pre-sink dash rejection | Normal diff; filesystem write; handler rejection | Other unpatched options are UNKNOWN ; missing or ambiguous sink structure rejects |
| DBHub / JavaScript | Unique classifier and handler functions; every statement reaches the classifier; failed guard returns before executeSQL | Single SELECT ; PRAGMA read; exact PRAGMA user_version = integer family | SQL read; SQLite mutation; handler rejection | Multiple or unsupported statements are UNKNOWN ; classifier, keyword, or guard-flow drift rejects or escalates |
| GitHub / Go | One CreateRepository ; Boolean private parser; direct value flow through the request to one create sink | Contract-bound name; omitted or explicit Boolean private | Authenticated repository creation; private or public exposure | Parser, default, type, or request-flow mismatch rejects; names outside the contract are UNKNOWN |
| Azure / C# | Legacy hard-coded enabled shape or complete option wiring to one ARM deployment sink; partial wiring rejects | Contract-bound resource; omission in either shape; explicit Boolean only in the wired shape | Redis creation intent; public network enabled or disabled | Explicit option on the legacy shape is UNKNOWN ; partial, duplicate, or missing wiring rejects |