7 papers
Attested Tool-Server Admission: A Security Extension to the Model Context Protocol
Alfredo Metere
The Model Context Protocol (MCP) standardizes how a large-language-model (LLM) agent and an external tool server exchange messages, but not trust: a host reads a server's self-decl…
An Application-Layer Multi-Modal Covert-Channel Reference Monitor for LLM Agent Egress
Alfredo Metere
A large language model (LLM) agent that sends messages can leak data inside them. Destination allowlists and content scanners do not police whether an otherwise-benign payload is i…
Skills as Verifiable Artifacts: A Trust Schema and a Biconditional Correctness Criterion for Human-in-the-Loop Agent Runtimes
Alfredo Metere
Agent skills - structured packages of instructions, scripts, and references that augment a large language model (LLM) without modifying the model itself - have moved from convenien…
enclawed: A Configurable, Sector-Neutral Hardening Framework for Single-User AI Assistant Gateways
Alfredo Metere
We present enclawed, a hard-fork hardening framework built on the OpenClaw AI assistant gateway. enclawed targets deployments that need attestable peer trust, deny-by-default exter…
Methods for Formal Verification of Agent Skills: Three Layers Toward a Mechanically Checkable Capability-Containment Proof
Alfredo Metere
The companion paper introduced a four-level verification lattice on agent-skill manifests (unverified, declared, tested, formal) and left the top level aspirational. This paper clo…
Architectural Obsolescence of Unhardened Agentic-AI Runtimes
Alfredo Metere
An agentic-AI runtime issues tool calls, sends messages, and actuates devices on behalf of an LLM. Catching the four ways an action can diverge from its audit record -- F1 gate-byp…