2 papers
cs.CR2026
Reachability-Based Capability Confinement for LLM Agents under Indirect Prompt Injection
Wujie Xiong, Rabimba Karanjai, Yang Lu +2
Large language model agents place outputs from external skills into their execution context, allowing attacker-controlled data to influence later privileged actions. Existing defen…
cs.CR2026
When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling
Rabimba Karanjai, Yang Lu, Nour Diallo +4
AI agents increasingly act rather than merely read: across the Model Context Protocol (MCP) ecosystem, the share of deployed tools that modify external state has risen from 27% to…