Policy dependency / Stack layer
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Policy dependency / Stack layer
RIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persisting
arXiv 2609.12127
Policy dependency / Stack layer
An audit of a production agent pipeline found a reported p99 latency of 2,147,483,647 ms, the signed 32-bit maximum, from a lifecycle clamp
arXiv 2609.12017
Stack layer / Threat pattern
Adversarial Issue Descriptions Make Repair Agents Ship Correct-but-Insecure Patches in 51.7% of Cases
arXiv 2609.15963
Stack layer / Threat pattern
51.1% of Multi-Version MCP Servers Changed What They Advertise, and 4.2% Repointed Their Endpoint to a Different Host Without Telling Clients
arXiv 2609.14119
Stack layer / Contrast
Two-gap framework recasts reward hacking and hallucination as symptoms of requirement and model gaps
arXiv
Policy dependency / Stack layer
HazardAuditor runs Claude Code, Codex, Hermes and OpenClaw in one harness and normalizes their events to train a guard model
arXiv / HuggingFace Daily Papers
Stack layer / Threat pattern
787,562 Function Pairs Show AI Code Is Half the Size of Human Code With Different Defect Classes, Not Fewer
arXiv 2609.12708