TEE-Backed Isolation for Computer-Use Agents: Intel TDX Blocks Unsafe Operations Before Execution
arXiv·medium signal
Researchers propose operation-centric risk-based confinement for self-hosted computer-use agents like OpenClaw, running security-critical classification and authorization inside Intel TDX trusted execution environments. The design blocks unsafe or policy-disallowed operations before execution while maintaining normal functionality and producing auditable evidence trails that cannot be forged by compromised host software.