Skip to content

Versioned Transitive Dependency-Closure Binding and Operation-Time Effect Governance for Agent Skills: ClosureBound

Sep 2026 · 0 citations · 56 references
Computer Science

TL;DR

This work presents ClosureBound, a reference monitor that prevents authorization transfer across material changes to this heterogeneous closure, and establishes metadata non-authority, closure determinism, version non-inheritance, effect non-amplification, bound-value freshness, and path invariance.

Abstract

Agent Skills combine instructions with files, packages, tools, models, and services, so operational identity can exceed a signed directory. Recursive or lazy dependencies may change while root-level evidence remains valid, and different surfaces may reach the same durable effect. We present ClosureBound, a reference monitor that prevents authorization transfer across material changes to this heterogeneous closure. Its resolver commits typed graph nodes and topology. Each grant binds an exact closure root, effect ceiling, purpose/provenance, validity, and epochs. At durability, it re-resolves closure and state, normalizes the operation into an external-effect IR, and admits it only if a joint witness satisfies every bound. Supported equivalent paths share one ceiling. Assuming complete mediation and discovery, authenticated freshness, sound normalization, cryptographic binding, and authoritative linearization, we establish metadata non-authority, closure determinism, version non-inheritance, effect non-amplification, bound-value freshness, and path invariance. We do not establish program equivalence or remote-service honesty. A provider-free implementation matches 40 frozen lifecycle fixtures; 18 kernel contracts and six mutants cover binding and downgrade cases. Full-profile exploration reaches 84,608 states and 530,752 transitions without a declared invariant violation; six weakened profiles yield witnesses. A lexical audit of 549 public Skills (4,872 unique files) finds that 21 of 526 roots with bundled files name every non-manifest path verbatim, 67 contain links resolving outside their roots, and no root declares a frontmatter dependencies field. These observations motivate conservative closure discovery and define concrete targets for broader runtime, interoperability, efficacy, and production validation.

View source

Similar papers

Preprint Aug 2026

A Contract-Centered Architecture for Scalable and Manageable Agentic Runtimes

A contract-bounded runtime architecture, a source-preserving data substrate, and a falsifiable measurement protocol are contributed, which proposes a cluster-period randomized crossover experiment with a four-state verdict: supported, falsified, conditional-engineering, or inconclusive.

Ya-Xiao Liu, Peng Liu, Yi-Wen Liu et al. · 0 citations
Preprint Sep 2026

Runtime Authorization for Resources Acquired by AI Agents

A provenance-bounded runtime authorization architecture that quarantines acquired outputs, resolves their actual capabilities from authenticated provider evidence through a versioned resolver, and activates them only through a current activation transaction that checks the resolved manifest, provenance, epochs, and a d...

Gen-Liang Zhu, Chu Wang Accentrust, Georgia Institute of Technology et al. · 0 citations
#artificial intelligence Preprint Oct 2026

Runtime Authorization of Self-Generated Subgoals in Long-Horizon Tool-Using AI Agents

Long-horizon tool-using AI agents create subgoals, replan, delegate work, and compose sibling results. Per-tool permission checks cannot establish that a changing goal graph remains within the principal-approved task. We address this authorization gap in a finite structured domain with one principal and one authorizati...

Gen-Liang Zhu, Chu Wang · 0 citations
Preprint Sep 2026

Agent Approval Laundering: Transitive Effects Beyond the Approved Invocation

Coding-agent approval interfaces bind a human decision to a command or tool call, while developer tools execute the transitive workflow that invocation activates. Package installation can run lifecycle hooks and write files; an MCP call can exercise network authority. We call the resulting record-coverage failure appro...

Jin-Qian Zhang, Hao-Jun Xia, Shu-Jiang Wu et al. · 0 citations
Review Sep 2026

When Does Authorization End? Effect Closure at Provider Boundaries

Revocation completion, clean state, or operation success can leave authorized work able to cause an effect the application rejects while the provider stays within its contract. We call the absence of all such paths policy-relative effect closure, or effect closure for short. Thus, a grant is closed when its existing au...

Igor Santos-Grueiro · 2 citations
#artificial intelligence Preprint Sep 2026

ZeroGate: Trust-Preserving Fast Paths for Governed AI Agent Runtimes

A conditional decision-preservation proposition: successful local admission implies that a specified synchronous policy would authorize the same action at the admission point, provided approval is sound, all policy dependencies are represented and current, observations are faithful, and consumption is atomic.

Ze-Xu Wang · 0 citations

Related blog posts

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.