PAPER / ARXIV:2609.08371
Dimitrios Stamatios Bouras, Yihan Dai, Sergey Mechtaev
RESUMO
Coding agents' system-level tools often carry ambient authority, where naming a resource suffices to act on it, which indirect prompt injection exploits via instructions hidden in repository files or tool output. CapScope is a harness-level authorization mechanism that derives a task-wide authority ceiling from trusted input and assigns each agent typed capabilities stored outside the model's context, checked on every tool call. In a repair workflow with 300 runs, the injected effect executed in 33-47/75 runs under baselines versus 3/75 under CapScope, while completing comparable repair rates.
NO MESMO MAPA