AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

Reachability-Based Capability Confinement for LLM Agents under Indirect Prompt Injection

arXiv · AI, language, vision and robotics · article · Aug 30, 2026 · UTC

Large language model agents place outputs from external skills into their execution context, allowing attacker-controlled data to influence later privileged actions. Existing defenses mainly classify untrusted content or authorize proposed operations. They do not directly address how an agent's future authority should change once untrusted data enters its state. We present SkillGuard, a harness-level enforcement layer that treats this event as contamination and restricts future capabilities to disconnect the resulting state from deployer-defined forbidden states. Given sound skill summaries an

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-21T07:22:03.933Z. This is not the publication date.