English

Grimlock: Guarding High-Agency Systems with eBPF and Attested Channels

Cryptography and Security 2026-05-28 v1 Artificial Intelligence

Abstract

Agentic systems increasingly run user-authored orchestration code that invokes tools, spawns subtasks, and delegates work across machines and clouds. Although this high agency is productive, it creates a security problem: identity, authorization, provenance, and delegation are often pushed into application code, where they become difficult to enforce consistently and difficult to audit. We present \emph{Grimlock}, an \emph{Agent Guard} that restores separation of concerns by moving trust enforcement into the sandbox substrate while leaving agent code unchanged. Grimlock uses \emph{eBPF-enforced traffic interception} to ensure that sandbox communication passes through a guard, and combines it with \emph{post-handshake attestation} bound to standard TLS~1.3 channel bindings. After a channel is established, the guard authorizes communication and mints short-lived, channel-bound \emph{scope tokens} that capture least-privilege delegation. At the receiving side, the destination guard re-validates identity, scope, and channel binding, terminates TLS, and releases plaintext to the destination sandbox only after policy checks succeed. kTLS provides an efficient dataplane for protected communication. As a result, Grimlock offers a path toward transparent, auditable, and scope-bound agent-to-agent communication across heterogeneous multi-cloud environments, using commodity Linux primitives and without requiring changes to user-layer orchestration code.

Keywords

Cite

@article{arxiv.2605.27488,
  title  = {Grimlock: Guarding High-Agency Systems with eBPF and Attested Channels},
  author = {Qiancheng Wu and Wenhui Zhang and Gan Fang and Sheng Mao and Biao Gao and David Levitsky and Shawna Murphy Butterworth and Rob Cameron},
  journal= {arXiv preprint arXiv:2605.27488},
  year   = {2026}
}
R2 v1 2026-07-22T07:35:21.440Z