English

Capability Gates Are Not Authorization: Confused-Deputy Failures in LLM Agent Frameworks

Cryptography and Security 2026-06-27 v1 Artificial Intelligence

Abstract

Tool-using LLM agents increasingly read untrusted content while holding side-effecting tools such as payments, email, CRM, and infrastructure APIs, yet common framework defaults still conflate tool exposure with authorization. We audit whether LangChain/LangGraph, LlamaIndex, and the Stripe Agent Toolkit re-authorize each model-emitted call, with concrete argument values, before execution. Across pinned public-source commits, all three provide capability gating by default, but none provides a deterministic fail-closed per-call value authorization gate by default. We introduce ScopeGate, a five-stage PDP/PEP for agent tool calls: scope, authorization, money ceiling, idempotency, and default deny. Evaluation shows the identical unauthorized payout call executes under LangChain's default dispatch (with a companion LlamaIndex PoC) but is denied by ScopeGate; the tested control reports 0/48 static bypasses, 0/29 unauthorized attempts (40-iteration adaptive run), 0/10 benign false-denies, and Latam-GPT payment-agent containment at 10/10. ASR denotes attempted unauthorized action, containment is not a cure, deployment-tier claims are inference over measured model classes, and no CVE is asserted.

Cite

@article{arxiv.2606.28679,
  title  = {Capability Gates Are Not Authorization: Confused-Deputy Failures in LLM Agent Frameworks},
  author = {David Mellafe Zuvic},
  journal= {arXiv preprint arXiv:2606.28679},
  year   = {2026}
}

Comments

7 pages, 3 figures, 3 tables. Artifact: https://github.com/raceksd-source/scopegate-runtime (run_proof.sh)

R2 v1 2026-07-22T20:12:12.228Z