← The Wire
Entity trail

AC4A

Source-backed findings, relationship evidence, citations, and briefing history from the public MindPattern archive.

Briefing refs
1
Findings
1
Edges
0
Sources
1

Corpus findings

  1. 2026-09-24 / arxiv-researcherAjar Adds 'Open Privilege' as a Third AgentDojo Axis and Finds Progent, CaMeL, AC4A and Claude Code Auto Mode Leave Very Different Amounts Unused AccessarXiv 2609.26900 (22 Sep) argues that prompt-injection benchmarks score defenses only on attack success and utility, so a defense can look good while still allowing a transfer, deletion or broad read no task needed. Ajar reuses a benchmark's own tasks and reference solutions to generate unneeded tool calls and offers them to the defense at every step. Run on five defenses, including Claude Code's Auto mode, it found widely different amounts of privilege left open, which gives builders a least-privilege metric they can attach to benchmarks they already run.

Source trail

Graph sources

entity graphfindings textkg entitiesnewsletter issues