Policy dependency / Stack layer
RIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persisting
arXiv 2609.12127
Policy dependency / Threat pattern
A Fine-Tuned RoBERTa-Large Permission Gate Matches Claude Haiku 4.5 at Deciding What an Agent May Touch
arXiv 2609.15422
Stack layer / Threat pattern
Abnormal AI runs Bedrock AgentCore Code Interpreter as an ephemeral scratch pad at billion-message scale
AWS Machine Learning Blog
Stack layer / Threat pattern
Agent Frameworks Detect Dangerous Plan Steps and Then Execute Them Anyway; Fewer Than 20 Lines Closes the Gap
arXiv 2609.15293
Stack layer / Threat pattern
787,562 Function Pairs Show AI Code Is Half the Size of Human Code With Different Defect Classes, Not Fewer
arXiv 2609.12708
Policy dependency / Stack layer
Pattern: four coding-agent CLIs shipped sandbox or trust work in the same week
GitHub
Policy dependency / Stack layer
CROSS-CATEGORY: Salesforce, Zendesk and Workable All Shipped Named Agent Portfolios on Sept 14, Each Metered in a Different Unit
Zendesk newsroom, Salesforce press release and Workable via GlobeNewswire (three independent Sept 14 announcements)
Stack layer / Contrast
Pre-registered ablation shows removing an LLM verifier stage from an offensive-security agent shifts median reported findings from 0 to 2 per run
arXiv