Stack layer / Threat pattern
Prompt Injection Hidden in Log Entries Makes SOC LLMs Call Compromised Traces Benign — but Their Own Explanations Leak the Attack
arXiv 2607.24174
Policy dependency / Threat pattern
ContainmentBench: Taint-Only Prompt-Injection Enforcement Completes Just 16.4% of Authorized Workflows While a Trusted Ledger Reaches 85.7%
arXiv 2607.23999
Policy dependency / Stack layer
Your CLAUDE.md doesn't actually constrain the agent: best model passes only 36.2% of long-horizon policy-compliance tasks
arXiv 2607.25398
Policy dependency / Stack layer
Stop authorizing tool calls off the model's own rationale — convert it to typed claims and check them against server-held facts
arXiv 2607.25364
Stack layer / Threat pattern
SkillGate Screens Agent Skill Files Before Install: F1=0.817 at 1.13% FPR While Cutting LLM Input Tokens 77%
arXiv 2607.25619
Stack layer / Contrast
Kontrast Audits Text, Tables, and Knowledge Graphs Against Each Other to Find Where Wikipedia and Wikidata Disagree
arXiv 2607.25959
Policy dependency / Stack layer
Carve regression tests from recorded production traffic plus a natural-language scenario — 85.4% adoption over a 9-month deployment
arXiv 2607.24000
Stack layer / Update thread
Seven Open-Weight Models Fail Team Cooperation the Same Way: They Pay the Query Cost Without Transmitting the Information
arXiv 2607.23982