Skills
An agent's own memory writer invented permissions it never had for up to 50% of unauthorized requests, and executors acted on them 98.6% of the time
EAL-Bench (arXiv 2609.01836, 2026-09-01) names a failure mode with no external attacker: when persistent memory summarizes an evolving authorization state, the compression can wash away provenance and leave a stored permission that the underlying event history never granted. Across five LLMs as memory writers and two as executors in procurement, cybersecurity, and finance, incremental memory updates created false authority for up to 50.2% of unauthorized requests, and once present, executors acted on it in 98.6% of trials. Two safeguards help, requiring stored permissions to trace to valid source events and bounded event sourcing for permission changes, but both reject more legitimate actions too.
↳ Follow the thread