Research
Ajar Adds 'Open Privilege' as a Third AgentDojo Axis and Finds Progent, CaMeL, AC4A and Claude Code Auto Mode Leave Very Different Amounts Unused Access
arXiv 2609.26900 (22 Sep) argues that prompt-injection benchmarks score defenses only on attack success and utility, so a defense can look good while still allowing a transfer, deletion or broad read no task needed. Ajar reuses a benchmark's own tasks and reference solutions to generate unneeded tool calls and offers them to the defense at every step. Run on five defenses, including Claude Code's Auto mode, it found widely different amounts of privilege left open, which gives builders a least-privilege metric they can attach to benchmarks they already run.
Source
↳ Follow the thread