SourcesAgent Primitives Reusable Building Blocks for Multi-Agent SystemsarXiv·high signalXBlueskyLinkedInCopy linkIdentifies three recurring computation primitives in multi-agent systems: Review, Voting/Selection, Planning/Execution as composable blocksSourceSource pagearXiv↳ Follow the threadStack layer / Threat pattern37,623 provenance-labeled agent PRs: Codex code was reverted half as often as human code, Devin's 31% more, and Claude Code PRs waited 12.6 hours for first reviewarXiv 2609.17598Stack layer / ContrastEmergence World ran 10 agents per world for 16 days and found no frontier model contained an injected attack — one acted on poisoned memory 46 hours laterarXivPolicy dependency / Stack layerEvery Step Passes Its Guardrail and the Workflow Still Violates Policy, and No Step-Scoped Monitor Can Catch ItarXiv 2609.18820Stack layer / ContrastAffora is a design system for interfaces that computer-use agents can read, with reusable components and executable checks rather than a separate agent-only surfacearXiv 2609.19125Policy dependency / ContrastIn a human-operator cyber range, RL-trained defensive agents beat heuristic policies but performance swings with the adversary and the simulated usersarXivStack layer / Threat patternDeobfuscating npm Packages Before the LLM Sees Them Raises Malicious-Detection Coverage From 69% to 99%arXiv 2609.18862Stack layer / ContrastModel-Checking an Agent's Plan Before Any Tool Runs Rejects Unsafe Plans Without Spending a Single Tool CallarXiv 2609.18674Stack layer / Update threadTwo Tool-Level Defenses Drive Prompt Injection and Memory Poisoning to 0% Attack Success in Many SettingsarXiv 2609.16098