Fetching from the wire…
Research2026-09-24 · source-backed
Calls that return success while delivering incomplete data or partial functionality, with no signal to the agent or the user. Mostly missing fields and inconsistent search, filter or ranking behavior, 51 in the API layer and 25 in the wrapper layer (arXiv). Wrapper-level schema checks on tool output would catch a large share. Almost nobody validates tool responses, because a 200 feels like an answer.
Each link below shares sources, entities, or timing with this story.
Between September 14 and September 15, NVD published seven entries hitting MCP infrastructure. I read all of them expecting to find something clever. There's nothing clever in any of them. CVE-2026-57124, 9.8, published September 14. PraisonAI's default UI exposes POST /api/mc...
The failure mode is a well-formed but policy-forbidden call, cancel a booking, change a passenger count, that neither the tool nor the agent's self-report flags (arXiv). In the airline domain tested, the fix wasn't more reasoning. It was cheap, read-only deterministic gates th...
arXiv 2609.18674 extends CaMeL with a static verification layer. CaMeLoT translates a generated plan into a finite-state transition system labeled with tool calls, provenance and taint, then checks it against CTL policies with nuXmv before execution starts. Unsafe plans get re...
arXiv 2609.17698 read documentation, source, config and tests across 157 LLM-agent projects with 100+ stars. Coverage fragments in a specific, checkable way: a guard on the direct tool call and nothing on the shell that reaches the same effect, tests that rarely exercise bound...
CapScope derives a task-wide authority ceiling from trusted input before any repository content or tool output is read, then gives each sub-agent typed capabilities stored outside the model's context. Every tool call checks against the issuing agent's capabilities, so one sub-...
arXiv 2608.03609 formalizes agentic systems over relational data as Stateful Tool-Enabled Agentic Deployments and proves verification against First-Order CTL specs is undecidable. Under a finite-domain restriction it becomes PSPACE-complete, but only if renaming opaque identif...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.