arxivcs.AI2026-07-31
CAGE: Certified Authorization under Typed-Return Uncertainty for Tool-Using Agents
Blaise Delattre, Cong Wang, Yang Cao
Tool-using LLM agents act on typed tool returns, records pairing provenance and categorical fields with numerical values. Runtime permission gates generally authorize the observed return and action, leaving the decision unprotected against small errors in how the return was bound…