arXiv · Software Engineering· Yang Wang·· 8 hr agoSelectedAI score62
Approval Laundering:系统化 AI 编码智能体 Harness 中的批准-执行绑定失效
Approval Laundering: Systematizing Approval--Execution Binding Failures in AI Coding-Agent Harnesses
AI brief
论文提出 Approval Laundering 分类法,揭示 Claude Code、Codex CLI、Cursor 等编码智能体在批准动作后由 harness 静默替换执行动作的六种失效模式:Scope、Argument、Temporal、Tool、Delegation 和 Semantic laundering。
Why it matters
论文系统揭示了 Claude Code 等编码智能体在批准与执行之间的绑定漏洞,并提供可复现的实验与防御原型。
Source: arXiv · Software Engineering · arxiv.org