{"data":{"id":"942dcf69-4cb4-4ced-a679-45db3c0aba85","title":"Formal Runtime Verification for Tool-Using LLM Agents: An Offline Same-Benchmark Study on AgentDojo and STAC","summary":"This study evaluates metric first-order temporal logic (MFOTL) as a declarative guardrail for tool-using LLM agents by replaying recorded trajectories from AgentDojo, STAC and R-Judge through the unmodified MonPoly monitor, offline and without running an agent. Five generic obligations flag 71.8% of STAC attack chains and 70.1% of successful AgentDojo attacks, but also fire on 29.3% of benign runs, an imprecision the authors attribute to the corpora, which rarely record approvals and never record timestamps. A planted line evades a naive provenance check in 94-99% of the runs it would otherwise flag, and binding provenance to the lookup that produced it closes this evasion at no cost in detection or benign firing.","solution":"Binding provenance to the lookup that produced it closes this evasion at no cost in detection or benign firing. The authors also propose a twelve-field enforcement-ready trace schema.","labels":["security","research"],"sourceUrl":"https://arxiv.org/abs/2610.09793v1","publishedAt":"2026-10-07T10:08:46.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":["prompt_injection","jailbreak"],"issueType":"research","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["AgentDojo","STAC","R-Judge","MonPoly"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-07T10:08:46.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","safety"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":"preprint","atlasIds":null}}