CARE:用于执行 shell 的语言模型代理的执行前命令验证
CARE: Pre-Execution Command Verification for Shell-Executing LLM Agents
浏览论文内容
中文总结 AI 辅助
研究 LLM 代理执行 shell 命令时的调度风险,提出 CARE 验证器,通过规范化命令、推导证据并结合 LLM 判断,实现命令级调解,降低调度边界风险,平衡良性恢复、误报负担、延迟和危害降低之间的关系。
中文摘要 AI 辅助
大语言模型(LLM)代理越来越多地用于编码和终端自动化,使 shell 命令调度成为高风险的运行时控制点。我们研究了在有限路径上下文下,LLM 代理生成的单个 shell 命令的命令级执行前调解。现有保护措施有限:通用护栏对 shell 结构建模不够详细,始终开启的 LLM 判断成本较高且可变,shell 解析器不能直接防止有害执行。我们提出了 CARE(规范化、归因和解析引擎),这是一个针对单个 shell 命令在执行前的特定于 shell 的、以静态为主的验证器。CARE 将生成的命令规范化为稳定的验证目标,推导语法、命令语义、路径上下文和来源支持的风险模式的确定性证据,仅将不确定的情况提交给 LLM 判断。在平衡的主分割上,CARE 的 F1 达到 85.64%,误报率为 0.91%,平均延迟为 2.32 毫秒。当以其静态执行配置文件部署时,CARE 在 0.34 毫秒时保留 84.99%的 F1,并将 RedCode-gen 上的实际危害降低到 37.33%。总体而言,命令级 shell 调解可以降低 LLM 代理的调度边界风险,同时保留大多数良性工作流程。
英文摘要
Large Language Model (LLM) agents are increasingly used for coding and terminal automation, making shell-command dispatch a high-stakes runtime control point. We study command-level pre-execution mediation for individual shell commands produced by LLM agents under bounded path context. Existing safeguards remain limited: generic guardrails do not model shell structure in sufficient detail, always-on LLM judges are relatively costly and variable, and shell parsers do not directly prevent harmful execution. We present CARE (Canonicalization, Attribution, and Resolution Engine), a shell-specific, static-first verifier for individual shell commands before execution. CARE canonicalizes generated commands into stable verification targets, derives deterministic evidence over syntax, command semantics, path context, and provenance-backed risk patterns, and escalates only underdetermined cases to an LLM judge. This design keeps the common case fast, reproducible, and auditable while reserving neural adjudication for borderline commands. On the balanced main split, CARE reaches 85.64% F1 with a 0.91% false-positive rate at 2.32 ms mean latency. When deployed in its static enforcement profile, CARE retains 84.99% F1 at 0.34 ms and reduces realised harm on RedCode-gen to 37.33%. Across external-generalization tests and controlled Docker-sandbox execution, these profiles expose a practical trade-off between benign recovery, false-positive burden, latency, and harm reduction. Overall, command-level shell mediation can reduce dispatch-boundary risk for LLM agents while preserving most benign workflows.