arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过工具工程分发安全控制

Distributing Security Controls Through Harness Engineering

William Robert Gore

arXiv 2607.25890首次发表:更新:

AI 中文总结

研究商业AI编码代理安全控制分发问题,通过分阶段测试方法,利用SHarD工具在多种代理配置上测试,证明三类安全控制可通过单个命令嵌入分发,效果与直接安装商业代理相同,还提出相关框架特征及后续研究问题。

AI 中文摘要

人工智能编码代理正以前所未有的速度被采用,但安全和风险问题仍是跨组织扩展代理人工智能的主要障碍。现有编码代理的安全控制未系统地分发给工程团队,供应商原生解决方案引入的生态系统依赖性可能不适合每个部署环境。本文研究了现成的安全控制是否可在商业人工智能编码代理上实施,并通过自定义代理工具扩展到分布式用户群。应用分阶段测试方法,使用源自OWASP针对代理应用的前10大漏洞的23个测试套件,对四种代理配置进行测试。基于Pi代理工具构建的可分发工具SHarD表明,三类安全控制——操作系统沙盒、技能扫描和工具限制——可通过单个安装命令嵌入和分发,同时保持与直接安装在商业代理上相同的效果。SHarD调整后的分数达到100%,与配置最佳的安全商业代理匹配,且在任何测试类别中均无回归。值得注意的观察结果包括模型不确定性产生不一致的安全结果,以及自主代理行为可跨越系统边界,而操作系统沙盒可直接缓解这种情况。提出了控制工具适用性框架的初步特征,并确定了第三个研究问题以供未来研究。

英文摘要

AI coding agents are being adopted at historic speed, yet security and risk concerns remain the primary barrier to scaling agentic AI across organizations. Existing security controls for coding agents are not systematically distributed to engineering teams, and vendor-native solutions introduce ecosystem dependencies that may not suit every deployment context. This paper investigates whether off-the-shelf security controls can be implemented on commercial AI coding agents and scaled to a distributed user base via a custom agent harness. A phased testing methodology was applied across four agent configurations --- two commercial agents with and without controls, a baseline harness, and a security-hardened harness --- using a 23-test suite derived from the OWASP Top 10 for Agentic Applications. SHarD (Secure Harness Distribution), a distributable harness built on the Pi agent harness, demonstrated that three categories of security controls --- OS sandboxing, skill scanning, and tool restriction --- can be embedded and distributed via a single install command while retaining equivalent efficacy to direct installation on commercial agents. SHarD achieved an adjusted score of 100\%, matching the best securely configured commercial agent, with no regression across any test category. Notable observations include evidence that model non-determinism produces inconsistent security outcomes and that autonomous agent behavior can cross system boundaries in ways that OS sandboxing directly mitigates. Initial characteristics toward a control harness fitness framework are proposed, and a third research question is identified for future investigation.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑