arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

渐进式技能发现作为工具使用LLM代理的访问控制:通过角色限定能力交付实现结构性治理

Progressive Skill Discovery as Access Control for Tool-Using LLM Agents: Structural Governance through Role-Scoped Capability Delivery

Michael Stettler, Benjamin Girardet, Jonas Canton, Nicolas Corod

arXiv 2609.28693首次发表:更新:

发表机构

Skilder(Skilder)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对LLM代理访问企业工具集时的安全与治理问题,提出skilder框架,将能力打包为角色并通过MCP服务器确定性强制治理边界,在保持灵活性的同时实现硬性系统级访问控制。

AI 中文摘要

大型语言模型(LLM)代理在面临庞大的企业工具集时难以安全扩展。为代理提供对所有内部工具的访问会导致上下文窗口过大、工具选择性能下降以及严重的治理漏洞——因为纯粹在提示中定义的系统策略仍然是概率性建议,而非硬性约束。现有的缓解措施,如多代理领域委派,分散了审计日志,并且无法保证跨会话的策略合规性。我们提出了skilder,一个将能力打包为角色的框架:技能、工具和指令的捆绑,以及约束它们的限制。代理从一个最小的角色目录开始,学习任务所需的角色,并通过单个MCP服务器接收每个角色的技能、指令和工具。由于工具仅在已学习的技能内到达代理,同一服务器以确定性方式强制执行所学内容的范围。我们在13个任务上使用六个模型(每个模型运行10次)将skilder与扁平上下文工具选择和多代理编排进行了评估。我们的结果表明,当模型完成发现并发出受治理的调用时,skilder模拟的授权层强制执行了治理边界:没有未授权的工具调用或参数违规(例如,超出支出限额)被执行。总体任务通过率也反映了每个模型是否遵循了发现协议并满足了响应质量检查;这些失误并非授权失败。此外,通过允许代理在任务中途动态获取跨角色能力,skilder在提供硬性系统级强制执行的同时保持了问题解决的灵活性。

英文摘要

Large Language Model (LLM) agents struggle to scale safely when exposed to vast enterprise toolsets. Providing an agent with access to every internal tool leads to oversized context windows, degraded tool selection, and severe governance vulnerabilities - as system policies defined purely in prompts remain probabilistic advice rather than hard constraints. Existing mitigations, such as multi-agent domain delegation, decentralize audit logs and fail to guarantee policy compliance across sessions. We introduce skilder, a framework that packages capabilities into roles: bundles of skills, tools, and instructions, together with the limits that bound them. An agent begins with a minimal role catalog, learns the roles a task requires, and receives each role's skills, instructions, and tools through a single MCP server. Because tools reach the agent only inside learned skills, the same server enforces the scope of what was learned deterministically. We evaluate skilder against flat-context tool selection and multi-agent orchestration across 13 tasks using six models (10 runs each). Our results show that, when models completed discovery and issued a governed call, the skilder simulated authorization layer enforced governance boundaries: no unauthorized tool call or parameter violation (e.g., a spending-limit breach) executed. Aggregate task pass rates also reflect whether each model followed the discovery protocol and satisfied response-quality checks; those misses are not authorization failures. Furthermore, by allowing agents to dynamically acquire cross-role capabilities mid-task, skilder preserves problem-solving flexibility while providing hard system-level enforcement.

CommentsWhite paper, 30 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑