[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-tool-maps-security-risks-hidden-in-llm-agent-code":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},10027,"new-tool-maps-security-risks-hidden-in-llm-agent-code","New Tool Maps Security Risks Hidden in LLM Agent Code","A new static-analysis tool found one confirmed vulnerability by tracing security-sensitive operations across 67 real-world AI agent repositories.","A new analysis tool found a real vulnerability by asking not just what an AI agent's code touches, but how it got there.\n\nResearchers built AgentSecGraph, a static-analysis framework that builds a dependency graph, called a Security-ADG, for every security-sensitive operation in an LLM agent's code - things like command execution, filesystem access, network calls, or browser control. Instead of just flagging that an operation exists, it traces where the inputs came from, whether a trust boundary was crossed, and whether any guardrail caught the risk. The team tested it on AgentSecBench, a corpus of 67 real-world agent repositories spanning 11 ecosystems and 37,542 files, which surfaced 23,866 candidate sensitive operations across 65 repos. The scan recovered dependency evidence for 41.15% of those candidates and guard evidence for 12.88%, finishing in 50.8 minutes.\n\nMost agent security tools treat \"runs a shell command\" as inherently dangerous no matter the context, which generates a lot of noise and buries the bugs that actually matter. By adding trust-boundary and guard context, AgentSecGraph preserved 91.1% of relevant context in held-out test cases, versus 20.0% for a sink-only view and 40.0% for a simpler dependency graph. That gap is what let the researchers isolate one confirmed vulnerability and one pending disclosure out of nearly 24,000 candidates, instead of drowning them in false positives.\n\nAs agents get more hands - executing code, browsing the web, touching your filesystem - knowing an action happened matters less than knowing why it was allowed to.","[\"llm-agents\",\"static-analysis\",\"ai-security\",\"vulnerability-research\"]","2026-10-05T04:00:00.000Z","2026-10-05T19:01:38.729Z","2026-10-05T19:01:44.675Z","published",null,[],"security",[26,27,28,29],"llm-agents","static-analysis","ai-security","vulnerability-research",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2610.03014",0,{"sections":36},[37,41,44,49,54,59,63,68,72,76,81,86,91,96],{"name":38,"slug":39,"count":40,"latest_published_at":18},"AI","ai",6233,{"name":42,"slug":24,"count":43,"latest_published_at":18},"Security",868,{"name":45,"slug":46,"count":47,"latest_published_at":48},"Policy","policy",444,"2026-10-03T15:02:01.000Z",{"name":50,"slug":51,"count":52,"latest_published_at":53},"Deals","deals",323,"2026-10-04T13:00:00.000Z",{"name":55,"slug":56,"count":57,"latest_published_at":58},"Hardware","hardware",204,"2026-10-03T14:50:50.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":18},"Science","science",177,{"name":64,"slug":65,"count":66,"latest_published_at":67},"Consumer Tech","consumer-tech",158,"2026-10-03T03:21:12.000Z",{"name":69,"slug":70,"count":71,"latest_published_at":18},"Dev Tools","dev-tools",97,{"name":73,"slug":74,"count":71,"latest_published_at":75},"Software","software","2026-10-04T10:00:00.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Startups","startups",92,"2026-10-04T14:36:25.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Gaming","gaming",53,"2026-10-02T02:50:39.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"General","general",51,"2026-10-05T02:35:01.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Reviews","reviews",32,"2026-10-02T18:00:00.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"How-To","how-to",7,"2026-10-01T09:00:00.000Z"]