Abstract
A tool-using model can follow a malicious instruction even when its credentials are valid. We study whether task-scoped authorization contains the resulting tool execution. Our paired-replay testbed samples a model request once and submits the same action, resource, and arguments to broad bearer, scoped JWT, sender-constrained, and Open Policy Agent conditions. The frozen main experiment uses 128 scenarios across four tool domains and five local model configurations. Among valid attacked post-exposure decisions, broad-bearer harmful execution ranges from 8.9% to 37.8% across models; all three scoped conditions record zero. The policy changes execution, not the frozen model decision. These results support containment of the tested cross-action and cross-resource consequences under researcher-supplied task authority, not prevention of prompt injection. A bounded six-task AgentDojo extension preserves native scoring and records 11/24 injected broad-policy attack flags versus 0/24 scoped flags, with utility of 5/24 and 6/24. Low exposure, invalid decisions, and purposive task selection limit that comparison. The primary experiment measures safe continuation rather than final-answer correctness. An empirical-bank fresh-sampling comparison finds no estimation advantage from pairing when scoped outcomes are constant zero. The contribution is a controlled measurement of compromise, enforcement, and continuation, with explicit limits on what each observation establishes.
Keywords
Subject
Publication details
- Journal
- Not available
- Open access
- Green open access
Cite this article
APA 7
Hagverdiyev, T. (2026). Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay. https://omanscience.com/en/articles/compromise-is-not-consequence-evaluating-task-scoped-authorization-in-llm-agents-with-paired-replay
MLA 9
Hagverdiyev, Tural. "Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay." https://omanscience.com/en/articles/compromise-is-not-consequence-evaluating-task-scoped-authorization-in-llm-agents-with-paired-replay.
Chicago (author–date)
Hagverdiyev, Tural. 2026. "Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay." https://omanscience.com/en/articles/compromise-is-not-consequence-evaluating-task-scoped-authorization-in-llm-agents-with-paired-replay.
Harvard
Hagverdiyev, T. (2026) 'Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay', Available at: https://omanscience.com/en/articles/compromise-is-not-consequence-evaluating-task-scoped-authorization-in-llm-agents-with-paired-replay.
Vancouver
Hagverdiyev T. Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay. https://omanscience.com/en/articles/compromise-is-not-consequence-evaluating-task-scoped-authorization-in-llm-agents-with-paired-replay
IEEE
T. Hagverdiyev, "Compromise Is Not Consequence: Evaluating Task-Scoped Authorization in LLM Agents with Paired Replay," https://omanscience.com/en/articles/compromise-is-not-consequence-evaluating-task-scoped-authorization-in-llm-agents-with-paired-replay.