When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866918401747714048 |
|---|---|
| author | Lu, Di Liao, Yongzhi Mu, Xutong Zheng, Lele Cheng, Ke Dong, Xuewen Shen, Yulong Ma, Jianfeng |
| author_facet | Lu, Di Liao, Yongzhi Mu, Xutong Zheng, Lele Cheng, Ke Dong, Xuewen Shen, Yulong Ma, Jianfeng |
| contents | Host-acting agents promise a convenient interaction model in which users specify goals and the system determines how to realize them. We argue that this convenience introduces a distinct security problem: semantic under-specification in goal specification. User instructions are typically goal-oriented, yet they often leave process constraints, safety boundaries, persistence, and exposure insufficiently specified. As a result, the agent must complete missing execution semantics before acting, and this completion can produce risky host-side plans even when the user-stated goal is benign. In this paper, we develop a semantic threat model, present a taxonomy of semantic-induced risky completion patterns, and study the phenomenon through an OpenClaw-centered case study and execution-trace analysis. We further derive defense design principles for making execution boundaries explicit and constraining risky completion. These findings suggest that securing host-acting agents requires governing not only which actions are allowed at execution time, but also how goal-only instructions are translated into executable plans. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2603_21231 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents Lu, Di Liao, Yongzhi Mu, Xutong Zheng, Lele Cheng, Ke Dong, Xuewen Shen, Yulong Ma, Jianfeng Cryptography and Security Artificial Intelligence Host-acting agents promise a convenient interaction model in which users specify goals and the system determines how to realize them. We argue that this convenience introduces a distinct security problem: semantic under-specification in goal specification. User instructions are typically goal-oriented, yet they often leave process constraints, safety boundaries, persistence, and exposure insufficiently specified. As a result, the agent must complete missing execution semantics before acting, and this completion can produce risky host-side plans even when the user-stated goal is benign. In this paper, we develop a semantic threat model, present a taxonomy of semantic-induced risky completion patterns, and study the phenomenon through an OpenClaw-centered case study and execution-trace analysis. We further derive defense design principles for making execution boundaries explicit and constraining risky completion. These findings suggest that securing host-acting agents requires governing not only which actions are allowed at execution time, but also how goal-only instructions are translated into executable plans. |
| title | When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2603.21231 |