When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lu, Di, Liao, Yongzhi, Mu, Xutong, Zheng, Lele, Cheng, Ke, Dong, Xuewen, Shen, Yulong, Ma, Jianfeng
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918401747714048
author Lu, Di
Liao, Yongzhi
Mu, Xutong
Zheng, Lele
Cheng, Ke
Dong, Xuewen
Shen, Yulong
Ma, Jianfeng
author_facet Lu, Di
Liao, Yongzhi
Mu, Xutong
Zheng, Lele
Cheng, Ke
Dong, Xuewen
Shen, Yulong
Ma, Jianfeng
contents Host-acting agents promise a convenient interaction model in which users specify goals and the system determines how to realize them. We argue that this convenience introduces a distinct security problem: semantic under-specification in goal specification. User instructions are typically goal-oriented, yet they often leave process constraints, safety boundaries, persistence, and exposure insufficiently specified. As a result, the agent must complete missing execution semantics before acting, and this completion can produce risky host-side plans even when the user-stated goal is benign. In this paper, we develop a semantic threat model, present a taxonomy of semantic-induced risky completion patterns, and study the phenomenon through an OpenClaw-centered case study and execution-trace analysis. We further derive defense design principles for making execution boundaries explicit and constraining risky completion. These findings suggest that securing host-acting agents requires governing not only which actions are allowed at execution time, but also how goal-only instructions are translated into executable plans.
format Preprint
id arxiv_https___arxiv_org_abs_2603_21231
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents
Lu, Di
Liao, Yongzhi
Mu, Xutong
Zheng, Lele
Cheng, Ke
Dong, Xuewen
Shen, Yulong
Ma, Jianfeng
Cryptography and Security
Artificial Intelligence
Host-acting agents promise a convenient interaction model in which users specify goals and the system determines how to realize them. We argue that this convenience introduces a distinct security problem: semantic under-specification in goal specification. User instructions are typically goal-oriented, yet they often leave process constraints, safety boundaries, persistence, and exposure insufficiently specified. As a result, the agent must complete missing execution semantics before acting, and this completion can produce risky host-side plans even when the user-stated goal is benign. In this paper, we develop a semantic threat model, present a taxonomy of semantic-induced risky completion patterns, and study the phenomenon through an OpenClaw-centered case study and execution-trace analysis. We further derive defense design principles for making execution boundaries explicit and constraining risky completion. These findings suggest that securing host-acting agents requires governing not only which actions are allowed at execution time, but also how goal-only instructions are translated into executable plans.
title When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2603.21231