CapSeal: Capability-Sealed Secret Mediation for Secure Agent Execution

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jin, Shutong, Guo, Ruiyi, Cheung, Ray C. C.
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910142998511616
author Jin, Shutong
Guo, Ruiyi
Cheung, Ray C. C.
author_facet Jin, Shutong
Guo, Ruiyi
Cheung, Ray C. C.
contents Modern AI agents routinely depend on secrets such as API keys and SSH credentials, yet the dominant deployment model still exposes those secrets directly to the agent process through environment variables, local files, or forwarding sockets. This design fails against prompt injection, tool misuse, and model-controlled exfiltration because the agent can both use and reveal the same bearer credential. We present CapSeal, a capability-sealed secret mediation architecture that replaces direct secret access with constrained invocations through a local trusted broker. CapSeal combines capability issuance, schema-constrained HTTP execution, broker-executed SSH actions, anti-replay session binding, policy evaluation, and tamper-evident audit trails. We describe a Rust prototype integrated with an MCP-facing adapter, formulate conditional security goals for non-disclosure, constrained use, replay resistance, and auditability, and define an evaluation plan spanning prompt injection, tool misuse, and SSH abuse. The resulting system reframes secret handling for agentic systems from handing the model a key to granting the model a narrowly scoped, non-exportable action capability.
format Preprint
id arxiv_https___arxiv_org_abs_2604_16762
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle CapSeal: Capability-Sealed Secret Mediation for Secure Agent Execution
Jin, Shutong
Guo, Ruiyi
Cheung, Ray C. C.
Cryptography and Security
Artificial Intelligence
Modern AI agents routinely depend on secrets such as API keys and SSH credentials, yet the dominant deployment model still exposes those secrets directly to the agent process through environment variables, local files, or forwarding sockets. This design fails against prompt injection, tool misuse, and model-controlled exfiltration because the agent can both use and reveal the same bearer credential. We present CapSeal, a capability-sealed secret mediation architecture that replaces direct secret access with constrained invocations through a local trusted broker. CapSeal combines capability issuance, schema-constrained HTTP execution, broker-executed SSH actions, anti-replay session binding, policy evaluation, and tamper-evident audit trails. We describe a Rust prototype integrated with an MCP-facing adapter, formulate conditional security goals for non-disclosure, constrained use, replay resistance, and auditability, and define an evaluation plan spanning prompt injection, tool misuse, and SSH abuse. The resulting system reframes secret handling for agentic systems from handing the model a key to granting the model a narrowly scoped, non-exportable action capability.
title CapSeal: Capability-Sealed Secret Mediation for Secure Agent Execution
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2604.16762