Megadose Built for builders and researchers.

Bounded Agents: Delegation Security for Multi-Agent AI Systems

· HF Daily Papers ·
APC makes agent permissions stateful, limiting what authority can be passed on and what action chains can add up to.

The paper frames prompt injection risk as an authorization problem when an agent already has the power to act. Its Agentic Principal Chain evaluates requests against session history, delegated scope, budgets, and prohibited action combinations outside the model. In tests across 3,154 instances, it cut AgentDojo exfiltration from 75-100% to 0% and blocked all 544 InjecAgent data-stealing cases. The tradeoff reported was lower utility in two AgentDojo settings, down 8.6 and 13.9 points.

HF Daily Papers' note

score 5

Categories: Research