acceptodds
Under review as a conference paper at ICLR 2027

AuthBench: Can Coding Agents Infer Least-Privilege File Permissions?

Abstract

Deploying autonomous coding agents in real-world environments faces an all-or-nothing dilemma: granting unrestricted shell and file access exposes systems to credential theft and prompt injection, while coarse hardcoded limits frequently break task execution. To resolve this tension, agents must autonomously determine their own permissions prior to execution. We formalize this challenge as permission-boundary inference, where a model infers a task-scoped read/write/execute policy through read-only inspection of the environment before acting. To evaluate this capability, we introduce AuthBench, comprising 120 realistic terminal tasks across 10 domains with human-reviewed, execution-calibrated ground truth and executable validators for utility and attack outcomes. AuthBench reveals that authorization is not a simple calibration problem: frontier models simultaneously omit permissions required by the execution chain while granting unused or sensitive accesses. Crucially, scaling test-time reasoning does not resolve this mismatch; instead, it reinforces model-specific authorization attractors, trapping models in either broad-but-exposed or tight-but-brittle regimes. We identify that the root bottleneck lies in one-pass policy generation, which forces the model to concurrently discover all necessary dependencies and prune all unnecessary accesses. We therefore propose Sufficiency-Tightness (S-T) Decomposition, separating policy generation into coverage-oriented forward simulation followed by an audit for grounding and sensitivity. Across evaluated models, S-T Decomposition consistently reduces attack success rates (by up to 15.8 percentage points) and cuts sensitive-file exposure by more than half, while boosting sensitive-task success rates by up to 15.9% on tightness-biased models.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.