acceptodds
Under review as a conference paper at ICLR 2027

RuntimeTickets: Source-Grounded Security Obligations for Agent Skills

Abstract

Third-party Agent Skills extend what an autonomous agent can do, but a malicious Skill can hide data exposure and output manipulation inside a legitimate workflow. Reading a Skill's description or granting tool permissions cannot tell whether its execution meets the user's security requirements. We introduce RuntimeTickets, a protocol that enforces and audits these requirements while a Skill runs. We derive a risk model from released malicious-Skill datasets and use it to build adversarial cases with matched benign counterparts. From the task's delivery contract, a language model proposes task-specific security obligations that cite the Skill's source lines they answer, and host approval admits them only as a narrowing of the host's grant. A runtime gate checks the recipient, object and amount of every outbound send before allowing it, and trusted monitors record effects within their observation scope. Tickets link these checks and observations to the approved obligations of each Skill run, and a deterministic decoder then reconstructs what was approved, attempted, observed and verified, keeping violations apart from missing evidence. Enforcement and decoding involve no language model. We evaluate RuntimeTickets at the network egress boundary of two unmodified agent frameworks, measuring harmful effects, unnecessary blocking and task completion, against production Skill scanners and against the same gate holding only the host's grant. Under RuntimeTickets no injected send took effect and no benign run was blocked, while the same gate holding only the host's grant forwarded injected sends that reused the task's recipient, and the scanners either admitted malicious Skills or withheld up to 53.3% of benign ones. Ablations remove the per-task ticket and the effect evidence. RuntimeTickets ties approved requirements to verifiable execution evidence, a common foundation for safer and auditable deployment of third-party Skills.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.