acceptodds
Under review as a conference paper at ICLR 2027

Execution Authority under Interface Drift: Verified Selective Migration of Tool Calls

Abstract

A tool-using agent can construct a valid rewrite of an action without evidence that the rewrite remains authorized to execute. This gap arises when an API or Model Context Protocol (MCP) contract changes after a call has been issued: a revised call may remain schema-valid even though its operation or argument roles are no longer uniquely determined. We formulate migration of an already-issued call as selective execution. ContractPatch executes a migrated call only when an independent verifier can reconstruct a unique correspondence from the old contract, new contract, and issued call; otherwise, it abstains. Unlike schema validation or checks against invented values, this certificate establishes why values retain their roles across versions. The verifier recomputes the evidence rather than trusting the proposed rewrite and requires no language-model tokens. Across 105 real-schema cases, seven language models recover many supported migrations yet still produce target-valid unsafe executions; a generic verifier reduces but does not remove these failures without sacrificing coverage. ContractPatch safely migrates all 60 adaptable calls, correctly refuses all 45 unsupported calls, and produces zero observed unsafe executions. The frozen method preserves zero observed unsafe execution across held-out REST and MCP settings, an untouched Notion release pair, 20,000 fuzz trials, and 28 end-to-end executions. On Notion, it safely automates 73.3% of adaptable calls and refuses cases whose correspondence the contracts do not establish. The results separate learned competence to propose a plausible action from the evidence required to authorize its execution.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.