{
  "id": 13625,
  "url": "https://arxiv.org/abs/2607.22024v1",
  "title": "Agent Security Needs Redefinition through a Holistic Framework",
  "summary": "Agent security is widely treated as a question about action content. Defenses ask whether an instruction looks malicious. Benchmarks ask whether an agent performs a harmful sounding action. \\textbf{We argue that agent security is fundamentally a contextual problem, and that the current content based framing systematically misdefines it.} A command to ``delete user data'' might be a routine administrative request or a prompt injection attacking production systems, and the content alone cannot dis",
  "authors": "Vincent Siu, Jingxuan He, Kyle Montgomery, Zhun Wang, Chenguang Wang, Dawn Song",
  "category": "research",
  "topics": "agents-autonomy",
  "orgs": null,
  "regions": null,
  "published_at": "2026-07-24T06:43:09.000Z",
  "fetched_at": "2026-07-27T05:10:06.638Z",
  "source_slug": "arxiv-ethics",
  "source_name": "arXiv",
  "source_homepage": "https://arxiv.org",
  "ethics_ai_record_url": "https://ethics.ai/record/13625",
  "original_url": "https://arxiv.org/abs/2607.22024v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}