{
  "id": 17347,
  "url": "https://arxiv.org/abs/2608.06130v1",
  "title": "Hardware Keystores for AI Agent Signing Workflows: A Zero-Trust MCP Enforcement Architecture",
  "summary": "AI agents performing cryptographic operations (signing Git commits, authenticating API calls, issuing certificates) currently store private keys in software-accessible locations: plaintext files, environment variables, or container memory. Any process with sufficient read privileges can extract the raw key material. A recent production incident demonstrated the practical severity: private keys were exfiltrated from a widely deployed framework via email injection in under five minutes. We aim to",
  "authors": "Leo Sambrook, Sampo Sovio",
  "category": "research",
  "topics": "agents-autonomy,environment",
  "orgs": null,
  "regions": null,
  "published_at": "2026-08-06T15:04:26.000Z",
  "fetched_at": "2026-08-07T05:10:58.501Z",
  "source_slug": "x-arxiv-cs-ai",
  "source_name": "arXiv cs.AI",
  "source_homepage": "https://arxiv.org/list/cs.AI/recent",
  "ethics_ai_record_url": "https://ethics.ai/record/17347",
  "original_url": "https://arxiv.org/abs/2608.06130v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}