Pith. sign in

REVIEW 3 major objections 4 minor 32 references

The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents

T0 review · 3 major / 4 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read This position paper proposes the agentic posture vulnerability (APV), a durable, task-conditioned vulnerability record that links the changing runtime manifestations of an AI coding agent to the invariant posture that makes them reachable.

desk verdict A well-scoped position paper that names a real gap and is honest about what it does not prove; the operational premise needs a pilot, not a theorem. read the letter →

arxiv 2608.05884 v1 pith:ZZJ4WFFS submitted 2026-08-06 cs.CR cs.CL

classification cs.CRcs.CL
keywords AIcodingagentsagenticposturevulnerabilitymanagementexcessiveagencyauthorizationleastprivilegesecurityruntimegovernance
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper argues that security teams should manage persistent weaknesses in deployed AI coding agents as a durable, task-conditioned object called an agentic posture vulnerability (APV). An APV exists when a persistent composition of agent settings, credentials, connectors, and reach can produce a consequential effect that exceeds the task's mandate, bypasses a required gate, or cannot be attributed and reconstructed well enough to govern it. The central move is to treat the invariant posture as the unit of work, so that one record can own, deduplicate, remediate, accept, or close an exposure that would otherwise surface over and over as different alerts. The paper provides a four-condition operational definition, six recurring patterns, a lifecycle, a minimum record, and a testable research agenda. A sympathetic reader would care because current vulnerability management has no natural home for a weakness that spans components and outlives any single event.

What carries the argument

The central object is the APV record itself, held together by the distinction between the invariant posture and its variable runtime manifestations. The load-bearing identity is the task-conditioned linkage: one durable record binds configuration snapshots, evidence of reachable consequential effects, mandate basis (supported, contradicted, or unknown), evidence gaps, scope, owner, remediation, and closure evidence, and stays open until the authority or control path changes. The paper also supplies threshold machinery: the four-condition definition, the persistence and expected-task-class criteria, and the materiality test that keeps generic logging deficiencies and non-consequential control weaknesses outside the boundary.

What would settle it

A longitudinal intervention study in which an APV workflow shows no higher owner-assignment rate, no more verified closures, no lower recurrence, and no shorter median exposure duration than alert-only handling; or a calibration study in which expert raters cannot agree on whether real-world agent configurations satisfy the four APV conditions. Either outcome would collapse the object into an ordinary control deficiency.

Watch

Extended reading notes

Core claim

The paper claims that a persistent, task-conditioned exposure in AI coding agents can be managed as a single vulnerability object, the agentic posture vulnerability. A posture is an APV when all four conditions hold: the enabling composition persists beyond a single event or trajectory; it applies to at least one approved or routinely expected task class; the agent can reach a consequential effect; and that effect exceeds the mandate, lacks required pre-effect mediation, or cannot be attributed and reconstructed to the level materially required to govern the authority. The object is not a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses. One posture can produce many different runtime manifestations across tasks, and the APV links those manifestations to the invariant posture, remaining open until authority is narrowed, a missing control is added, risk is accepted, or closure is verified.

Load-bearing premise

The APV definition can only be applied if security teams can reliably assemble a mandate record and assess effective authority and consequential reach well enough to classify a posture; the paper itself notes that mandate evidence can be incomplete or contested and that effective authority is hard to enumerate when agents discover tools, invoke nested services, delegate to sub-agents, or change the environment during execution.

Editorial extensions

If this is right

  • Security teams can open a vulnerability record for a posture before any harmful event occurs, and keep it open until authority is narrowed, a control is added, risk is accepted, or closure is verified.
  • Alert rules no longer need to capture every manifestation; detections and incidents become evidence of an APV, and the APV record becomes the unit of ownership, deduplication, and remediation.
  • Closure becomes verifiable: it requires evidence across the affected scope that the consequential effect is no longer reachable, is narrower, is reliably mediated, or is covered by an explicit risk decision — not the disappearance of one command pattern.
  • The framework produces testable hypotheses: posture-based prioritization should reduce ranking inversions against expert adjudication, a fixed posture should yield more distinct consequential action classes across task families than within one task class, and an APV workflow should beat alert-only handling on owner-assignment rate, verified closures, recurrence, and median exposure duration.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If APVs gain adoption, the boundary of the CVE model becomes explicit: patchable product defects keep a patch lifecycle, while composed postures need an identifier and lifecycle of their own, possibly pushing standards bodies to define a complementary posture-level scheme.
  • The supported/contradicted/unknown mandate tri-state suggests a practical audit pattern: organizations can precompute 'unknown' zones where the agent's mandate is ambiguous and require human review before consequential actions, turning the APV definition into a design principle for approval gates.
  • The four-condition threshold could be operationalized as an inter-rater reliability study; if security practitioners cannot agree on mandate and effective authority, the abstraction would remain a taxonomical exercise rather than a working management object.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. This position paper proposes a new vulnerability-management abstraction for AI coding agents, called the agentic posture vulnerability (APV). An APV is defined as a persistent, task-conditioned posture in which a consequential effect is reachable and either exceeds the mandate, lacks required pre-effect mediation, or cannot be attributed and reconstructed to the level needed to govern the authority. The paper distinguishes APVs from CVE-addressable product defects, OWASP Excessive Agency, Agent Baseline control outcomes, and the runtime authorization–execution gap. It presents a motivating field vignette (explicitly not a prevalence study), a four-condition operational definition, six recurring APV patterns, a vulnerability lifecycle, a minimum record, a control-and-closure matrix, tooling implications, and a testable research agenda. The authors state that APV is not a new root-cause class of risk but an operationalization of existing excessive-agency, authorization, and control-composition weaknesses.

Significance. If the APV abstraction works in practice, it gives security teams a durable, named, owned object for managing composed agent-control exposures that persist across sessions and manifest differently across tasks. This is a genuine gap: current practice treats detections and incidents as the unit of work, while the underlying posture remains unmanaged. The paper's strengths include its explicit evidence-and-method note (§3.1), its anchoring to external frameworks (OWASP, Agent Baseline, AEG), its falsifiable research agenda (§9), and its unusually candid discussion of limitations (§10). The contribution is conceptual and operational rather than empirical, which is appropriate for a position paper. The main open risk is whether the construct is decidable enough for real security teams to classify, remediate, and close APVs; this risk is acknowledged by the authors but not yet resolved.

major comments (3)
  1. [§4, Condition 3; §6, Step 5; §10]
  2. [§1; §4, Condition 1; §10]
  3. [§4, Condition 4; §6; §10]
minor comments (4)
  1. [§4, Condition 2] The phrase “approved or routinely expected class of task” is left undefined. It should be clarified whether “routinely expected” is determined by telemetry, by policy, by the vendor’s documentation, or by some combination, and who makes that determination.
  2. [§9, Hypothesis 1] The hypothesis “fewer pairwise ranking inversions” needs a specified baseline model and a description of how the expert-adjudicated risk rankings are created. Without these details, the hypothesis is not yet measurable.
  3. [§7, Table 4] The management functions “Bound” and “Mediate” are used in the matrix but are not defined in the text before the table; their distinction from “Observe” and “Verify” may confuse readers. One sentence defining each function would improve readability.
  4. [§2] The sentence introducing AEG as “the closest academic concept” is not backed by a comparison with the other cited frameworks (PAuth, AgentSpec, AuthBench). A brief justification or a small comparison table would make the boundary clearer.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: APV is an explicit management abstraction, not a derived prediction, and its components are defined from evidence rather than from the conclusion.

full rationale

The paper's chain of support is self-contained and non-circular. APV is introduced as an operational vulnerability-management abstraction, with an explicit statement that it is not a new root-cause class: 'APV is not proposed as a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses' (Abstract and §10). The definition in §4 is a thresholded construct requiring persistence, an expected task class, consequential reach, and a mandate/mediation/evidence deficit; none of these conditions is defined in terms of the APV outcome itself. 'Mandate' is defined from external evidence ('explicit user instructions, tickets, repository and organizational policy, environmental constraints, and approved exceptions'), and 'effective authority' is defined from tool, credential, connector, environment, and control composition, not from the record being produced. The paper makes no fitted predictions and the §9 research agenda is presented as tests, not results: 'The following hypotheses are not results; they state measurable tests that could support or falsify the position.' The field vignette is explicitly illustrative and not used as prevalence evidence ('This vignette supports construct formation and illustrates the lifecycle; it does not establish prevalence, causality, or independent reproducibility'). Related work is external (OWASP, Agent Baseline, AEG) and the crosswalk is explicitly version-specific and non-load-bearing: 'The crosswalk used later in this paper is illustrative and version-specific; the APV lifecycle does not depend on Agent Baseline retaining its current structure.' Section 10 contains the paper's own limitation that effective authority 'can be difficult to enumerate when agents discover tools and credentials, invoke nested services, delegate to sub-agents, or change the environment during execution'; this is an acknowledged feasibility threat to applying the definition, not a circular step in which the definition presupposes its own conclusion. No self-citations appear, no uniqueness theorem is imported, and no known result is renamed as a derivation. The skeptical concern about undecidable reachability or unstable authority is a correctness or applicability risk, which the paper itself flags, and it does not constitute circularity under the stated criteria.

Assumptions & free parameters 0 free parameters · 4 assumptions · 1 invented entities

The paper adds one conceptual artifact, APV, with no external validation. Its machinery rests on four domain assumptions about security practice: that persistent composed exposures deserve a distinct record, that mandates can be assembled from evidence, that the definition's conditions can be assessed in practice, and that adopting APVs will improve operational outcomes. Each is acknowledged by the authors, with the final one explicitly framed as untested hypotheses.

assumptions (4)
  • domain assumption Persistent composed exposures warrant a distinct vulnerability-management object separate from detections, incidents, and runtime authorization gaps.
    Central premise of the paper, stated in the abstract and Section 2; asserted, not empirically demonstrated.
  • domain assumption A mandate can be assembled as an evidence-backed record from user instructions, tickets, policy, and exceptions, with supported/contradicted/unknown states.
    Invoked in Section 1 and the operational definition; Section 10 concedes mandate evidence can remain incomplete or contested.
  • domain assumption Persistence, expected task class, consequential reach, and material evidence deficits can be assessed in practice well enough to classify a posture as an APV.
    Required by the four-condition definition in Section 4; Section 10 admits the boundary is partly judgment-based and effective authority is hard to enumerate.
  • ad hoc to paper Adopting APV records will improve ownership, deduplication, remediation, risk acceptance, and verified closure compared with alert-only handling.
    The value proposition, framed as testable Hypotheses 1-4 in Section 9, all unrun.
invented entities (1)
  • Agentic posture vulnerability (APV)
    purpose: A durable, task-conditioned vulnerability record linking persistent composed agent-control exposures to runtime manifestations, with lifecycle and closure verification.
    The paper introduces APV as a new conceptual object. It provides no data or external measurement validating its utility; the proposed hypotheses in Section 9 are untested, so there is no falsifiable handle outside the paper.

how reviews work

0 comments
Cite this review

Pith. "Pith review of The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents." pith.science (2026). https://pith.science/paper/ZZJ4WFFS

@misc{pith2026260805884,
  author       = {Pith},
  title        = {Pith review of: The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ZZJ4WFFS}},
  note         = {Machine review of arXiv:2608.05884}
}
read the original abstract

Existing guidance identifies excessive agency, excessive permission, weak task-bound authorization, and inadequate agent controls as important risks. Control frameworks also describe capabilities for constraining, authorizing, observing, validating, and responding to agent activity. Yet security programs still need a way to manage persistent deployed instances that span components and outlive any one event. We propose the agentic posture vulnerability (APV) as a task-conditioned vulnerability-management abstraction: a durable record for a composed agent-control exposure. One posture may produce different runtime manifestations across tasks; APV links those manifestations to the invariant posture and remains open until authority is narrowed, a missing control is added, risk is accepted, or closure is verified. APV is not proposed as a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses. We distinguish APVs from CVE-addressable product defects, OWASP Excessive Agency, Agent Baseline control outcomes, and the runtime authorization-execution gap. We then provide a field vignette, a thresholded definition, six recurring APV patterns, a vulnerability lifecycle, a minimum record, a control-and-closure matrix, tooling implications, and a testable research agenda.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

32 extracted references · 20 canonical work pages

  1. [1]

    Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code

    Anthropic . Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code . GitHub Security Advisory GHSA-x5gv-jw7f-j6xj, August 2025. URL https://github.com/anthropics/claude-code/security/advisories/GHSA-x5gv-jw7f-j6xj. CVE-2025-55284; affected versions before 1.0.4; patched in 1.0.4; accessed 2026-08-06

  2. [2]

    Accelerating the adoption of software and artificial intelligence agent identity and authorization

    Harold Booth, William Fisher, Ryan Galluzzo, and Joshua Roberts. Accelerating the adoption of software and artificial intelligence agent identity and authorization. Initial public draft concept paper, National Institute of Standards & Technology , National Cybersecurity Center of Excellence, February 2026. URL https://csrc.nist.gov/pubs/other/2026/02/05/a...

  3. [4]

    CVE program glossary

    CVE Program . CVE program glossary. https://www.cve.org/ResourcesSupport/Glossary, n.d. Accessed 2026-08-06

  4. [5]

    Agent baseline: Six security outcomes for safely building, deploying and operating AI agents

    Ranti Familusi, Chris Huszcza, William Manning, Kamil Potrec, David Schott, and Jelmer Snoeck. Agent baseline: Six security outcomes for safely building, deploying and operating AI agents. https://agentbaseline.org/whitepaper.pdf, July 2026. Version 1.0-draft, published 2026-07-30; accessed 2026-08-06

  5. [6]

    Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey

    L. Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey. Guide for security-focused configuration management of information systems. NIST Special Publication 800-128, National Institute of Standards & Technology , August 2011. URL https://csrc.nist.gov/pubs/sp/800/128/upd1/final. Includes updates as of 2019-10-10

  6. [9]

    LLM06:2025 Excessive Agency

    OWASP Gen AI Security Project . LLM06:2025 Excessive Agency . https://genai.owasp.org/llmrisk/llm062025-excessive-agency/, 2025. Accessed 2026-08-06

  7. [12]

    Haines, Somesh Jha, Richard P

    Oleg Sheyner, Joshua W. Haines, Somesh Jha, Richard P. Lippmann, and Jeannette M. Wing. Automated generation and analysis of attack graphs. In Proceedings of the 2002 IEEE Symposium on Security and Privacy, pages 273--284, 2002. doi:10.1109/SECPRI.2002.1004377

  8. [13]

    Guide to enterprise patch management planning: Preventive maintenance for technology

    Murugiah Souppaya and Karen Scarfone. Guide to enterprise patch management planning: Preventive maintenance for technology. NIST Special Publication 800-40 Revision 4, National Institute of Standards & Technology , April 2022. URL https://csrc.nist.gov/pubs/sp/800/40/r4/final

Show all 32 references
  1. [16]

    Poskitt, and Jun Sun

    Haoyu Wang, Christopher M. Poskitt, and Jun Sun. AgentSpec : Customizable runtime enforcement for safe and reliable LLM agents. In Proceedings of the 48th IEEE/ACM International Conference on Software Engineering, 2026. URL https://arxiv.org/abs/2503.18666. Also available as a...

  2. [19]

    Cyber defense matrix

    Sounil Yu. Cyber defense matrix. https://cyberdefensematrix.com/, n.d. Accessed 2026-08-06

  3. [20]

    AI agent remote code execution

    Zed Industries . AI agent remote code execution. GitHub Security Advisory GHSA-x34m-39xw-g2wr, August 2025. URL https://github.com/zed-industries/zed/security/advisories/GHSA-x34m-39xw-g2wr. CVE-2025-55012; affected versions before 0.197.3; patched in 0.197.3; accessed 2026-08-06

  4. [22]

    , howpublished =

    n.d. , howpublished =

  5. [23]

    2025 , howpublished =

  6. [24]

    2026 , month = jul, howpublished =

    Ranti Familusi and Chris Huszcza and William Manning and Kamil Potrec and David Schott and Jelmer Snoeck , title =. 2026 , month = jul, howpublished =

  7. [25]

    2025 , month = aug, howpublished =

    Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in. 2025 , month = aug, howpublished =

  8. [26]

    2025 , month = aug, howpublished =

  9. [27]

    2022 , month = apr, doi =

    Murugiah Souppaya and Karen Scarfone , title =. 2022 , month = apr, doi =

  10. [28]

    Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =

    L. Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =. 2011 , month = aug, note =. doi:10.6028/NIST.SP.800-128 , url =

  11. [29]

    Haines and Somesh Jha and Richard P

    Oleg Sheyner and Joshua W. Haines and Somesh Jha and Richard P. Lippmann and Jeannette M. Wing , title =. Proceedings of the 2002 IEEE Symposium on Security and Privacy , year =

  12. [30]

    2026 , month = feb, type =

    Harold Booth and William Fisher and Ryan Galluzzo and Joshua Roberts , title =. 2026 , month = feb, type =

  13. [31]

    arXiv preprint arXiv:2501.09674 , year =

    Tobin South and Samuele Marro and Thomas Hardjono and Robert Mahari and Cedric Deslandes Whitney and Dazza Greenwood and Alan Chan and Alex Pentland , title =. arXiv preprint arXiv:2501.09674 , year =

  14. [32]

    Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =

    Reshabh K. Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =. arXiv preprint arXiv:2603.17170 , year =

  15. [33]

    arXiv preprint arXiv:2605.11003 , year =

    Baoyuan Wu and Qingshan Liu and Adel Bibi and Irwin King and Siwei Lyu , title =. arXiv preprint arXiv:2605.11003 , year =

  16. [34]

    arXiv preprint arXiv:2605.18583 , year =

    Yubin Qu and Ying Zhang and Yanjun Zhang and Gelei Deng and Yuekang Li and Leo Yu Zhang and Yi Liu , title =. arXiv preprint arXiv:2605.18583 , year =

  17. [35]

    arXiv preprint arXiv:2605.14859 , year =

    Zheng Yan and Jingxiang Weng and Charles Chen and Dengyun Peng and Ethan Qin and Jiannan Guan and Jinhao Liu and Qiming Yu and Yixin Yuan and Fanqing Meng and Carl Che and Mengkang Hu , title =. arXiv preprint arXiv:2605.14859 , year =

  18. [36]

    Poskitt and Jun Sun , title =

    Haoyu Wang and Christopher M. Poskitt and Jun Sun , title =. Proceedings of the 48th IEEE/ACM International Conference on Software Engineering , year =

  19. [37]

    arXiv preprint arXiv:2603.20953 , year =

    Uchi Uchibeke , title =. arXiv preprint arXiv:2603.20953 , year =

  20. [38]

    Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =

    Christoph B. Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =. doi:10.1145/3808103 , publisher =

  21. [39]

    arXiv preprint arXiv:2603.16586 , year =

    Maurits Kaptein and Vassilis-Javed Khan and Andriy Podstavnychy , title =. arXiv preprint arXiv:2603.16586 , year =

  22. [40]

    arXiv preprint arXiv:2606.22916 , year =

    Genliang Zhu and Chu Wang , title =. arXiv preprint arXiv:2606.22916 , year =

  23. [41]

    arXiv preprint arXiv:2507.09329 , year =

    Matous Kozak and Roshanak Zilouchian Moghaddam and Siva Sivaraman , title =. arXiv preprint arXiv:2507.09329 , year =

  24. [42]

    Sounil Yu , title =. n.d. , howpublished =

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.