{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:UVDUHUI5KFRRXRKNIZ6XZHPRMJ","short_pith_number":"pith:UVDUHUI5","schema_version":"1.0","canonical_sha256":"a54743d11d51631bc54d467d7c9df16255ec1c915b35955ea66a34da6cb246ee","source":{"kind":"arxiv","id":"2604.16870","version":2},"attestation_state":"computed","paper":{"title":"Governed MCP: Kernel-Level Tool Governance for AI Agents via Logit-Based Safety Primitives","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Kernel-resident gateway for AI agent tool calls makes 10-line userspace bypasses structurally impossible.","cross_cats":["cs.AI","cs.OS"],"primary_cat":"cs.CR","authors_text":"Daeyeon Son","submitted_at":"2026-04-18T06:40:20Z","abstract_excerpt":"AI agents increasingly call external tools (file system, network, APIs) through the Model Context Protocol (MCP). These tool calls are the agent's syscalls: privileged operations with side effects on shared state, yet today's safety enforcement lives entirely in userspace, where a 10-line script can bypass it. I propose Governed MCP, a kernel-resident tool governance gateway built on a logit-based safety primitive (ProbeLogits). The gateway interposes on every MCP tool call in a 6-layer pipeline: schema validation, trust tier, rate limit, adversarial pre-filter, a ProbeLogits semantic gate (th"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2604.16870","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-04-18T06:40:20Z","cross_cats_sorted":["cs.AI","cs.OS"],"title_canon_sha256":"55c75cf4f14ad024be9d2e0ae6469b4a34f4d3a26f1d79df791c39e1a9497648","abstract_canon_sha256":"d8841aa4de7c071d81abd4fd1c3963a816845eac8874a693ffff78e8c36443d0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-07T02:18:40.735482Z","signature_b64":"jIf/wCqY7nZ2i6FuCEeYtDyhKNc7ww+3/sfRtKUQS4gr52kp0jKQsh+wJy4oz65YGbiJBkrg4UYJLRnG4iSCBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a54743d11d51631bc54d467d7c9df16255ec1c915b35955ea66a34da6cb246ee","last_reissued_at":"2026-07-07T02:18:40.734679Z","signature_status":"signed_v1","first_computed_at":"2026-07-07T02:18:40.734679Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Governed MCP: Kernel-Level Tool Governance for AI Agents via Logit-Based Safety Primitives","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Kernel-resident gateway for AI agent tool calls makes 10-line userspace bypasses structurally impossible.","cross_cats":["cs.AI","cs.OS"],"primary_cat":"cs.CR","authors_text":"Daeyeon Son","submitted_at":"2026-04-18T06:40:20Z","abstract_excerpt":"AI agents increasingly call external tools (file system, network, APIs) through the Model Context Protocol (MCP). These tool calls are the agent's syscalls: privileged operations with side effects on shared state, yet today's safety enforcement lives entirely in userspace, where a 10-line script can bypass it. I propose Governed MCP, a kernel-resident tool governance gateway built on a logit-based safety primitive (ProbeLogits). The gateway interposes on every MCP tool call in a 6-layer pipeline: schema validation, trust tier, rate limit, adversarial pre-filter, a ProbeLogits semantic gate (th"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"a 10-LoC userspace bypass that defeats existing guardrail libraries is structurally impossible against the kernel-resident gate; all 15 WASM-to-system host functions route through the gateway.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the ProbeLogits semantic gate (detailed in the companion paper) reliably identifies unsafe or unintended MCP tool calls across realistic adversarial and benign scenarios, as the reported support is an ablation on a 101-prompt benchmark.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Governed MCP implements kernel-level governance for MCP tool calls in AI agents through a 6-layer pipeline including ProbeLogits semantic verification, with an ablation showing F1 drop from 0.773 to 0.327 without it and structural prevention of userspace bypasses.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Kernel-resident gateway for AI agent tool calls makes 10-line userspace bypasses structurally impossible.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"d77cec4a42890b7b2766df18a45a50d7a20f8203e2b5c8de601ac8b6d6a81eb3"},"source":{"id":"2604.16870","kind":"arxiv","version":2},"verdict":{"id":"d1dbfa2e-8bbe-495f-a05d-ca3ecfb9a622","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-10T06:51:26.482129Z","strongest_claim":"a 10-LoC userspace bypass that defeats existing guardrail libraries is structurally impossible against the kernel-resident gate; all 15 WASM-to-system host functions route through the gateway.","one_line_summary":"Governed MCP implements kernel-level governance for MCP tool calls in AI agents through a 6-layer pipeline including ProbeLogits semantic verification, with an ablation showing F1 drop from 0.773 to 0.327 without it and structural prevention of userspace bypasses.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the ProbeLogits semantic gate (detailed in the companion paper) reliably identifies unsafe or unintended MCP tool calls across realistic adversarial and benign scenarios, as the reported support is an ablation on a 101-prompt benchmark.","pith_extraction_headline":"Kernel-resident gateway for AI agent tool calls makes 10-line userspace bypasses structurally impossible."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2604.16870/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2604.16870","created_at":"2026-07-07T02:18:40.734786+00:00"},{"alias_kind":"arxiv_version","alias_value":"2604.16870v2","created_at":"2026-07-07T02:18:40.734786+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.16870","created_at":"2026-07-07T02:18:40.734786+00:00"},{"alias_kind":"pith_short_12","alias_value":"UVDUHUI5KFRR","created_at":"2026-07-07T02:18:40.734786+00:00"},{"alias_kind":"pith_short_16","alias_value":"UVDUHUI5KFRRXRKN","created_at":"2026-07-07T02:18:40.734786+00:00"},{"alias_kind":"pith_short_8","alias_value":"UVDUHUI5","created_at":"2026-07-07T02:18:40.734786+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ","json":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ.json","graph_json":"https://pith.science/api/pith-number/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/graph.json","events_json":"https://pith.science/api/pith-number/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/events.json","paper":"https://pith.science/paper/UVDUHUI5"},"agent_actions":{"view_html":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ","download_json":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ.json","view_paper":"https://pith.science/paper/UVDUHUI5","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2604.16870&json=true","fetch_graph":"https://pith.science/api/pith-number/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/graph.json","fetch_events":"https://pith.science/api/pith-number/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/action/storage_attestation","attest_author":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/action/author_attestation","sign_citation":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/action/citation_signature","submit_replication":"https://pith.science/pith/UVDUHUI5KFRRXRKNIZ6XZHPRMJ/action/replication_record"}},"created_at":"2026-07-07T02:18:40.734786+00:00","updated_at":"2026-07-07T02:18:40.734786+00:00"}