🚀NEW COURSEVibe Coding AI Apps with Claude Code 🤖✨Enroll now
← All papers  /  Sep 4, 2026
Safety

CONTINUITY: Security-Context Contracts for Composable LLM Agent Controls

First page
CONTINUITY: Security-Context Contracts for Composable LLM Agent Controls
The curator’s take

Chris Zheng and Geng Yang name a failure mode where individually correct agent security controls stop composing, and build a contract framework that carries authenticated security context across component boundaries.

Ask this paper

Key points
01

Security-context discontinuity. As an action crosses from provenance tracking to authorization to policy enforcement to protocol adapters to execution, the security-critical context can be dropped, widened, rebound, or reinterpreted.

02

The mechanism. Each component gets an assume-guarantee contract, and context travels on signed root grants, provenance commitments, role-bound transition receipts, bounded typed releases, transformation witnesses, and effect-bound execution permits.

03

End-to-end consequence integrity. Every realized external effect must be backed by a valid current authorization witness linking principal, task, provenance, delegation, policy state, canonical action, and finality boundary.

04

Evaluation. A reference verifier plus a deterministic cross-layer fault-injection suite covering 32 fault classes across four domains, run over 2,560 parameterized attack instances spanning 128 fault-domain classes.

05

Results. The full configuration commits no harmful external effect, completes all 700 benign tasks, and escalates all 200 ambiguous cases.

Abstract

LLM agent systems increasingly combine provenance tracking, authorization, policy enforcement, protocol adapters, and execution controls. However, individually correct security mechanisms do not necessarily compose into an end-to-end secure system: security-critical context may be dropped, widened, rebound, or reinterpreted as actions cross component boundaries. We identify this failure mode as security-context discontinuity and introduce CONTINUITY, a framework for verifiable composition of agent security controls. CONTINUITY models each component with an assume-guarantee contract and carries authenticated security context across transitions using signed root grants, provenance commitments, role-bound transition receipts, bounded typed releases, transformation witnesses, and effect-bound execution permits. We formalize end-to-end consequence integrity, requiring every realized external effect to be backed by a valid and current authorization witness linking the principal, task, provenance, delegation, policy state, canonical action, and finality boundary. We implement a reference verifier and deterministic cross-layer fault-injection suite covering 32 fault classes across four application domains. In 2,560 parameterized attack instances spanning 128 fault-domain classes, the full CONTINUITY configuration commits no harmful external effect, while completing all 700 benign tasks and escalating all 200 ambiguous cases. These results show that secure agent execution requires not only sound individual controls, but explicit contracts that preserve their guarantees across the complete instruction-to-effect path.

Every Monday
Get next week’s papers.
Subscribe on Substack