{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_471fc8ea47392e8d4ba0777d2eef1d63917c3f503b38d9dcd3bfa7b358349f9b","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_471fc8ea47392e8d4ba0777d2eef1d63917c3f503b38d9dcd3bfa7b358349f9b","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"e26e5ec81d43ae6e88636454ded4ae4cd0bbdd5f0dea8862f0f77b9532424c9f","published":"Tue, 09 Jun 2026 00:00:00 -0400","receipt_hash":"e26e5ec81d43ae6e88636454ded4ae4cd0bbdd5f0dea8862f0f77b9532424c9f","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"e26e5ec81d43ae6e88636454ded4ae4cd0bbdd5f0dea8862f0f77b9532424c9f","observed_at":"2026-06-09T04:43:45.619596Z","parent_run_hash":"f2344865fd128464efd1bacba326b5a7ccea707694b8c5650dd51ae8c46ac8a1","published":"Tue, 09 Jun 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2606.09549v1 Announce Type: cross \nAbstract: Tool-using large language model (LLM) agents face two distinct security failures: unauthorized external actions and exposure of sensitive plaintext inside the runtime before any final output check can intervene. Existing defenses usually protect one boundary, either the planner/runtime or the action sink, and therefore do not by themselves secure both surfaces. We present SecureClaw, a dual-boundary architecture that places authorization at the effect sink and plaintext confinement at the read boundary. Sensitive reads pass through a trusted gateway that replaces raw values with opaque handles and, in the evaluated deployment, bounded summaries as an explicit declassification interface. Writes that change external state follow a PREVIEW$\\rightarrow$COMMIT protocol in which only a trusted executor may commit the exact canonical request authorized by policy. The runtime can still plan over summaries and symbolic references, but cannot di","title":"SecureClaw: Clawing Back Control of LLM Agents","url":"https://arxiv.org/abs/2606.09549","vendor":"arxiv_cs_ai"},"summary":"arXiv:2606.09549v1 Announce Type: cross \nAbstract: Tool-using large language model (LLM) agents face two distinct security failures: unauthorized external actions and exposure of sensitive plaintext inside the runtime before any final output check can intervene. Existing defenses usually protect one boundary, either the planner/runtime or the action sink, and therefore do not by themselves secure both surfaces. We present SecureClaw, a dual-boundary architecture that places authorization at the effect sink and plaintext confinement at the read boundary. Sensitive reads pass through a trusted gateway that replaces raw values with opaque handles and, in the evaluated deployment, bounded summaries as an explicit declassification interface. Writes that change external state follow a PREVIEW$\\rightarrow$COMMIT protocol in which only a trusted executor may commit the exact canonical request authorized by policy. The runtime can still plan over summaries and symbolic references, but cannot di","title":"SecureClaw: Clawing Back Control of LLM Agents","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-06-09T04:43:45Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2606.09549"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:230f95bc6a105531a2972cfc3d8a61b2c247fef4167bc6368c641ff7d8d4a3ce843de999ab48a9c135bfa3fee0be7cf9477d03d4badd4b99cf67beb4f6a5e40e","signer":"crovia.substrate","subject":{"observed_at":"2026-06-09T04:43:45Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2606.09549"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"59105e13cb0e13484460de6f526ea369ba077ff06e170f9ec63155f4c4d09e9b","leaf_index":224407,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"5ab3a3c2ff231f4f55da35f669500aa5a6e995b8d400d78416a1046ab6b023ea","side":"left"},{"sibling":"101be1d5194b19fb78b1c56471854549526c204691f3dbedfdb1a282aade4ebb","side":"left"},{"sibling":"df6fc20fe6b2ffb1e4337362c95a18b3ff63ac0120c0045acdf8125c79527a6c","side":"left"},{"sibling":"9bbb3105070aae704f9e13f8a7ee758d1233a7914a4103e760ef0f042dfb5dbd","side":"right"},{"sibling":"a6aaa1c1a90d0aedb2f6e97fb7160e235cc8094ba1e4d594c5abde0c180ca2ac","side":"left"},{"sibling":"a9aa5cffe4385f8c60a6f86a47c98b79615188a6c53dc52766e6f0213889a0b2","side":"right"},{"sibling":"e608affc2056362c3a340b4c445f33ace512b2cfe2d91dd48dbc62ed1cd1d32e","side":"right"},{"sibling":"0dba1b4aa8c69a39c01dbd9d9884405788a8121b073c56815159112e9ccba4bd","side":"left"},{"sibling":"f6fb234a4e2f067b22329eec05b093a8b38f0411de9434d5a8eb55c2f70f1a2f","side":"right"},{"sibling":"b2df6a4bb3e928f0b447931cc688ae01d2415773a2b07cfed0b1cba689078aed","side":"right"},{"sibling":"b1c9ec856caa0fd46bb47b46f18c59ebcd295d774ca17adb3b46f05d394a6a5d","side":"left"},{"sibling":"24fdc29d461691aedb6fa920758206b5bb43851f477ef7a04c34aaed84b8971b","side":"left"},{"sibling":"036922da4e1e2c46d948f070454bfad299b7406fb00735ea9d8bd1e687f5f445","side":"right"},{"sibling":"533d82482604463aa4a281b9d8b85917b383b7c5f924b2b494039524c55e8797","side":"left"},{"sibling":"b2590791b920ca2a4ed39de126d2c0b1a10d9e7e62f572f12425f214e767b6e1","side":"left"},{"sibling":"87c6b850dfec08ac35a693d9db3a3315250a68adb1cfab9b1015f212b63b15bd","side":"right"},{"sibling":"c300cf0154c136afc09b1702a0be98f4ba5b6dc5cf57e8cc714ec1eaf4196eff","side":"left"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":224761,"merkle_root":"e9f7b49b652e869ab97ffba9c5a31356b2d0e3dc5d00bb28944adf737c46b1e7","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260609T103805Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-06-09T14:15:34Z","sig_algorithm":"ed25519","signature":"8ad8076fb12c8e486ae1d1559a9a7ba8e2ee996a9ad3d8ba7bcdbdbd88ab3a15bcb429707aca6d3e9d8b97e2ba755b3dcc77b1abb6601ccb829842719a6fb30d","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_471fc8ea47392e8d4ba0777d2eef1d63917c3f503b38d9dcd3bfa7b358349f9b"}}