{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_ae79c922684f04f04a71b48b5e6aa8aaee904668df2adb57e2828f63d0cc1ca9","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_ae79c922684f04f04a71b48b5e6aa8aaee904668df2adb57e2828f63d0cc1ca9","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"a3344113a4b3aa75173bf923413232d5252141716e7a626267b140f049021a6f","published":"Thu, 18 Jun 2026 00:00:00 -0400","receipt_hash":"a3344113a4b3aa75173bf923413232d5252141716e7a626267b140f049021a6f","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"a3344113a4b3aa75173bf923413232d5252141716e7a626267b140f049021a6f","observed_at":"2026-06-18T04:43:37.219665Z","parent_run_hash":"de79a40f7b3537d88842f7ac355e799c5df2adcb4fc32a4e28096d4bbdf01739","published":"Thu, 18 Jun 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2606.18356v1 Announce Type: cross \nAbstract: Tool-using language-model agents introduce security failures that go beyond unsafe text: they can disclose protected objects, write persistent memory, send messages, modify databases, or trigger harmful code and tool effects. Existing evaluations often collapse these stages into a single attack success rate, making it difficult to tell whether a model merely agreed with an attacker or actually produced observable harm. We introduce SafeClawBench, a staged benchmark for tool-using agent security with 600 controlled adversarial tasks across six attack families: direct and indirect prompt injection, tool-return injection, memory poisoning, memory extraction, and ambiguity-driven unsafe inference. SafeClawBench reports three separate endpoints: semantic attack acceptance, audit-visible harm evidence, and sandbox-observed tool/state harm. Evaluating five agent endpoints under four prompt-level policies, we find that these endpoints capture ","title":"SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents","url":"https://arxiv.org/abs/2606.18356","vendor":"arxiv_cs_ai"},"summary":"arXiv:2606.18356v1 Announce Type: cross \nAbstract: Tool-using language-model agents introduce security failures that go beyond unsafe text: they can disclose protected objects, write persistent memory, send messages, modify databases, or trigger harmful code and tool effects. Existing evaluations often collapse these stages into a single attack success rate, making it difficult to tell whether a model merely agreed with an attacker or actually produced observable harm. We introduce SafeClawBench, a staged benchmark for tool-using agent security with 600 controlled adversarial tasks across six attack families: direct and indirect prompt injection, tool-return injection, memory poisoning, memory extraction, and ambiguity-driven unsafe inference. SafeClawBench reports three separate endpoints: semantic attack acceptance, audit-visible harm evidence, and sandbox-observed tool/state harm. Evaluating five agent endpoints under four prompt-level policies, we find that these endpoints capture ","title":"SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-06-18T04:43:37Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2606.18356"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:f3fce6c5e9366a67c29fd32addd26e68aa337314dd2322d1f3810391ca563672e02352e97564a3cee8ae8e39b118c7b04b696522cadcd1acde40440516ebd30f","signer":"crovia.substrate","subject":{"observed_at":"2026-06-18T04:43:37Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2606.18356"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"77c8477337a25c3fd4c7f7eb53d2530ca07c04ec7920a174df239ffe0d3ea861","leaf_index":233317,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"0374a4fa6393cefee611de1c145886de3d24f8a187868d4479e8550a5290f007","side":"left"},{"sibling":"cf7104178b9cecdbd1c42afbffe8309160de4b87e004e19a727c3544b7363d31","side":"right"},{"sibling":"0aa24df9a698f2480684ada34dc1e92de67f4bbbd6d76e2acffb25a0e72f7e35","side":"left"},{"sibling":"64a6d63442b08edc8054efbb6d4ea9089b975b1e93fb487772dbb43506cc2b27","side":"right"},{"sibling":"e1ef239f83e3a692374edca05d0280820b1aff2d562e9422d67f4377018cc826","side":"right"},{"sibling":"fffc094d5a9b079ba5f4fd126957bc58d6ef5e5cde89e47f776f9bae2ad17a6b","side":"left"},{"sibling":"fb2efccf288f12f103208a3d9da4b3826488e1b2cf803df6c0d9957623efbe10","side":"left"},{"sibling":"0330fab6a2deb3386a57965a262bbfda239c89f35362e27a0c4e7f3a9108ec2e","side":"right"},{"sibling":"429c2a92a65e6eeaa2eda0a35fdb9e541472a1eace4c69a4d01a618a659a110f","side":"left"},{"sibling":"d97d1ebe04af6ea572f9d4334004d01026acffa3da5be2883c7566513c76e2c0","side":"left"},{"sibling":"571eb56e7ce00fe1f38d0ac4fc56828d01b2cfc1ab9089cde245c0656bee0514","side":"left"},{"sibling":"7ac50038a8ced3aeaf1194a2407a4a09346b0e4399da36ecde4390675a0c4bf1","side":"left"},{"sibling":"8c5e2b48dc31ef0edcd35c3db048235aa78cc48443aa2a8da3aa6e9b5524d2c4","side":"right"},{"sibling":"e616c34dbaf9456d5a6d3e2da82cde8621293c9f6d8a4cf9e441d7fd9cc81579","side":"right"},{"sibling":"94c0c932e61657f5e37fdba43f6ca9eddea8359425a7c1558dabe566911d5304","side":"right"},{"sibling":"a04392fb9f2a3a620840e3b3fecd93d12e6d224e481c162389d8ae64e7194599","side":"left"},{"sibling":"c300cf0154c136afc09b1702a0be98f4ba5b6dc5cf57e8cc714ec1eaf4196eff","side":"left"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":234491,"merkle_root":"02576a6980e38bab47864ae2c57b5a5ff21e554e9bdf8f64bdf28155ff1aabec","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260618T143732Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-06-18T18:33:39Z","sig_algorithm":"ed25519","signature":"b6c708778fc38b7789a2b91156cfe87252a7cd3a1d29121cba11a0c78f8cf104ca3019fc50a962fa5a216bcc4922fc8f3f69c04d1f8332c6dc0d931e1012e502","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_ae79c922684f04f04a71b48b5e6aa8aaee904668df2adb57e2828f63d0cc1ca9"}}