{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_d6514e393b15ee82b0a9b7115dab4750a29663ba2f383b7f2cea6ac1dd7902d5","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_d6514e393b15ee82b0a9b7115dab4750a29663ba2f383b7f2cea6ac1dd7902d5","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"7cb98da08b7c73335e753f5ad1bd4b0328dfe2114ebdd63a42920e3190294f46","published":"Tue, 21 Jul 2026 00:00:00 -0400","receipt_hash":"7cb98da08b7c73335e753f5ad1bd4b0328dfe2114ebdd63a42920e3190294f46","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"7cb98da08b7c73335e753f5ad1bd4b0328dfe2114ebdd63a42920e3190294f46","observed_at":"2026-07-21T04:43:35.036805Z","parent_run_hash":"03e944014de2697434479833d15ea9303e014945afc230ecc7f207824493b589","published":"Tue, 21 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2509.25624v3 Announce Type: replace-cross \nAbstract: As LLMs advance into autonomous agents with tool-use capabilities, they introduce security challenges that extend beyond traditional content-based LLM safety concerns. This paper introduces Sequential Tool Attack Chaining (\\STAC), a novel multi-turn attack framework that exploits agent tool use. \\STAC chains together tool calls that each appear harmless in isolation but, when combined, collectively enable harmful operations that only become apparent at the final execution step. At the core of \\STAC is an automated, closed-loop pipeline that synthesizes executable multi-step tool chains, validates them through in-environment execution, and reverse-engineers stealthy multi-turn prompts that reliably induce agents to execute the verified malicious sequence. Using this framework, we generate and systematically evaluate 483 \\STAC cases, featuring 1,352 sets of user-agent-environment interactions and spanning diverse domains, tasks, ","title":"STAC: When Innocent Tools Form Dangerous Chains for LLM Agents","url":"https://arxiv.org/abs/2509.25624","vendor":"arxiv_cs_ai"},"summary":"arXiv:2509.25624v3 Announce Type: replace-cross \nAbstract: As LLMs advance into autonomous agents with tool-use capabilities, they introduce security challenges that extend beyond traditional content-based LLM safety concerns. This paper introduces Sequential Tool Attack Chaining (\\STAC), a novel multi-turn attack framework that exploits agent tool use. \\STAC chains together tool calls that each appear harmless in isolation but, when combined, collectively enable harmful operations that only become apparent at the final execution step. At the core of \\STAC is an automated, closed-loop pipeline that synthesizes executable multi-step tool chains, validates them through in-environment execution, and reverse-engineers stealthy multi-turn prompts that reliably induce agents to execute the verified malicious sequence. Using this framework, we generate and systematically evaluate 483 \\STAC cases, featuring 1,352 sets of user-agent-environment interactions and spanning diverse domains, tasks, ","title":"STAC: When Innocent Tools Form Dangerous Chains for LLM Agents","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-21T04:43:35Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2509.25624"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:2e78d6623c1b96daca44f6641c1932cb102c6868c1bd49748b5c7db68c36e7628cdf8e0e504e3252f53cacd66928df9329d11aebca51680c244637651acdfb0d","signer":"crovia.substrate","subject":{"observed_at":"2026-07-21T04:43:35Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2509.25624"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"e6c51345284ea2231572be88862fc547a9d90e3458443e18b39867493d81169b","leaf_index":336925,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"83a7cb43e05aaa067abd69354fba05d6fefcc0c86b23557424fa14600fb3c70c","side":"left"},{"sibling":"b477edcf99de62152a9fbf3bdcda9df595e7d6bdb97248aa217de58d440f4dc5","side":"right"},{"sibling":"53473f996723a2430ffa846ca63d763deb7b4498d2c5dd7a229211f4544a44d7","side":"left"},{"sibling":"d89012ad4b4b04af4b5b85e5621247729e7e9285d4e581399129044abafec755","side":"left"},{"sibling":"7d21e41d8dbce978fcdadd7bfac6afaf79d14d4b14efd41f4eb6d9a6d02090d9","side":"left"},{"sibling":"970de1a9ae0755f91297bfb952a2e1b5408d3c6ffa1792b61545c081aaf5382d","side":"right"},{"sibling":"950013dbd7f9f5861e4c5ff582a4f28f41529fee5ece541adb6d424c9cbd1f75","side":"right"},{"sibling":"45255096c5a08e740a615b6e3c262589a170dbfc373bdeaceae175916dd2ab97","side":"right"},{"sibling":"1298242aa509bc13b92160250ead2d95a721941ca6310e33b9eb0bf0821557d0","side":"right"},{"sibling":"61d44c6d16b87de577db53cff0dba2f003c50c036d92dc335120aa70124c8788","side":"right"},{"sibling":"5d0b792dbe69fd0a7cd8d79b467aa10204d1f25be602c06190f3423bc22727b8","side":"left"},{"sibling":"9eb5077edfb3dc553857d4794b925bfce117e0f8a1d049af5d0dd9026b470eef","side":"right"},{"sibling":"414b1a70fd1dcb25489a194714b97492b066684b15d0b7a48a176c4b9b5bc713","side":"right"},{"sibling":"21d66dd41003813f710b7617944f1bfba3258658a5d3370c21cad8f9e945bc99","side":"left"},{"sibling":"613f015699131eb89bd755dee67133be95af25cf5f16c1c8ce4b99d963b8dd86","side":"right"},{"sibling":"a729b574b1135956436ded5eef1fe8f08014ff6a0729749d307ab1bca93fcdc9","side":"right"},{"sibling":"77025bcb374a7ad74f520643e20a8ae1205a7ee78507b0beb93117760f1c29d3","side":"left"},{"sibling":"4bf21052e085e8ac81f1dec1d2b310bd12bf948992de6177d12e9d2fda8d39f0","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":337144,"merkle_root":"5e969cc01afa67e4dbe5d37b712cdb10f4aa1fd74404e02eab724cf487c8d6d9","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260721T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-21T05:38:38Z","sig_algorithm":"ed25519","signature":"5c0c1a8dd2793d787ccd5e49e8b4d70eed136352555518589f05c74be357fc171702e42a76c3a556d90e3d51ff36cb3d292aaac83c66566de7b943f318bda50c","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_d6514e393b15ee82b0a9b7115dab4750a29663ba2f383b7f2cea6ac1dd7902d5"}}