{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_e5d1e8312acc2d9cc1a9693d97e5753adf2b710782cd635ba00b1ccb185c52bf","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_e5d1e8312acc2d9cc1a9693d97e5753adf2b710782cd635ba00b1ccb185c52bf","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"298cba9760ca2839b260e7e531f3beeb21d2b112ae2fdeeeb613c44e5f60f489","published":"Sat, 06 Jun 2026 00:00:00 -0400","receipt_hash":"298cba9760ca2839b260e7e531f3beeb21d2b112ae2fdeeeb613c44e5f60f489","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"298cba9760ca2839b260e7e531f3beeb21d2b112ae2fdeeeb613c44e5f60f489","observed_at":"2026-06-06T04:43:19.193968Z","parent_run_hash":"550d5b02674822f43975c282be668ca76a4d9c7c957eb1601ba8b07dcb67715e","published":"Sat, 06 Jun 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2601.09923v3 Announce Type: replace \nAbstract: AI agents are vulnerable to prompt injection attacks, where malicious content hijacks agent behavior. Among proposed defenses, architectural isolation provides the strongest guarantees by strictly separating trusted task planning from untrusted environment observations. However, applying this design to Computer Use Agents (CUAs), which automate tasks by viewing screens and executing actions, presents a fundamental challenge. Current agents require continuous observation of UI state to determine each action, which conflicts with the isolation required for security. We resolve this tension by demonstrating that UI workflows, while dynamic, are structurally predictable. Single-shot planning, where a trusted planner emits upfront a complete branching plan covering all anticipated runtime states, provides control flow integrity guarantees against arbitrary instruction injections. We introduce NOVA (Navigating via Observation, Verification","title":"CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents","url":"https://arxiv.org/abs/2601.09923","vendor":"arxiv_cs_ai"},"summary":"arXiv:2601.09923v3 Announce Type: replace \nAbstract: AI agents are vulnerable to prompt injection attacks, where malicious content hijacks agent behavior. Among proposed defenses, architectural isolation provides the strongest guarantees by strictly separating trusted task planning from untrusted environment observations. However, applying this design to Computer Use Agents (CUAs), which automate tasks by viewing screens and executing actions, presents a fundamental challenge. Current agents require continuous observation of UI state to determine each action, which conflicts with the isolation required for security. We resolve this tension by demonstrating that UI workflows, while dynamic, are structurally predictable. Single-shot planning, where a trusted planner emits upfront a complete branching plan covering all anticipated runtime states, provides control flow integrity guarantees against arbitrary instruction injections. We introduce NOVA (Navigating via Observation, Verification","title":"CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-06-06T04:43:19Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2601.09923"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:6e28b8168b84558dd50e69a2a78f2d9711aebf65a51ed53d0539ec633f9b8e9932824db32d4d85d45866f25917753a3185d8de8d7e1a6b80844ee817c3c8240d","signer":"crovia.substrate","subject":{"observed_at":"2026-06-06T04:43:19Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2601.09923"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"865b5b6edd65d3475650b34cdf20f51187d1d17fb0d42ff7bb003d9cc5a261a3","leaf_index":219425,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"d3d59455a4cfaef2eb57bd853e73cae786939f8bd78467cde5d3ec1713f872ae","side":"left"},{"sibling":"57a85548ca482c10771b0cd596f1a4d056ca9c5f8dceaaac0548166866ac0e51","side":"right"},{"sibling":"78956c32cc9ab0d287c6f0193c805535639ce50ea50c38015305e6a56ab0215d","side":"right"},{"sibling":"f30d9adf8d68647203d590f72b652b669ae0e978d513aad63528cd22c04479c8","side":"right"},{"sibling":"e6771f7e0abe1bb2ff4409bdbaefde823f3052d98ce5fc2a1899822d30cb7ca1","side":"right"},{"sibling":"0533945d48fc5cfd005a76d7e01ac78a1ad97725a2e0650037feaf4a36bde567","side":"left"},{"sibling":"c6d85f421226f83ff8cf32aaff89929d6dc9d5d94759254073631ced17a73907","side":"right"},{"sibling":"242ec7690d5995e1b5c2e94f2a8cedd5416b170d2db6fb44c95d0f9fb134a235","side":"right"},{"sibling":"42875175baa73c49869c927a23711e8bef732331ce49af85fa7e86d0903b1066","side":"left"},{"sibling":"84d2509eab51047589142ed6da8c496305d2fbcbe148e0e6755163db2c7a4bc4","side":"right"},{"sibling":"9e3ea17e834fab022f2eabcfedb8ea0ac95c1f9fb57edc5004dded68522d3c9e","side":"right"},{"sibling":"41d58fea95a95071715ee23ef8bcd15f5867a3639da28e62a0641bc95eb83094","side":"left"},{"sibling":"27ad9d6a9ab792d708709017242a61b9ca519da4e035f87a342811aae221d000","side":"left"},{"sibling":"5f303e2a7840c60038ff2d035b1cd911feefb0fba880de2d737c6671ace594d4","side":"right"},{"sibling":"b2590791b920ca2a4ed39de126d2c0b1a10d9e7e62f572f12425f214e767b6e1","side":"left"},{"sibling":"1a61eadbf0217d063ab78291ccafdc0c92907f7d6ccdc3357534ef89f07d78ae","side":"right"},{"sibling":"c300cf0154c136afc09b1702a0be98f4ba5b6dc5cf57e8cc714ec1eaf4196eff","side":"left"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":219672,"merkle_root":"d3e32d3a61ca02ce6b1f0b2db86721107770b250e8a5bf762a2c225d2f03c870","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260606T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-06-06T05:38:35Z","sig_algorithm":"ed25519","signature":"dab214c2d4d857f01383c8e93a521a774b1aba60eaee5677d4e43e4074f0342b2c6a9b9bfcff0eba74f7ac81fcb490dd0e43727979c1a7e8979c7e11547fb101","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_e5d1e8312acc2d9cc1a9693d97e5753adf2b710782cd635ba00b1ccb185c52bf"}}