Recognition Without Enforcement: Configuration-Dependent Failures in LLM Agent Instruction Arbitration and External Control
This work treats model self-arbitration as a capability rather than a security boundary and implements an external reference monitor combining authenticated source routing with capability-gated tool execution, deterministically rejects all tested forged, tampered, replayed, and unsigned requests while preserving legiti...