← 피드로
[Submitted on 27 Feb 2026 (v1), last revised 5 Aug 2026 (this version, v2)]
Abstract:32 pages, 5 theorems with full proofs, 68 references, open-source tool: this https URL. v2: corrects the bibliography (22 entries had author lists that did not match the papers at the cited arXiv identifiers; all verified against the arXiv API and corrected, and affected authors notified) and three external claims against primary sources: MalTool reports 1,300 standalone and 5,727 embedded malicious tools, not 6,487; CVE-2026-25253 is authentication-token exfiltration via an unvalidated gatewayUrl, credited to depthfirst and fixed in 2026.1.29, not remote code execution through a crafted skill package; ClawHavoc counts are 341, later 824, and 1,184 by source and date, not “over 1,200”. All experiments re-measured against the released v0.6.0 implementation using harnesses now committed to the repository. E1/E2 unchanged (F1 96.15%). E3 reverses to a negative result: information flow analysis adds no detections over pattern matching on this corpus. The soundness theorem’s scope is stated explicitly and no longer conflated with the zero false-positive rate.
Submission history
From: Varun Pratap Bhardwaj [view email]
[v1]
Fri, 27 Feb 2026 06:21:53 UTC (70 KB)
[v2]
Wed, 5 Aug 2026 13:43:09 UTC (84 KB)
추출 본문 · 출처: arxiv.org · https://arxiv.org/abs/2603.00195
답글 남기기