REVIEW 3 major objections 4 minor 32 references
The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents
T0 review · 3 major / 4 minor · reviewed 2026-08-07 · deepseek-v4-flash
Pith's one-line read This position paper proposes the agentic posture vulnerability (APV), a durable, task-conditioned vulnerability record that links the changing runtime manifestations of an AI coding agent to the invariant posture that makes them reachable.
desk verdict A well-scoped position paper that names a real gap and is honest about what it does not prove; the operational premise needs a pilot, not a theorem. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is the APV record itself, held together by the distinction between the invariant posture and its variable runtime manifestations. The load-bearing identity is the task-conditioned linkage: one durable record binds configuration snapshots, evidence of reachable consequential effects, mandate basis (supported, contradicted, or unknown), evidence gaps, scope, owner, remediation, and closure evidence, and stays open until the authority or control path changes. The paper also supplies threshold machinery: the four-condition definition, the persistence and expected-task-class criteria, and the materiality test that keeps generic logging deficiencies and non-consequential control weaknesses outside the boundary.
What would settle it
A longitudinal intervention study in which an APV workflow shows no higher owner-assignment rate, no more verified closures, no lower recurrence, and no shorter median exposure duration than alert-only handling; or a calibration study in which expert raters cannot agree on whether real-world agent configurations satisfy the four APV conditions. Either outcome would collapse the object into an ordinary control deficiency.
Extended reading notes
Core claim
The paper claims that a persistent, task-conditioned exposure in AI coding agents can be managed as a single vulnerability object, the agentic posture vulnerability. A posture is an APV when all four conditions hold: the enabling composition persists beyond a single event or trajectory; it applies to at least one approved or routinely expected task class; the agent can reach a consequential effect; and that effect exceeds the mandate, lacks required pre-effect mediation, or cannot be attributed and reconstructed to the level materially required to govern the authority. The object is not a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses. One posture can produce many different runtime manifestations across tasks, and the APV links those manifestations to the invariant posture, remaining open until authority is narrowed, a missing control is added, risk is accepted, or closure is verified.
Load-bearing premise
The APV definition can only be applied if security teams can reliably assemble a mandate record and assess effective authority and consequential reach well enough to classify a posture; the paper itself notes that mandate evidence can be incomplete or contested and that effective authority is hard to enumerate when agents discover tools, invoke nested services, delegate to sub-agents, or change the environment during execution.
Editorial extensions
If this is right
- Security teams can open a vulnerability record for a posture before any harmful event occurs, and keep it open until authority is narrowed, a control is added, risk is accepted, or closure is verified.
- Alert rules no longer need to capture every manifestation; detections and incidents become evidence of an APV, and the APV record becomes the unit of ownership, deduplication, and remediation.
- Closure becomes verifiable: it requires evidence across the affected scope that the consequential effect is no longer reachable, is narrower, is reliably mediated, or is covered by an explicit risk decision — not the disappearance of one command pattern.
- The framework produces testable hypotheses: posture-based prioritization should reduce ranking inversions against expert adjudication, a fixed posture should yield more distinct consequential action classes across task families than within one task class, and an APV workflow should beat alert-only handling on owner-assignment rate, verified closures, recurrence, and median exposure duration.
Reading between the lines
- If APVs gain adoption, the boundary of the CVE model becomes explicit: patchable product defects keep a patch lifecycle, while composed postures need an identifier and lifecycle of their own, possibly pushing standards bodies to define a complementary posture-level scheme.
- The supported/contradicted/unknown mandate tri-state suggests a practical audit pattern: organizations can precompute 'unknown' zones where the agent's mandate is ambiguous and require human review before consequential actions, turning the APV definition into a design principle for approval gates.
- The four-condition threshold could be operationalized as an inter-rater reliability study; if security practitioners cannot agree on mandate and effective authority, the abstraction would remain a taxonomical exercise rather than a working management object.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This position paper proposes a new vulnerability-management abstraction for AI coding agents, called the agentic posture vulnerability (APV). An APV is defined as a persistent, task-conditioned posture in which a consequential effect is reachable and either exceeds the mandate, lacks required pre-effect mediation, or cannot be attributed and reconstructed to the level needed to govern the authority. The paper distinguishes APVs from CVE-addressable product defects, OWASP Excessive Agency, Agent Baseline control outcomes, and the runtime authorization–execution gap. It presents a motivating field vignette (explicitly not a prevalence study), a four-condition operational definition, six recurring APV patterns, a vulnerability lifecycle, a minimum record, a control-and-closure matrix, tooling implications, and a testable research agenda. The authors state that APV is not a new root-cause class of risk but an operationalization of existing excessive-agency, authorization, and control-composition weaknesses.
Significance. If the APV abstraction works in practice, it gives security teams a durable, named, owned object for managing composed agent-control exposures that persist across sessions and manifest differently across tasks. This is a genuine gap: current practice treats detections and incidents as the unit of work, while the underlying posture remains unmanaged. The paper's strengths include its explicit evidence-and-method note (§3.1), its anchoring to external frameworks (OWASP, Agent Baseline, AEG), its falsifiable research agenda (§9), and its unusually candid discussion of limitations (§10). The contribution is conceptual and operational rather than empirical, which is appropriate for a position paper. The main open risk is whether the construct is decidable enough for real security teams to classify, remediate, and close APVs; this risk is acknowledged by the authors but not yet resolved.
major comments (3)
- [§4, Condition 3; §6, Step 5; §10]
- [§1; §4, Condition 1; §10]
- [§4, Condition 4; §6; §10]
minor comments (4)
- [§4, Condition 2] The phrase “approved or routinely expected class of task” is left undefined. It should be clarified whether “routinely expected” is determined by telemetry, by policy, by the vendor’s documentation, or by some combination, and who makes that determination.
- [§9, Hypothesis 1] The hypothesis “fewer pairwise ranking inversions” needs a specified baseline model and a description of how the expert-adjudicated risk rankings are created. Without these details, the hypothesis is not yet measurable.
- [§7, Table 4] The management functions “Bound” and “Mediate” are used in the matrix but are not defined in the text before the table; their distinction from “Observe” and “Verify” may confuse readers. One sentence defining each function would improve readability.
- [§2] The sentence introducing AEG as “the closest academic concept” is not backed by a comparison with the other cited frameworks (PAuth, AgentSpec, AuthBench). A brief justification or a small comparison table would make the boundary clearer.
Circularity Check
No circularity: APV is an explicit management abstraction, not a derived prediction, and its components are defined from evidence rather than from the conclusion.
full rationale
The paper's chain of support is self-contained and non-circular. APV is introduced as an operational vulnerability-management abstraction, with an explicit statement that it is not a new root-cause class: 'APV is not proposed as a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses' (Abstract and §10). The definition in §4 is a thresholded construct requiring persistence, an expected task class, consequential reach, and a mandate/mediation/evidence deficit; none of these conditions is defined in terms of the APV outcome itself. 'Mandate' is defined from external evidence ('explicit user instructions, tickets, repository and organizational policy, environmental constraints, and approved exceptions'), and 'effective authority' is defined from tool, credential, connector, environment, and control composition, not from the record being produced. The paper makes no fitted predictions and the §9 research agenda is presented as tests, not results: 'The following hypotheses are not results; they state measurable tests that could support or falsify the position.' The field vignette is explicitly illustrative and not used as prevalence evidence ('This vignette supports construct formation and illustrates the lifecycle; it does not establish prevalence, causality, or independent reproducibility'). Related work is external (OWASP, Agent Baseline, AEG) and the crosswalk is explicitly version-specific and non-load-bearing: 'The crosswalk used later in this paper is illustrative and version-specific; the APV lifecycle does not depend on Agent Baseline retaining its current structure.' Section 10 contains the paper's own limitation that effective authority 'can be difficult to enumerate when agents discover tools and credentials, invoke nested services, delegate to sub-agents, or change the environment during execution'; this is an acknowledged feasibility threat to applying the definition, not a circular step in which the definition presupposes its own conclusion. No self-citations appear, no uniqueness theorem is imported, and no known result is renamed as a derivation. The skeptical concern about undecidable reachability or unstable authority is a correctness or applicability risk, which the paper itself flags, and it does not constitute circularity under the stated criteria.
Assumptions & free parameters
assumptions (4)
- domain assumption Persistent composed exposures warrant a distinct vulnerability-management object separate from detections, incidents, and runtime authorization gaps.
- domain assumption A mandate can be assembled as an evidence-backed record from user instructions, tickets, policy, and exceptions, with supported/contradicted/unknown states.
- domain assumption Persistence, expected task class, consequential reach, and material evidence deficits can be assessed in practice well enough to classify a posture as an APV.
- ad hoc to paper Adopting APV records will improve ownership, deduplication, remediation, risk acceptance, and verified closure compared with alert-only handling.
invented entities (1)
-
Agentic posture vulnerability (APV)
Cite this review
Pith. "Pith review of The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents." pith.science (2026). https://pith.science/paper/ZZJ4WFFS
@misc{pith2026260805884,
author = {Pith},
title = {Pith review of: The Vulnerability With No CVE: Managing Persistent Gaps Between Mandate and Authority in AI Coding Agents},
year = {2026},
howpublished = {\url{https://pith.science/paper/ZZJ4WFFS}},
note = {Machine review of arXiv:2608.05884}
}
read the original abstract
Existing guidance identifies excessive agency, excessive permission, weak task-bound authorization, and inadequate agent controls as important risks. Control frameworks also describe capabilities for constraining, authorizing, observing, validating, and responding to agent activity. Yet security programs still need a way to manage persistent deployed instances that span components and outlive any one event. We propose the agentic posture vulnerability (APV) as a task-conditioned vulnerability-management abstraction: a durable record for a composed agent-control exposure. One posture may produce different runtime manifestations across tasks; APV links those manifestations to the invariant posture and remains open until authority is narrowed, a missing control is added, risk is accepted, or closure is verified. APV is not proposed as a new root-cause class of risk; it operationalizes existing excessive-agency, authorization, and control-composition weaknesses. We distinguish APVs from CVE-addressable product defects, OWASP Excessive Agency, Agent Baseline control outcomes, and the runtime authorization-execution gap. We then provide a field vignette, a thresholded definition, six recurring APV patterns, a vulnerability lifecycle, a minimum record, a control-and-closure matrix, tooling implications, and a testable research agenda.
Reference graph
Works this paper leans on
-
[1]
Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code
Anthropic . Permissive default allowlist enables unauthorized file read and network exfiltration in Claude Code . GitHub Security Advisory GHSA-x5gv-jw7f-j6xj, August 2025. URL https://github.com/anthropics/claude-code/security/advisories/GHSA-x5gv-jw7f-j6xj. CVE-2025-55284; affected versions before 1.0.4; patched in 1.0.4; accessed 2026-08-06
work page 2025
-
[2]
Accelerating the adoption of software and artificial intelligence agent identity and authorization
Harold Booth, William Fisher, Ryan Galluzzo, and Joshua Roberts. Accelerating the adoption of software and artificial intelligence agent identity and authorization. Initial public draft concept paper, National Institute of Standards & Technology , National Cybersecurity Center of Excellence, February 2026. URL https://csrc.nist.gov/pubs/other/2026/02/05/a...
work page 2026
-
[4]
CVE Program . CVE program glossary. https://www.cve.org/ResourcesSupport/Glossary, n.d. Accessed 2026-08-06
work page 2026
-
[5]
Agent baseline: Six security outcomes for safely building, deploying and operating AI agents
Ranti Familusi, Chris Huszcza, William Manning, Kamil Potrec, David Schott, and Jelmer Snoeck. Agent baseline: Six security outcomes for safely building, deploying and operating AI agents. https://agentbaseline.org/whitepaper.pdf, July 2026. Version 1.0-draft, published 2026-07-30; accessed 2026-08-06
work page 2026
-
[6]
Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey
L. Johnson, Kelley Dempsey, Ron Ross, Sarbari Gupta, and Dennis Bailey. Guide for security-focused configuration management of information systems. NIST Special Publication 800-128, National Institute of Standards & Technology , August 2011. URL https://csrc.nist.gov/pubs/sp/800/128/upd1/final. Includes updates as of 2019-10-10
work page 2011
-
[9]
OWASP Gen AI Security Project . LLM06:2025 Excessive Agency . https://genai.owasp.org/llmrisk/llm062025-excessive-agency/, 2025. Accessed 2026-08-06
work page 2025
-
[12]
Oleg Sheyner, Joshua W. Haines, Somesh Jha, Richard P. Lippmann, and Jeannette M. Wing. Automated generation and analysis of attack graphs. In Proceedings of the 2002 IEEE Symposium on Security and Privacy, pages 273--284, 2002. doi:10.1109/SECPRI.2002.1004377
arXiv 2002
-
[13]
Guide to enterprise patch management planning: Preventive maintenance for technology
Murugiah Souppaya and Karen Scarfone. Guide to enterprise patch management planning: Preventive maintenance for technology. NIST Special Publication 800-40 Revision 4, National Institute of Standards & Technology , April 2022. URL https://csrc.nist.gov/pubs/sp/800/40/r4/final
work page 2022
Show all 32 references
-
[16]
Poskitt, and Jun Sun
Haoyu Wang, Christopher M. Poskitt, and Jun Sun. AgentSpec : Customizable runtime enforcement for safe and reliable LLM agents. In Proceedings of the 48th IEEE/ACM International Conference on Software Engineering, 2026. URL https://arxiv.org/abs/2503.18666. Also available as a...
2026 arXiv
-
[19]
Cyber defense matrix
Sounil Yu. Cyber defense matrix. https://cyberdefensematrix.com/, n.d. Accessed 2026-08-06
2026
-
[20]
AI agent remote code execution
Zed Industries . AI agent remote code execution. GitHub Security Advisory GHSA-x34m-39xw-g2wr, August 2025. URL https://github.com/zed-industries/zed/security/advisories/GHSA-x34m-39xw-g2wr. CVE-2025-55012; affected versions before 0.197.3; patched in 0.197.3; accessed 2026-08-06
2025
-
[22]
, howpublished =
n.d. , howpublished =
-
[23]
2025 , howpublished =
2025
-
[24]
2026 , month = jul, howpublished =
Ranti Familusi and Chris Huszcza and William Manning and Kamil Potrec and David Schott and Jelmer Snoeck , title =. 2026 , month = jul, howpublished =
2026
-
[25]
2025 , month = aug, howpublished =
Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in. 2025 , month = aug, howpublished =
2025
-
[26]
2025 , month = aug, howpublished =
2025
-
[27]
2022 , month = apr, doi =
Murugiah Souppaya and Karen Scarfone , title =. 2022 , month = apr, doi =
2022
-
[28]
Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =
L. Johnson and Kelley Dempsey and Ron Ross and Sarbari Gupta and Dennis Bailey , title =. 2011 , month = aug, note =. doi:10.6028/NIST.SP.800-128 , url =
2011 doi
-
[29]
Haines and Somesh Jha and Richard P
Oleg Sheyner and Joshua W. Haines and Somesh Jha and Richard P. Lippmann and Jeannette M. Wing , title =. Proceedings of the 2002 IEEE Symposium on Security and Privacy , year =
2002
-
[30]
2026 , month = feb, type =
Harold Booth and William Fisher and Ryan Galluzzo and Joshua Roberts , title =. 2026 , month = feb, type =
2026
-
[31]
arXiv preprint arXiv:2501.09674 , year =
Tobin South and Samuele Marro and Thomas Hardjono and Robert Mahari and Cedric Deslandes Whitney and Dazza Greenwood and Alan Chan and Alex Pentland , title =. arXiv preprint arXiv:2501.09674 , year =
-
[32]
Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =
Reshabh K. Sharma and Linxi Jiang and Zhiqiang Lin and Shuo Chen , title =. arXiv preprint arXiv:2603.17170 , year =
-
[33]
arXiv preprint arXiv:2605.11003 , year =
Baoyuan Wu and Qingshan Liu and Adel Bibi and Irwin King and Siwei Lyu , title =. arXiv preprint arXiv:2605.11003 , year =
-
[34]
arXiv preprint arXiv:2605.18583 , year =
Yubin Qu and Ying Zhang and Yanjun Zhang and Gelei Deng and Yuekang Li and Leo Yu Zhang and Yi Liu , title =. arXiv preprint arXiv:2605.18583 , year =
-
[35]
arXiv preprint arXiv:2605.14859 , year =
Zheng Yan and Jingxiang Weng and Charles Chen and Dengyun Peng and Ethan Qin and Jiannan Guan and Jinhao Liu and Qiming Yu and Yixin Yuan and Fanqing Meng and Carl Che and Mengkang Hu , title =. arXiv preprint arXiv:2605.14859 , year =
-
[36]
Poskitt and Jun Sun , title =
Haoyu Wang and Christopher M. Poskitt and Jun Sun , title =. Proceedings of the 48th IEEE/ACM International Conference on Software Engineering , year =
-
[37]
arXiv preprint arXiv:2603.20953 , year =
Uchi Uchibeke , title =. arXiv preprint arXiv:2603.20953 , year =
-
[38]
Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =
Christoph B. Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering , year =. doi:10.1145/3808103 , publisher =
-
[39]
arXiv preprint arXiv:2603.16586 , year =
Maurits Kaptein and Vassilis-Javed Khan and Andriy Podstavnychy , title =. arXiv preprint arXiv:2603.16586 , year =
-
[40]
arXiv preprint arXiv:2606.22916 , year =
Genliang Zhu and Chu Wang , title =. arXiv preprint arXiv:2606.22916 , year =
-
[41]
arXiv preprint arXiv:2507.09329 , year =
Matous Kozak and Roshanak Zilouchian Moghaddam and Siva Sivaraman , title =. arXiv preprint arXiv:2507.09329 , year =
-
[42]
Sounil Yu , title =. n.d. , howpublished =
Reviewed August 7, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.