pith. sign in
Pith Number

pith:AVU7VU5Z

pith:2026:AVU7VU5ZLAEBPBVGCVRWBOJP7V
not attested not anchored not stored refs resolved

Tracking Capabilities for Safer Agents

Cao Nguyen Pham, Martin Odersky, Oliver Bra\v{c}evac, Yaoyu Zhao, Yichen Xu

AI agents can generate capability-safe code with no significant loss in task performance while the type system blocks leaks and side effects.

arxiv:2603.00991 v2 · 2026-03-01 · cs.AI · cs.PL

Add to your LaTeX paper
\usepackage{pith}
\pithnumber{AVU7VU5ZLAEBPBVGCVRWBOJP7V}

Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge

Record completeness

1 Bitcoin timestamp
2 Internet Archive
3 Author claim open · sign in to claim
4 Citations open
5 Replications open
Portable graph bundle live · download bundle · merged state
The bundle contains the canonical record plus signed events. A mirror can host it anywhere and recompute the same current state with the deterministic merge algorithm.

Claims

C1strongest claim

Our experiments show that agents can generate capability-safe code with no significant loss in task performance, while the type system reliably prevents unsafe behaviors such as information leakage and malicious side effects.

C2weakest assumption

That large language models can reliably produce correct, well-typed capability-safe Scala code for arbitrary tasks and that the capture-checking system covers all relevant safety properties for real-world tool use.

C3one line summary

AI agents can generate code in a capability-safe Scala dialect that statically prevents information leakage and malicious side effects while preserving task performance.

References

86 extracted · 86 resolved · 15 Pith anchors

[1] Amazon Web Services. 2025. Bedrock AgentCore policy. Accessed: 2025-06-01. https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/policy.htm l (cit. on p. 8) 2025
[2] Amazon Web Services. 2024. Cedar policy language. Accessed: 2025-06-01. https://www.cedarpolicy.com/ (cit. on p. 8) 2024
[3] Nada Amin, Samuel Grütter, Martin Odersky, Tiark Rompf, and Sandro Stucki
[4] InA List of Successes That Can Change the World(Lecture Notes in Computer Science) · doi:10.1007/978-3-319-30936-1_14
[5] Concrete Problems in AI Safety 2016 · arXiv:1606.06565

Formal links

2 machine-checked theorem links

Cited by

2 papers in Pith

Receipt and verification
First computed 2026-05-29T01:05:06.002593Z
Builder pith-number-builder-2026-05-17-v1
Signature Pith Ed25519 (pith-v1-2026-05) · public key
Schema pith-number/v1.0

Canonical hash

0569fad3b958081786a6156360b92ffd653d665f55c9c5b981f241537db931be

Aliases

arxiv: 2603.00991 · arxiv_version: 2603.00991v2 · doi: 10.48550/arxiv.2603.00991 · pith_short_12: AVU7VU5ZLAEB · pith_short_16: AVU7VU5ZLAEBPBVG · pith_short_8: AVU7VU5Z
Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/AVU7VU5ZLAEBPBVGCVRWBOJP7V \
  | jq -c '.canonical_record' \
  | python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 0569fad3b958081786a6156360b92ffd653d665f55c9c5b981f241537db931be
Canonical record JSON
{
  "metadata": {
    "abstract_canon_sha256": "266cf315043be1b306a934dbec5f5a625482f53b76e632685de57b404af56204",
    "cross_cats_sorted": [
      "cs.PL"
    ],
    "license": "http://creativecommons.org/licenses/by/4.0/",
    "primary_cat": "cs.AI",
    "submitted_at": "2026-03-01T08:39:37Z",
    "title_canon_sha256": "ca75e8f7641b32cc65ca0d137e97b5f5ef576666ac7f35c8594d1436fd6d9d1c"
  },
  "schema_version": "1.0",
  "source": {
    "id": "2603.00991",
    "kind": "arxiv",
    "version": 2
  }
}