Loopjacking: Hijacking Human-in-the-Loop Approval
4.40T1 sourcearXiv cs.MA
Source record
Published by arXiv cs.MA (T1 source). The original is at https://arxiv.org/abs/2609.21081.
Pipeline notes
The summary and note below are generated by the signal pipeline — they are Beyond Desk’s reading, not quotations from the source.
SummaryResearch paper defining 'Loopjacking': attacks where a human's approval for operation A is bound to a different operation B in AI agent systems. Authors reproduce post-approval state substitution in Agno AgentOS (versions up to 3.0.9) and LangGraph Agent Server (up to 0.14.0), and representation mismatch in OpenClaw. OpenAI Agents SDK serves as a negative control. Mitigations: canonical approval rendering and use-time comparison.
Why it mattersAnyone building human-in-the-loop agent workflows needs to know that several released agent frameworks fail to bind approval to the exact operation later executed. Specific vulnerable framework versions and the proposed mitigations are directly actionable for tool selection and security review.
Cited by
No citations on record.
