Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents

Large language model (LLM)-based agents increasingly connect model-generated decisions to security-sensitive software capabilities, including command execution, filesystem access, network communication, browser control, and external tools. Existing analyses often use predefined sensitive operations to anchor their analysis, but operation identity alone is insufficient to determine the security implications of an agent behavior. We present AgentSecGraph, a security-aware static analysis framework that constructs a candidate-centered Security-Aware Agent Dependency Graph (Security-ADG) for each security-sensitive operation. The representation augments operation identity with agent relevance, source and dependency evidence, trust-boundary context, guard evidence, and external-effect semantics. We further introduce AgentSecBench, a reproducible corpus of 67 real-world LLM-agent repositories spanning 11 agent ecosystems and 37,542 source files. Applying the current analyzer to all frozen repositories yields 23,866 static security-sensitive operation candidates across 65 repositories, for which AgentSecGraph emits 23,866 candidate-centered Security-ADG artifacts without reported construction failures. Corpus-wide analysis recovers source-to-operation dependency evidence for 9,821 candidates (41.15%) and potential guard evidence for 3,075 (12.88%). The complete analysis finishes in 50.8 minutes. Using a separate reproduction-backed evaluation layer, we establish a conservative reference set of 22 security-sensitive behaviors across 13 repositories: one confirmed vulnerability, one pending disclosure candidate, and 20 guarded behaviors that do not meet the vulnerability criteria. In a held-out representation study, Security-ADG preserves 91.1% of the reference context and all five observed guards, compared with 20.0% for a sink-only view and 40.0% for a simplified ADG. These results show that security-aware dependency and contextual evidence enable distinctions that cannot be recovered from sensitive-operation identity alone.

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-30
DOI
https://doi.org/10.5281/zenodo.23066368
Primary Topic
Software System Performance and Reliability
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents

hang cui
Zenodo (CERN European Organization for Nuclear Research)
Software System Performance and Reliability
preprint

Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents

hang cui
preprint en

Abstract

Large language model (LLM)-based agents increasingly connect model-generated decisions to security-sensitive software capabilities, including command execution, filesystem access, network communication, browser control, and external tools. Existing analyses often use predefined sensitive operations to anchor their analysis, but operation identity alone is insufficient to determine the security implications of an agent behavior. We present AgentSecGraph, a security-aware static analysis framework that constructs a candidate-centered Security-Aware Agent Dependency Graph (Security-ADG) for each security-sensitive operation. The representation augments operation identity with agent relevance, source and dependency evidence, trust-boundary context, guard evidence, and external-effect semantics. We further introduce AgentSecBench, a reproducible corpus of 67 real-world LLM-agent repositories spanning 11 agent ecosystems and 37,542 source files. Applying the current analyzer to all frozen repositories yields 23,866 static security-sensitive operation candidates across 65 repositories, for which AgentSecGraph emits 23,866 candidate-centered Security-ADG artifacts without reported construction failures. Corpus-wide analysis recovers source-to-operation dependency evidence for 9,821 candidates (41.15%) and potential guard evidence for 3,075 (12.88%). The complete analysis finishes in 50.8 minutes. Using a separate reproduction-backed evaluation layer, we establish a conservative reference set of 22 security-sensitive behaviors across 13 repositories: one confirmed vulnerability, one pending disclosure candidate, and 20 guarded behaviors that do not meet the vulnerability criteria. In a held-out representation study, Security-ADG preserves 91.1% of the reference context and all five observed guards, compared with 20.0% for a sink-only view and 40.0% for a simplified ADG. These results show that security-aware dependency and contextual evidence enable distinctions that cannot be recovered from sensitive-operation identity alone.

Zenodo (CERN European Organization for Nuclear Research)
University of Chinese Academy of Sciences (CN)
Software System Performance and Reliability
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents — hang cui · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS