Beyond Predefined Sinks: Security-Aware Dependency Analysis for LLM Agents
Large language model (LLM)-based agents increasingly connect model-generated decisions to security-sensitive software capabilities, including command execution, filesystem access, network communication, browser control, and external tools. Existing analyses often use predefined sensitive operations to anchor their analysis, but operation identity alone is insufficient to determine the security implications of an agent behavior. We present AgentSecGraph, a security-aware static analysis framework that constructs a candidate-centered Security-Aware Agent Dependency Graph (Security-ADG) for each security-sensitive operation. The representation augments operation identity with agent relevance, source and dependency evidence, trust-boundary context, guard evidence, and external-effect semantics. We further introduce AgentSecBench, a reproducible corpus of 67 real-world LLM-agent repositories spanning 11 agent ecosystems and 37,542 source files. Applying the current analyzer to all frozen repositories yields 23,866 static security-sensitive operation candidates across 65 repositories, for which AgentSecGraph emits 23,866 candidate-centered Security-ADG artifacts without reported construction failures. Corpus-wide analysis recovers source-to-operation dependency evidence for 9,821 candidates (41.15%) and potential guard evidence for 3,075 (12.88%). The complete analysis finishes in 50.8 minutes. Using a separate reproduction-backed evaluation layer, we establish a conservative reference set of 22 security-sensitive behaviors across 13 repositories: one confirmed vulnerability, one pending disclosure candidate, and 20 guarded behaviors that do not meet the vulnerability criteria. In a held-out representation study, Security-ADG preserves 91.1% of the reference context and all five observed guards, compared with 20.0% for a sink-only view and 40.0% for a simplified ADG. These results show that security-aware dependency and contextual evidence enable distinctions that cannot be recovered from sensitive-operation identity alone.
Authors
- hang cui (ORCID: https://orcid.org/0009-0002-2315-2456)
Institutions
- University of Chinese Academy of Sciences (CN)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-30
- DOI
- https://doi.org/10.5281/zenodo.23066368
- Primary Topic
- Software System Performance and Reliability
- Type
- preprint