Runtime Governance of Agent Actions in Agentic AI: Design and Evaluation of a Governance Proxy
Large language model (LLM) agents increasingly interact with external tools, shared memory, and orchestration layers, shifting system risk from isolated model outputs to runtime action selection and execution. In such settings, static guardrails and post-hoc evaluation provide limited protection against indirect prompt injection, unsafe tool invocation, and behavioral drift across long-horizon workflows. This paper presents a Governance Proxy, a mediation layer for agentic AI orchestration positioned between agents and Model Context Protocol (MCP) servers. The proxy combines three control mechanisms: (a) capability boundaries that enforce least-privilege access to tools and parameter ranges, (b) a context-aware policy shield that can allow, block, rewrite, or escalate proposed actions, and (c) trust-aware routing that reduces autonomy when repeated violations or unstable behavior are detected. The contribution lies in integrating these mechanisms into a single middleware layer at the language-to-action boundary, rather than relying on model-internal safeguards alone. The paper formalizes the proxy design, describes its request-handling logic, and evaluates it in an MCP-mediated database management setting. The results indicate improved containment of unsafe tool-use behavior with moderate runtime overhead, highlighting the trade-off between agent autonomy and governed execution.
Fri 12 JunDisplayed time zone: London change
09:00 - 17:00 | Software Security Engineering WorkshopSSE-26 Workshop on Software Security Engineering at JMS 707 Chair(s): Mohammad Alshayeb King Fahd University of Petroleum & Minerals, Mahmood Niazi King Fahd University of Petroleum and Minerals | ||
09:00 15mDay opening | Welcome by the Organizers SSE-26 Workshop on Software Security Engineering | ||
09:15 15mTalk | A Multi-Agentic AI Pipeline for Iterative Vulnerability Detection and Auto-Remediation in Python SSE-26 Workshop on Software Security Engineering | ||
09:30 15mTalk | An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code SSE-26 Workshop on Software Security Engineering | ||
09:45 15mTalk | Symbolic Execution Meets Multi-LLM Orchestration: Detecting Memory Vulnerabilities in Incomplete Rust CVE Snippets SSE-26 Workshop on Software Security Engineering | ||
10:00 15mTalk | Low-Code Paradox in DevOps: Security and Governance Insights from Practitioners SSE-26 Workshop on Software Security Engineering Muhammad Azeem Akbar LUT University, Saima Rafi Edinburgh Napier University, Arif Ali Khan University of Oulu | ||
10:15 15mTalk | An Empirical Study of Challenges for Developing Global Cybersecurity Culture SSE-26 Workshop on Software Security Engineering Nisar Muhammad , Siffat Ullah Khan University of Malakand, Mahmood Niazi King Fahd University of Petroleum and Minerals, Mohammad Shameem | ||
10:30 30mBreak | Coffee Break SSE-26 Workshop on Software Security Engineering | ||
11:00 15mTalk | Pick and Sort for Graphical Authentication SSE-26 Workshop on Software Security Engineering Argianto Rahartomo TU Clausthal, Amirhossein Jamshidipoor , Mohammad Ghafari Tehran Institute for Advanced Studies (TEIAS) | ||
11:15 15mTalk | Runtime Governance of Agent Actions in Agentic AI: Design and Evaluation of a Governance Proxy SSE-26 Workshop on Software Security Engineering Petru-Liviu Bouruc , Ciprian Păduraru University of Bucharest, Alin Stefanescu The Institute for Logic and Data Science (ILDS), and University of Bucharest | ||
11:30 15mTalk | Empirical Evaluation of TLS Communication Overhead in Federated Learning Systems SSE-26 Workshop on Software Security Engineering | ||
11:45 15mTalk | Understanding Security Issues in Open-Source Agentic AI Frameworks: An Empirical Analysis SSE-26 Workshop on Software Security Engineering Muhammad Hamza Lappeenranta-Lahti University of Technology (LUT), Muhammad Azeem Akbar LUT University, Wardah Naeem Awan LUT University, Muhammad Shoaib | ||