Standing Framework

Research paper 27

Plugin Runtime Trust Boundaries for Governed Agent Systems

Tool-using agents are exposed to untrusted data, but plugin-enabled agent systems add another layer of risk: installable runtime surfaces. A plugin is not only a tool. It has package bytes, a manifest, worker entrypoints, UI launchers, secrets, host APIs, approval paths, compatibility rules, and rollout state. This paper studies Switchboard's plugin runtime trust boundaries as a governed-agent security architecture. The source threat-model refresh records enforced boundaries around reviewed artifact records, hosted package-byte agreement, rollout attestation, sandboxed iframe UI launchers, explicit secret references, and distinct-reviewer dual control for high-risk approvals. It also records open follow-through around immutable artifact distribution and broader fuzz coverage. The contribution is a trust-boundary model for plugin systems: artifact review, distribution, network, secret, UI, worker capability, approval, and compatibility boundaries must be represented separately and produce auditable denial evidence.

Paper
27
Authors
A.G. Mauro and C.A. Harris
Date
2026-07-19
Collection
Standing Framework Research

Abstract

Tool-using agents are exposed to untrusted data, but plugin-enabled agent systems add another layer of risk: installable runtime surfaces. A plugin is not only a tool. It has package bytes, a manifest, worker entrypoints, UI launchers, secrets, host APIs, approval paths, compatibility rules, and rollout state. This paper studies Switchboard's plugin runtime trust boundaries as a governed-agent security architecture. The source threat-model refresh records enforced boundaries around reviewed artifact records, hosted package-byte agreement, rollout attestation, sandboxed iframe UI launchers, explicit secret references, and distinct-reviewer dual control for high-risk approvals. It also records open follow-through around immutable artifact distribution and broader fuzz coverage. The contribution is a trust-boundary model for plugin systems: artifact review, distribution, network, secret, UI, worker capability, approval, and compatibility boundaries must be represented separately and produce auditable denial evidence.

← Back to research papers