Research paper 27
Plugin Runtime Trust Boundaries for Governed Agent Systems
Tool-using agents are exposed to untrusted data, but plugin-enabled agent systems add another layer of risk: installable runtime surfaces. A plugin is not only a tool. It has package bytes, a manifest, worker entrypoints, UI launchers, secrets, host APIs, approval paths, compatibility rules, and rollout state. This paper studies Switchboard's plugin runtime trust boundaries as a governed-agent security architecture. The source threat-model refresh records enforced boundaries around reviewed artifact records, hosted package-byte agreement, rollout attestation, sandboxed iframe UI launchers, explicit secret references, and distinct-reviewer dual control for high-risk approvals. It also records open follow-through around immutable artifact distribution and broader fuzz coverage. The contribution is a trust-boundary model for plugin systems: artifact review, distribution, network, secret, UI, worker capability, approval, and compatibility boundaries must be represented separately and produce auditable denial evidence.
- Paper
- 27
- Authors
- A.G. Mauro and C.A. Harris
- Date
- 2026-07-19
- Collection
- Standing Framework Research
Abstract
Tool-using agents are exposed to untrusted data, but plugin-enabled agent systems add another layer of risk: installable runtime surfaces. A plugin is not only a tool. It has package bytes, a manifest, worker entrypoints, UI launchers, secrets, host APIs, approval paths, compatibility rules, and rollout state. This paper studies Switchboard's plugin runtime trust boundaries as a governed-agent security architecture. The source threat-model refresh records enforced boundaries around reviewed artifact records, hosted package-byte agreement, rollout attestation, sandboxed iframe UI launchers, explicit secret references, and distinct-reviewer dual control for high-risk approvals. It also records open follow-through around immutable artifact distribution and broader fuzz coverage. The contribution is a trust-boundary model for plugin systems: artifact review, distribution, network, secret, UI, worker capability, approval, and compatibility boundaries must be represented separately and produce auditable denial evidence.
← Back to research papers