Coding-agent approvals can authorize actions different from those executed

A controlled study identifies six ways Claude Code can lose the binding between an approved action and its eventual execution.

Top University
Yang Wang

Fudan University

Research Digest··3 min read
Wang tests whether an AI coding harness executes precisely the action covered by a human approval, rather than merely presenting an approval checkpoint.

The author defines Approval Laundering as the silent substitution of an executed action for the action authorized under the harness's stated approval policy.

Why this paper

From Fudan University

In one line

AI coding-agent approvals can diverge from execution through six binding failures, while cryptographic tokens stop only divergences visible at dispatch.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ✓Limitations stated by the authors (2 noted)
  • ·No benchmark numbers found

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.