ActGuard: Pre-execution Action Auditing Against Indirect Prompt Injection in LLM Agents
A new arXiv paper proposes ActGuard, a defense that audits an LLM agent's planned tool calls before they are executed. The approach targets indirect prompt injection, where malicious instructions hidden in tool outputs can hijack an agent's behavior. The authors position it as an alternative to existing defenses such as prompt hardening and content filtering.