SEAD: SAGE defender cuts tool-agent attack success from 48% to 4% against DART attacks

Xinjie Shen · hf · 2026-09-30

SEAD formalizes attack and defense for tool-using agents as partially observed state control: earlier actions can alter files, permissions, or database state, making later routine-looking actions harmful in ways the visible interaction doesn't reveal.

Code and data: https://github.com/EverywhereSafety/SEAD

Original post →

More from coding & agent

coding & agent channel →