Searcharxiv⌕ Search

arXiv · 2609.35659

Tracekit: Tamper-Evident Intent-Reasoning-Action Auditing for Autonomous Coding Agents

Abstract

Autonomous coding agents read untrusted files, run shell commands and spawn sub-agents with little supervision, yet their record is usually an editable log. We present Tracekit, an open-source, dependency-free system that captures three channels for every agent session: what the human asked (intent), what the model said of its reasoning (self-report), and what it actually executed (actions). These are written to a hash-chained, externally anchorable ledger and cross-checked. Tracekit hooks into Claude Code's lifecycle events, reconstructs multi-agent hierarchies, gates tool calls with a pre-execution policy, accepts events from other agents via an SDK or HTTP API, and renders a live observer that re-verifies the ledger in the browser. We evaluate Tracekit in five experiments. (1) Across 1,600 random mutations, the chain detects every edit, deletion, reordering, forged insertion and torn write; tail truncation and full re-chaining are caught only by anchors, with detection falling to 0.47 at an anchoring interval of 300 records, matching a closed-form model. (2) A hook costs 23.9 ms median, flat up to 100,000 ledger records, and the chain stays correct under 16 concurrent writers. (3) A regular-expression gate blocks only 18 of 44 harmful tool calls (41%) while wrongly blocking 3 of 40 benign ones; trivial rewrites evade it. (4) In 14 real Claude Code runs, the agent never acted on four planted indirect prompt injections and disclosed each. The provider withheld the text of all 27 thinking blocks, so self-report was limited to visible prose. (5) With seeded-fault splicing, a new method that inserts concealed misaligned steps into real traces, over 63 traces and 126 reviewer calls, rule flags caught 40/49 (82%) of faulted traces and an independent LLM reviewer caught 98/98 (100%), with a false-positive rate of 1/14 on unmodified traces. We release the system, harness and all traces.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Bravish Ghosh. 2026-09-28. Tracekit: Tamper-Evident Intent-Reasoning-Action Auditing for Autonomous Coding Agents. https://arxiv.org/abs/2609.35659

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

From Word Counts to Context: Topic Models for Asset Pricing

News may reveal systematic risk, but whether its context enhances the construction of systematic risk factors is still unclear. We seek to test whether utilizing a sentence transformer represents an improvement over techniques such as Latent Dirichlet Allocation (LDA) in the coherence of topic term lists generated from unstructured text data. To test this, the same collection of unstructured text data comprising of 394,661 articles and the same downstream financial portfolio construction pipeline were applied with the text layer differing, including the length of article text each model used and how topic terms were ranked: we benchmark LDA against a frozen sentence transformer with k-means clustering. We find that the sentence transformer branch had higher observed scores both in terms of coherence (measured by NPMI) as well as financial performance (measured by Sharpe), although the available tests do not establish outperformance. Further exploratory specifications such as utilizing spherical clustering and multi-horizon exposures had an observed excess-return Sharpe of 1.03 for the combined model. We believe that there is some promise in applying context-aware techniques on unstructured news text, but stricter tests using only information available at each date and broader datasets may be required to enhance the confidence in the observed performance.

cs.CE↗

A Comparative Study on Robust Topology Optimization of Design-Dependent Pressure-Actuated Compliant Mechanisms with Quadrilateral Elements

This paper presents a comparative study of compliant mechanisms generated using a robust topology optimization technique involving design-dependent pressure loads. Design domains are parameterized using standard and higher-order quadrilateral elements. Both eroded and blueprint configurations are considered. A min-max optimization model combined with an output-spring method is employed to extremize the mechanisms' output displacements. A volume and a strain energy constraint are applied to the blueprint and the eroded designs, respectively. The optimization process is executed using the method of moving asymptotes. Numerical experiments are performed to optimize the pressure-actuated inverter and gripper mechanisms using Q4, Q8, and Q9 elements, and the results are compared. The research highlights how quadrilateral element selection influences both the resulting topologies and performance characteristics.

cs.CE↗

Construction-Reuse Trade-offs for Exact Certificates in Fixed-Rank Threshold Screening

Repeated threshold queries may reuse selected identities without reusing stale reports, but cheaper certificates need not shorten the complete response. We study selected-lower, atomic-upper (SLA) certificates for fixed-rank conjunctive screening with explicit missing-information semantics. An endpoint characterization and a counterexample separate same-source containment from policy-dependent online behavior. The original 320-session experiment reduces summed construction medians by 31.18% against an exclusion-cover certificate, yet its Cover/SLA full-API geometric time ratio is 0.9682 (95% conditional blocked interval 0.9593-0.9769), and SLA takes 12.94% more summed time than uncached Bitmap. Three separately launched complete repeats preserve this adverse ordering, with Cover/SLA ratios of 0.9665-0.9718. An additional 720-configuration exploration varies catalogue size, construction period, requested count and query locality on empirically resampled tables. SLA is faster in 295 configurations against Cover and 271 against Bitmap, descriptive counts that do not establish universal superiority. Separately instrumented additive costs distinguish construction savings from retrieval and report costs. A plane-stress component case adds an independent analytical displacement check and 4,608 boundary-challenging queries: five implementations agree exactly, while medium- and fine-mesh selections differ at 459 positions. A state-stratified public bolt-record exercise preserves 185 incomplete positions among 1,479 requests. Raw timings, complete configuration results and a tested clean-environment package support reproducibility. The SLA construction was explored and refined through the self-evolving AI system ZiYor; the named authors specified, implemented and evaluated it. This is a bounded mechanics-to-query study, not physical joint qualification or universal speedup.

cs.CE↗