Research

Research seriesL3data science

The Static-Analysis Confidence Gap in AI-Agent Software

Static analysis can find real defects in an agent's software substrate, but a clean report cannot prove that model-mediated intent, framework semantics, delegated authority, and multi-step behavior are secure. This series measures that boundary and develops an honest assurance envelope for reporting what was checked, what was missed, and what remains unknown.

Murali Chillakuru·10 articles
  1. 1
    What a Clean Static-Analysis Report Actually Proves

    A report with no findings is evidence about a bounded search, not a certificate of safety — and for AI-agent software that boundary is unusually narrow.

  2. 2
    Measuring Static Analysis on AI-Agent Vulnerabilitiesplanned
  3. 3
    The Agent-Framework Modeling Gapplanned
  4. 4
    Model-Mediated Taint Trackingplanned
  5. 5
    Modeling Agent-Specific Sources, Sinks, and Trust Boundariesplanned
  6. 6
    False Positives and Function-Breaking Remediationplanned
  7. 7
    Agentic Risks Beyond Source-to-Sink Analysisplanned
  8. 8
    When Safe Operations Compose into an Unsafe Planplanned
  9. 9
    Static Analysis as a Gate for AI-Generated Codeplanned
  10. 10
    An Honest Assurance Report for Agent Softwareplanned