Behavioral Firewalls for AI Agents: Compiling Tool-Call Telemetry into a Finite Automaton
LLM agents invoke external services through tool-call protocols like MCP. Today's firewalls intercept these calls, validate schemas, and scan signatures. Each call is judged alone. The paper challenges that assumption. An adversary injecting instruct