CAVA and PCAA are entering the research conversation.
Two independent agent-security preprints cite our work on action identity and approval binding. A small milestone worth celebrating, with the sources in full view.
Two independent agent-security preprints cite our work on action identity and approval binding. A small milestone worth celebrating, with the sources in full view.

Two independent research teams have cited CAVA and PCAA in new papers on agent security. For a small team building in public, seeing other researchers engage with the work is a milestone worth pausing for.
We started with a practical question: when someone approves an agent action, what exactly have they approved? A tool name is often too broad. A command string may omit context. A log produced afterward cannot, by itself, establish that the action stayed within its authority.
PCAA develops proof-carrying action governance. CAVA addresses canonical action identity across heterogeneous runtimes. They are part of the research behind OSuite. It is encouraging to see these questions being examined independently, with other researchers bringing their own mechanisms and tests.
In When Valid Tool Calls Change Meaning: Formation-Consistent Dispatch for LLM Agents, Geonwoo Kim and Brent ByungHoon Kang of KAIST investigate a subtle failure: a tool call can remain valid while the implementation that gives it meaning changes.
Their Formation-Consistent Dispatch approach retains the interpreters authorized to give that action meaning. Section VIII-B places CAVA among related work on isolation, provenance and runtime action binding:
Isolation and provenance systems mediate components or bind runtime actions [56, 57, 58, 59, 60, 61]. FCD retains the interpreters authorized to give that action meaning.
CAVA is reference [60] in that group. The distinction matters: preserving an action's identity and preserving the interpreter that gives it meaning are related, but not interchangeable, problems.
Agent Approval Laundering: Transitive Effects Beyond the Approved Invocation comes from authors affiliated with the Chinese Academy of Sciences, the University of Chinese Academy of Sciences, Beihang University and Beijing University of Posts and Telecommunications.
The paper examines what an approved invocation activates downstream. Approving a package-manager command, for example, is not necessarily the same as approving every script or side effect it triggers. In Related Work, the authors write:
Proof-Carrying Agent Actions and CAVA bind action identity, receipts, canonicalization, and attestation [16, 17]
They then distinguish that work from their closure-bound approval approach, which measures coverage between the decision-time approval object and the invocation's execution closure. That is a useful distinction for anyone building controls around real developer tools.
CAVA appears in both papers; PCAA appears in the approval-laundering paper. Both sources are arXiv preprints, and the links above preserve the v1 manuscripts we checked. Their citations are not evidence that either team has deployed or evaluated OSuite, nor do they imply a partnership or institutional endorsement.
What they do show is that our published work is becoming part of an independent technical discussion. For us, that is the point of publishing: make an idea precise enough that someone else can locate it, distinguish it from their own contribution, and take the problem further.
Thank you to the authors for engaging with the work. We will keep publishing the mechanisms, the evidence and the limits. The next milestone is not a bigger claim. It is a better answer to what happens between approval and execution.
[Explore the citation record and our research library](/research#citations).
Request enterprise access and send your first governed decision today.