Back to today's list

Agent libOS: A Runtime Substrate for Capability-Controlled Self-Evolving LLM Agents

Yingqi Zhang

Published Aug 19, 2026Featured #4In the daily list Jun 4, 2026
Daily score71.5
Editorial review7.5
Relevance0.460
Freshness0.722

Why It Matters

What makes this one worth your time

As LLMs evolve into more complex agents, a structured runtime like Agent libOS is crucial for ensuring safety, accountability, and effective resource management.

Agent libOS enables robust, capability-controlled execution for long-running LLM agents.

Summary

The paper introduces Agent libOS, a runtime environment designed for long-running LLM agents that allows for state maintenance, task forking, and human interaction, while implementing strict capability controls and auditing mechanisms.

Key contributions

  • Introduction of a library-OS-inspired runtime for LLM agents.
  • Implementation of a prototype featuring async scheduling and capability checks.
  • Development of a safety-oriented evaluation framework for long-running agent processes.

Notable insights

  • The design emphasizes explicit capability boundaries to enhance security and control over agent actions.
  • The integration of human approval and auditing mechanisms addresses critical concerns in deploying LLM agents in real-world applications.

Possible limitations

  • Not stated in the abstract.

Abstract

arXiv:2606.03895v3 Announce Type: replace-cross Abstract: Large language model (LLM) agents can persist across tasks, acquire memory, activate Skills, synthesize tools, fork child processes, attach remote resources, and commit checkpoints as reusable images. These mechanisms expand the action surface after deployment and create authority-escalation and data-exfiltration risks when visibility is mistaken for permission. We present Agent libOS, an agent-native library OS substrate that separates three planes. Operation admission combines process identity, Task Authority ceilings, typed Capabilities, policy or Human approval, budgets, and concrete primitives. Information-flow admission propagates labels and immutable source references, resolves Host-registered Sinks, and requires an exact one-shot Human release for conditional high-sensitivity egress. Durable causal evidence records intent, outcomes, accounting, and causal links but never grants authority. Thus, the model-visible action surface may evolve without implicitly expanding resource authority or permitted information flows. The implementation provides persistent processes, Object Memory, Skills, syscall-mediated JIT Tools, images and checkpoints, typed providers, Human queues, budgets, and durable recovery. Provider-backed effects use a prepare-dispatch-settle protocol that exposes ambiguity and prevents blind replay. In source-bound evaluation, 33/33 deterministic full-runtime tasks pass both task and safety oracles. Across 12 canonical real-model runs, observed safety and strict utility are 12/12. In a paired 30-run Skill projection study, the observable-state oracle passes in all runs, with 13/15 fully correct runs in each arm. These results describe the evaluated model/provider configuration. Agent libOS does not prevent prompt injection, provide kernel-grade sandboxing, or roll back irreversible external effects.