Semantic policy enforcement for low-level CUA tools
Develop semantic security policies and the necessary supporting infrastructure for low-level Computer Use Agent tools such as click and find, enabling effective data-flow restrictions during plan execution; concretely specify mechanisms like planner-provided intent annotations on tool calls or website-provided metadata restricting permissible actions to make such policies enforceable.
References
Extending semantic policies to CUA tools remains an open research question that would require additional infrastructure such as planner-provided intent annotations on tool calls or website-provided metadata restricting permissible actions as is proposed by~\citet{meng2025cellmate}.
Proposition 2: early warning without the answer. Can routing information survive when the credited downstream rule language is absent from the policy centroid?