Structured Database Tools for Agents: Security Gains, Utility Costs, and Residual Inference Channels
Dipankar Sarkar
Abstract
Language-model database agents often execute model-authored SQL, which exposes a broad security surface. We evaluate a structured alternative in which the agent calls typed ORM tools whose arguments are policy-checked and compiled to parameterised queries. AgentDB-Sec pairs a multi-tenant probe database, ten canonical attacks, a 28-task benign suite with independently computed gold answers, and a multi-turn injection harness, across ten hosted models. Scored for value-oracle attack success, structured mediation takes our deterministic matrix from $9/10$ to $1/10$; under property-aware scoring that additionally counts non-verbatim inference, it goes from $10/10$ to $3/10$, because a policy can mask a field and still permit aggregating, filtering and ordering over it. That residue is a genuine inference channel. Under repeated sampling, models exploit it at rates from 0 to 0.90 under one identical policy, and the spread is explained almost entirely by whether a model selects the disclosing aggregation affordance. Confining computation to readable fields closes the channel under both scorings, with a model-clustered 95% interval that bounds any accuracy loss to about 1.4 percentage points. Mediation itself is not cheap: accuracy on our suite falls from 100% to 55%, decomposing into policy-mandated refusals, joins the typed DSL cannot express, and a 22-point deficit on otherwise-permitted tasks caused by malformed tool calls and wrong answers rather than by the security policy. We also show that a retired endpoint, a rate limit or a malformed call is easily mis-scored as a safety success unless evaluations report how many attempts reached the mechanism under test. Structured mediation removes important attack classes, but confidentiality requires constraining computation as well as visibility.
Chat is not available.
Successful Page Load