# Two Papers Warn That Safe LLMs Do Not Compose Into Safe Multi-Agent Systems

ChannelGuard shows every hop between agents is an unmonitored injection channel, while ChainWatch proposes kill-chain-aligned detection for attacks on Model Context Protocol (MCP) tool systems.

- Published: 2026-07-23T05:46:05.758Z
- Canonical: https://polylog.news/ai/2026-07-23/two-papers-warn-that-safe-llms-do-not-compose-into-safe-mult
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [arXiv cs.CR (ChannelGuard)](https://arxiv.org/abs/2607.19430), [arXiv cs.CR (ChainWatch)](https://arxiv.org/abs/2607.19432)

Two security papers converge on the same weakness in agent architectures. ChannelGuard argues that safe models do not compose into safe multi-agent systems. A pipeline of planner, worker agents, verifier, and synthesizer creates an unmonito…

This story is for subscribers. Read it in full at https://polylog.news/ai/2026-07-23/two-papers-warn-that-safe-llms-do-not-compose-into-safe-mult (subscription information: https://polylog.news/pricing).