🤖 AI Summary
This work addresses the lack of a unified language-level abstraction for key agent behaviors—such as model invocation, tool usage, memory access, and strategic decision-making—which hinders static guarantees for authorization, auditing, and security in existing agent systems. To bridge this gap, the paper introduces ETAS, a novel effect-typed language that treats agent behavior components (e.g., prompts, tool calls, policies) as first-class semantic objects, cleanly separating deterministic computation from non-deterministic actions. ETAS features a dual-indexed type system that statically tracks escaping effects and execution traces. The core contributions include the first integration of agent-centric constructs into language semantics, compile-time policy verification coupled with runtime obligation enforcement, formal proofs of type soundness, trace transparency, and policy safety, and a complete Rust-based toolchain supporting type checking, policy diagnostics, and auditable execution.
📝 Abstract
ETAS is a programming language for agent systems that treats model-backed agents, tool calls, prompts, typed memory, human approvals, policies, and execution traces as semantic program elements rather than library conventions. It separates deterministic computation from agentic nondeterminism and externally visible actions while preserving a direct programming style.
We present the core design of ETAS. Its static semantics assigns ordinary types through spec conformance and tracks each computation with two behavioral indices: an escaping effect row and a persistent abstraction of the typed action trace it may request. Specs form a terminating compile-time constraint calculus: type specs provide evidence for polymorphism and resource facts, callable specs constrain function and stage shapes, and trace specs express allow, deny, and temporal constraints. Typing checks requested traces against compiled monitors and emits residual obligations when dynamic resources preclude a complete static proof. The dynamic semantics distinguish requested, handled, denied, and committed events; handlers interpret typed actions without making their requests invisible to authorization or audit.
We formalize a core calculus and state preservation, progress, type/effect soundness, handler trace-transparency, and policy safety. We also implement ETAS in Rust with a command-line interface, typed HIR checks, effect and policy diagnostics, handler checks, and trace-aware execution hooks. ETAS provides a programming-language foundation for reasoning about authorization, nondeterminism, recovery, and audit evidence before and during agent execution.