← All parts of this equation

Equation 2 · Part 3 · Ten Failure Modes in Agentic Coding, from Prompt Injection to False Completion

Symbol L

Risk⁡(a)=P(unsafe proposal)⋅P(authorization∣proposal)⋅P(escape detection)⋅L(a),\operatorname{Risk}(a)= P(\text{unsafe proposal}) \cdot P(\text{authorization}\mid\text{proposal}) \cdot P(\text{escape detection}) \cdot L(a),
LL

What this part means

consequence.

Its job in the formula

L is one factor in the product that computes the quantity on the left.

Where the article explains it

where L(a) is consequence.

The passage around this formula

The risk of an action a is not reducible to model error probability. A simple decomposition is Risk⁡(a)=P(unsafe proposal)⋅P(authorization∣proposal)⋅P(escape detection)⋅L(a)\operatorname{Risk}(a)= P(\text{unsafe proposal}) \cdot P(\text{authorization}\mid\text{proposal}) \cdot P(\text{escape detection}) \cdot L(a). where L(a) is consequence. Better models can reduce the first factor. Sandboxes, permission policy, independent evaluators, and staged execution reduce the others. Security architecture should assume every factor is nonzero.

Read this part in the article →

Learn the underlying idea

A function assigns an output to each allowed input. The expression f(x) means “apply f to x”.

Open the illustrated functions: inputs become outputs guide →

See this notation across published equations →

Sources cited in the article section

These citations provide research context; check each source for the exact claim it supports.