Where Is the Tradeoff in Using Third-Party API Routers for Agentic Software Development?
cs.SE, cs.AI, cs.CL
Submitted: 2026-07-26
Updated: 2026-09-05
Code: https://github.com/Riyasushin/SIDEL
License: http://creativecommons.org/licenses/by/4.0/
The gist: Third-party API routers have become a common layer that unifies access across increasingly diverse LLM providers.
Terminology
Abstract
Third-party API routers have become a common layer that unifies access across increasingly diverse LLM providers. In coding-agent workflows, high-autonomy operation is widely adopted because it reduces interaction overhead. As a result, a third-party API router, which sits between the agent and the upstream provider, inevitably occupies the trusted path. It can inspect and modify every request and response, yet no mechanism verifies alignment between the provider's output and the repository-level actions ultimately executed by the agent. Consequently, client-side permission mechanisms may become ineffective in practice. Whether this control gap produces real, hard-to-detect effects on software development tasks remains empirically unmeasured. In this paper, we conduct an empirical study of router-side injection in coding agents, examining four intervention levels of increasing subtlety: Response Substitution (L1), Response Append (L2), LLM-Polished Injection (L3), and LLM-Polished with Distribution Alignment Injection (L4). Moreover, we develop SIDEL, a framework for trace recording, replay, injection, and defense evaluation, with a curated dataset of 400 samples. We evaluate four representative coding agents, and further evaluate whitelist-based execution control and LLM review. Router-side intervention substantially alters repository-level actions and remains difficult for existing client-side safeguards to detect. Without additional mitigations, all evaluated agents achieved a defense success rate of 0 percent across all injection levels. Client-side mitigations and reactive reviews improve resistance but do not fully restore end-to-end control, motivating provider-side output-integrity guarantees. Our code is available at https://github.com/Riyasushin/SIDEL.
Sources
- Understanding Software Engineering Agents: A Study of Thought-Action-Result Trajectories
- You Name It, I Run It: An LLM Agent to Execute Tests of Arbitrary Projects
- SoK: The Attack Surface of Agentic AI - Tools and Autonomy
- DeltaBox: Scaling Stateful AI Agents with Millisecond-Level Sandbox Checkpoint/Rollback
- Beyond Data Privacy: New Privacy Risks for Large Language Models
- Auditing MCP Servers for Over-Privileged Tool Capabilities
- SWE-bench: Can Language Models Resolve Real-World GitHub Issues?
- The Attack and Defense Landscape of Agentic AI: A Comprehensive Survey
- Why AI Agents Still Need You: Findings from Developer-Agent Collaborations in the Wild
- AgentCanary: A Security Evaluation Framework for Autonomous AI Agents in Real Executable Environments
- Life-Cycle Routing Vulnerabilities of LLM Router
- SafeHarness: Lifecycle-Integrated Security Architecture for LLM-based Agent Deployment
- Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
- Dive into Claude Code: The Design Space of Today's and Future AI Agent Systems
- Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents
- ToolSafe: Enhancing Tool Invocation Safety of LLM-based agents via Proactive Step-level Guardrail and Feedback
- Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
- Prompt Injection Attack to Tool Selection in LLM Agents
- Human-In-the-Loop Software Development Agents
- Authorization Propagation in Multi-Agent AI Systems: Identity Governance as Infrastructure
Related papers
- Falsification-Based Verification of LLM-Generated Optimization Models: Sound Test Batteries and Their Detection Limits
- GitSkills: A Dataset of Agent Skills on GitHub
- SABER: Benchmarking Operational Safety of LLM Coding Agents in Stateful Project Workspaces
- PackMonitor: Enabling Zero Package Hallucinations Through Decoding-Time Monitoring
- IntentCoding: Amplifying User Intent in Code Generation
- Incentives and Outcomes in Bug Bounties