Beyond the Payload: How User Invocation Shapes Coding Agent Vulnerability to Repository Poisoning
cs.CR, cs.CL
Submitted: 2026-08-31
Updated: 2026-08-31
Comments: 30 pages,7 figures, Accepted to EMNLP 2026 Main Conference
Code: https://github.com/StarConnor/CIPR
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- When Prompt Under-Specification Improves Code Correctness: An Exploratory Study of Prompt Wording and Structure Effects on LLM-Based Code Generation
- Securing AI Agents with Information-Flow Control
- How to Prompt? Opportunities and Challenges of Zero- and Few-Shot Learning for Human-AI Interaction in Creative Applications of Generative Models
- Defeating Prompt Injections by Design
- When Prompts Go Wrong: Evaluating Code Model Robustness to Ambiguous, Contradictory, and Incomplete Task Descriptions
- Takedown: How It's Done in Modern Coding Agent Exploits
- A Survey of Vibe Coding with Large Language Models
- The System Prompt Is the Attack Surface: How LLM Agent Configuration Shapes Security and Creates Exploitable Vulnerabilities
- Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
- "Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
- Prompt Stability in Code LLMs: Measuring Sensitivity across Emotion- and Personality-Driven Variations
- Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
- You Told Me to Do It: Measuring Instructional Text-induced Private Data Leakage in LLM Agents
- Prompt Flow Integrity to Prevent Privilege Escalation in LLM Agents
- GPT-4o System Card
- Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
- Is Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World Tasks
- Ambig-SWE: Interactive Agents to Overcome Underspecificity in Software Engineering
- QueryIPI: Query-agnostic Indirect Prompt Injection on Coding Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs