"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
Fuente:
arXiv
Saved in:
| Main Authors: | Liu, Yue, Zhao, Yanjie, Lyu, Yunbo, Zhang, Ting, Wang, Haoyu, Lo, David |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026)
by: Liu, Yue, et al.
Published: (2026)
What You Trust Is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
by: Niu, Yuqing, et al.
Published: (2025)
by: Niu, Yuqing, et al.
Published: (2025)
All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart Contracts
by: Sun, Tianle, et al.
Published: (2024)
by: Sun, Tianle, et al.
Published: (2024)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
Gotcha! This Model Uses My Code! Evaluating Membership Leakage Risks in Code Models
by: Yang, Zhou, et al.
Published: (2023)
by: Yang, Zhou, et al.
Published: (2023)
Are AI-assisted Development Tools Immune to Prompt Injection?
by: Huang, Charoes, et al.
Published: (2026)
by: Huang, Charoes, et al.
Published: (2026)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
CKGFuzzer: LLM-Based Fuzz Driver Generation Enhanced By Code Knowledge Graph
by: Xu, Hanxiang, et al.
Published: (2024)
by: Xu, Hanxiang, et al.
Published: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
Investigating Detection and Obfuscation of Prompt Injection Attacks Against Software Reverse Engineering AI Agents
by: Crawford, Brian, et al.
Published: (2026)
by: Crawford, Brian, et al.
Published: (2026)
Detecting Stealthy Data Poisoning Attacks in AI Code Generators
by: Improta, Cristina
Published: (2025)
by: Improta, Cristina
Published: (2025)
Defending Code Language Models against Backdoor Attacks with Deceptive Cross-Entropy Loss
by: Yang, Guang, et al.
Published: (2024)
by: Yang, Guang, et al.
Published: (2024)
Evaluating Tool Cloning in Agentic-AI Ecosystems
by: Kim, Taein, et al.
Published: (2026)
by: Kim, Taein, et al.
Published: (2026)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
by: Pan, Shidong, et al.
Published: (2024)
by: Pan, Shidong, et al.
Published: (2024)
FDI: Attack Neural Code Generation Systems through User Feedback Channel
by: Sun, Zhensu, et al.
Published: (2024)
by: Sun, Zhensu, et al.
Published: (2024)
Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities
by: Ma, Yujie, et al.
Published: (2026)
by: Ma, Yujie, et al.
Published: (2026)
ARAP: Demystifying Anti Runtime Analysis Code in Android Apps
by: Suo, Dewen, et al.
Published: (2024)
by: Suo, Dewen, et al.
Published: (2024)
SecureVibeBench: Benchmarking Secure Vibe Coding of AI Agents via Reconstructing Vulnerability-Introducing Scenarios
by: Chen, Junkai, et al.
Published: (2025)
by: Chen, Junkai, et al.
Published: (2025)
"My productivity is boosted, but ..." Demystifying Users' Perception on AI Coding Assistants
by: Lyu, Yunbo, et al.
Published: (2025)
by: Lyu, Yunbo, et al.
Published: (2025)
Demystifying and Detecting Cryptographic Defects in Ethereum Smart Contracts
by: Zhang, Jiashuo, et al.
Published: (2024)
by: Zhang, Jiashuo, et al.
Published: (2024)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection
by: Weng, Shihao, et al.
Published: (2026)
by: Weng, Shihao, et al.
Published: (2026)
Usability as a Weapon: Attacking the Safety of LLM-Based Code Generation via Usability Requirements
by: Li, Yue, et al.
Published: (2026)
by: Li, Yue, et al.
Published: (2026)
Backdoors in Code Summarizers: How Bad Is It?
by: Wang, Chenyu, et al.
Published: (2025)
by: Wang, Chenyu, et al.
Published: (2025)
Secure Coding with AI -- From Detection to Repair
by: Belozerov, Vladislav, et al.
Published: (2025)
by: Belozerov, Vladislav, et al.
Published: (2025)
Demonstration Attack against In-Context Learning for Code Intelligence
by: Ge, Yifei, et al.
Published: (2024)
by: Ge, Yifei, et al.
Published: (2024)
The Power of Words: Generating PowerShell Attacks from Natural Language
by: Liguori, Pietro, et al.
Published: (2024)
by: Liguori, Pietro, et al.
Published: (2024)
Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
by: Sahin, Omur, et al.
Published: (2026)
by: Sahin, Omur, et al.
Published: (2026)
Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
by: Huang, Charoes, et al.
Published: (2026)
by: Huang, Charoes, et al.
Published: (2026)
Trim My View: An LLM-Based Code Query System for Module Retrieval in Robotic Firmware
by: Arasteh, Sima, et al.
Published: (2025)
by: Arasteh, Sima, et al.
Published: (2025)
When AI Takes the Wheel: Security Analysis of Framework-Constrained Program Generation
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
I Know Who Clones Your Code: Interpretable Smart Contract Similarity Detection
by: Liu, Zhenguang, et al.
Published: (2025)
by: Liu, Zhenguang, et al.
Published: (2025)
Prompt Fuzzing for Fuzz Driver Generation
by: Lyu, Yunlong, et al.
Published: (2023)
by: Lyu, Yunlong, et al.
Published: (2023)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
by: Sharma, Aman, et al.
Published: (2024)
by: Sharma, Aman, et al.
Published: (2024)
XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding Assistants
by: Štorek, Adam, et al.
Published: (2025)
by: Štorek, Adam, et al.
Published: (2025)
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
by: Hamer, Sivana, et al.
Published: (2025)
by: Hamer, Sivana, et al.
Published: (2025)
Give LLMs a Security Course: Securing Retrieval-Augmented Code Generation via Knowledge Injection
by: Lin, Bo, et al.
Published: (2025)
by: Lin, Bo, et al.
Published: (2025)
AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality Apps
by: Kim, John Y., et al.
Published: (2025)
by: Kim, John Y., et al.
Published: (2025)
Similar Items
-
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026) -
What You Trust Is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice
by: Niu, Yuqing, et al.
Published: (2025) -
All Your Tokens are Belong to Us: Demystifying Address Verification Vulnerabilities in Solidity Smart Contracts
by: Sun, Tianle, et al.
Published: (2024) -
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024) -
Gotcha! This Model Uses My Code! Evaluating Membership Leakage Risks in Code Models
by: Yang, Zhou, et al.
Published: (2023)