Are AI-assisted Development Tools Immune to Prompt Injection?
Fuente:
arXiv
Salvato in:
| Autori principali: | Huang, Charoes, Huang, Xin, Fard, Amin Milani |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
di: Huang, Charoes, et al.
Pubblicazione: (2026)
di: Huang, Charoes, et al.
Pubblicazione: (2026)
Auditing MCP Servers for Over-Privileged Tool Capabilities
di: Huang, Charoes, et al.
Pubblicazione: (2026)
di: Huang, Charoes, et al.
Pubblicazione: (2026)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
di: Liu, Yue, et al.
Pubblicazione: (2025)
di: Liu, Yue, et al.
Pubblicazione: (2025)
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection
di: Weng, Shihao, et al.
Pubblicazione: (2026)
di: Weng, Shihao, et al.
Pubblicazione: (2026)
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
di: Pan, Shidong, et al.
Pubblicazione: (2024)
di: Pan, Shidong, et al.
Pubblicazione: (2024)
Evaluating Tool Cloning in Agentic-AI Ecosystems
di: Kim, Taein, et al.
Pubblicazione: (2026)
di: Kim, Taein, et al.
Pubblicazione: (2026)
Investigating Detection and Obfuscation of Prompt Injection Attacks Against Software Reverse Engineering AI Agents
di: Crawford, Brian, et al.
Pubblicazione: (2026)
di: Crawford, Brian, et al.
Pubblicazione: (2026)
Enhancing Productivity with AI During the Development of an ISMS: Case Kempower
di: Niemeläinen, Atro, et al.
Pubblicazione: (2024)
di: Niemeläinen, Atro, et al.
Pubblicazione: (2024)
TPSQLi: Test Prioritization for SQL Injection Vulnerability Detection in Web Applications
di: Yang, Guan-Yan, et al.
Pubblicazione: (2025)
di: Yang, Guan-Yan, et al.
Pubblicazione: (2025)
Killing Two Birds with One Stone: Malicious Package Detection in NPM and PyPI using a Single Model of Malicious Behavior Sequence
di: Zhang, Junan, et al.
Pubblicazione: (2023)
di: Zhang, Junan, et al.
Pubblicazione: (2023)
Large Language Model assisted Hybrid Fuzzing
di: Meng, Ruijie, et al.
Pubblicazione: (2024)
di: Meng, Ruijie, et al.
Pubblicazione: (2024)
The Kubernetes Security Landscape: AI-Driven Insights from Developer Discussions
di: Curtis, J. Alexander, et al.
Pubblicazione: (2024)
di: Curtis, J. Alexander, et al.
Pubblicazione: (2024)
Enhancing REST API Fuzzing with Access Policy Violation Checks and Injection Attacks
di: Sahin, Omur, et al.
Pubblicazione: (2026)
di: Sahin, Omur, et al.
Pubblicazione: (2026)
Characterizing JavaScript Security Code Smells
di: Kambhampati, Vikas, et al.
Pubblicazione: (2024)
di: Kambhampati, Vikas, et al.
Pubblicazione: (2024)
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
di: Sharma, Aman, et al.
Pubblicazione: (2024)
di: Sharma, Aman, et al.
Pubblicazione: (2024)
DLAP: A Deep Learning Augmented Large Language Model Prompting Framework for Software Vulnerability Detection
di: Yang, Yanjing, et al.
Pubblicazione: (2024)
di: Yang, Yanjing, et al.
Pubblicazione: (2024)
SafeToolBench: Pioneering a Prospective Benchmark to Evaluating Tool Utilization Safety in LLMs
di: Xia, Hongfei, et al.
Pubblicazione: (2025)
di: Xia, Hongfei, et al.
Pubblicazione: (2025)
Enterprise Identity Integration for AI-Assisted Developer Services: Architecture, Implementation, and Case Study
di: Chinthareddy, Manideep Reddy
Pubblicazione: (2026)
di: Chinthareddy, Manideep Reddy
Pubblicazione: (2026)
Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns
di: Klemmer, Jan H., et al.
Pubblicazione: (2024)
di: Klemmer, Jan H., et al.
Pubblicazione: (2024)
SafeTrans: LLM-assisted Transpilation from C to Rust
di: Farrukh, Muhammad, et al.
Pubblicazione: (2025)
di: Farrukh, Muhammad, et al.
Pubblicazione: (2025)
From Component Manipulation to System Compromise: Understanding and Detecting Malicious MCP Servers
di: Huang, Yiheng, et al.
Pubblicazione: (2026)
di: Huang, Yiheng, et al.
Pubblicazione: (2026)
Prompt Fuzzing for Fuzz Driver Generation
di: Lyu, Yunlong, et al.
Pubblicazione: (2023)
di: Lyu, Yunlong, et al.
Pubblicazione: (2023)
Give LLMs a Security Course: Securing Retrieval-Augmented Code Generation via Knowledge Injection
di: Lin, Bo, et al.
Pubblicazione: (2025)
di: Lin, Bo, et al.
Pubblicazione: (2025)
SBOM Generation Tools in the Python Ecosystem: an In-Detail Analysis
di: Cofano, Serena, et al.
Pubblicazione: (2024)
di: Cofano, Serena, et al.
Pubblicazione: (2024)
Uncover the Premeditated Attacks: Detecting Exploitable Reentrancy Vulnerabilities by Identifying Attacker Contracts
di: Yang, Shuo, et al.
Pubblicazione: (2024)
di: Yang, Shuo, et al.
Pubblicazione: (2024)
Security Is Relative: Training-Free Vulnerability Detection via Multi-Agent Behavioral Contract Synthesis
di: Wang, Yongchao, et al.
Pubblicazione: (2026)
di: Wang, Yongchao, et al.
Pubblicazione: (2026)
Guardrails as Infrastructure: Policy-First Control for Tool-Orchestrated Workflows
di: Sigdel, Akshey, et al.
Pubblicazione: (2026)
di: Sigdel, Akshey, et al.
Pubblicazione: (2026)
PentestGPT: An LLM-empowered Automatic Penetration Testing Tool
di: Deng, Gelei, et al.
Pubblicazione: (2023)
di: Deng, Gelei, et al.
Pubblicazione: (2023)
Centralized Defense: Logging and Mitigation of Kubernetes Misconfigurations with Open Source Tools
di: Russell, Eoghan, et al.
Pubblicazione: (2024)
di: Russell, Eoghan, et al.
Pubblicazione: (2024)
Building a Cybersecurity Risk Metamodel for Improved Method and Tool Integration
di: Ponsard, Christophe
Pubblicazione: (2024)
di: Ponsard, Christophe
Pubblicazione: (2024)
Transferable Backdoor Attacks for Code Models via Sharpness-Aware Adversarial Perturbation
di: Chang, Shuyu, et al.
Pubblicazione: (2026)
di: Chang, Shuyu, et al.
Pubblicazione: (2026)
HyperPUT: Generating Synthetic Faulty Programs to Challenge Bug-Finding Tools
di: Felici, Riccardo, et al.
Pubblicazione: (2022)
di: Felici, Riccardo, et al.
Pubblicazione: (2022)
Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?
di: Chaliasos, Stefanos, et al.
Pubblicazione: (2023)
di: Chaliasos, Stefanos, et al.
Pubblicazione: (2023)
MCP-SandboxScan: WASM-based Secure Execution and Runtime Analysis for MCP Tools
di: Tan, Zhuoran, et al.
Pubblicazione: (2026)
di: Tan, Zhuoran, et al.
Pubblicazione: (2026)
Clawdrain: Exploiting Tool-Calling Chains for Stealthy Token Exhaustion in OpenClaw Agents
di: Dong, Ben, et al.
Pubblicazione: (2026)
di: Dong, Ben, et al.
Pubblicazione: (2026)
ChainFuzzer: Greybox Fuzzing for Workflow-Level Multi-Tool Vulnerabilities in LLM Agents
di: Wu, Jiangrong, et al.
Pubblicazione: (2026)
di: Wu, Jiangrong, et al.
Pubblicazione: (2026)
UniBOM -- A Unified SBOM Analysis and Visualisation Tool for IoT Systems and Beyond
di: Safronov, Vadim, et al.
Pubblicazione: (2025)
di: Safronov, Vadim, et al.
Pubblicazione: (2025)
Unity is Strength: Enhancing Precision in Reentrancy Vulnerability Detection of Smart Contract Analysis Tools
di: Wang, Zexu, et al.
Pubblicazione: (2024)
di: Wang, Zexu, et al.
Pubblicazione: (2024)
From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
di: Zhou, Dongchao, et al.
Pubblicazione: (2025)
di: Zhou, Dongchao, et al.
Pubblicazione: (2025)
HarnessAgent: Scaling Automatic Fuzzing Harness Construction with Tool-Augmented LLM Pipelines
di: Yang, Kang, et al.
Pubblicazione: (2025)
di: Yang, Kang, et al.
Pubblicazione: (2025)
Documenti analoghi
-
Model Context Protocol Threat Modeling and Analyzing Vulnerabilities to Prompt Injection with Tool Poisoning
di: Huang, Charoes, et al.
Pubblicazione: (2026) -
Auditing MCP Servers for Over-Privileged Tool Capabilities
di: Huang, Charoes, et al.
Pubblicazione: (2026) -
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
di: Liu, Yue, et al.
Pubblicazione: (2025) -
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection
di: Weng, Shihao, et al.
Pubblicazione: (2026) -
"I Don't Use AI for Everything": Exploring Utility, Attitude, and Responsibility of AI-empowered Tools in Software Development
di: Pan, Shidong, et al.
Pubblicazione: (2024)