pith. sign in

arxiv: 2605.25871 · v1 · pith:FLL4J6P4new · submitted 2026-05-25 · 💻 cs.SE · cs.CR

How Agentic AI Coding Assistants Become the Attacker's Shell

classification 💻 cs.SE cs.CR
keywords assistantsagenticartifactsattackercodingcommandsexternalshell
0
0 comments X
read the original abstract

Agentic AI coding assistants can edit files, run commands, and access the internet on behalf of developers. However, their reliance on unvetted external artifacts introduces a new attack vector. Hidden instructions in external artifacts can hijack these assistants, turning them into an attacker's shell to run unauthorized commands. In this article, we examine how these prompt injection attacks work, measure their prevalence, discuss the limitations and challenges of current defenses, and suggest future research directions.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.