Pith. sign in

Paper Citation Record · LEDGER

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests

As of 23 August 2026, this Paper Citation Record lists 34 of 34 outbound references and 0 inbound Pith citation observations for arXiv:2607.20759.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.20759 v1

Coverage vector

measured 34 of 34 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T09:30:52.016053Z

measured 34 of 34 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

34 of 34 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved34
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 00b96736-6621-43b3-96db-d0ecb4c10ff8 · outbound

This paper cites When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.387916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.387916Z digest=sha256:fdea9131cf0bc39263c146be6961a868db66478f29bc179ad82c98e6cac4c243

Observation 39d17516-ad31-42c7-815d-f9d689553c94 · outbound

This paper cites OpenHands: An Open Platform for AI Software Developers as Generalist Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests OpenHands: An Open Platform for AI Software Developers as Generalist Agents

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.497431Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.497431Z digest=sha256:a7229368a50c187583ef57b2f2525ee61925baa86f80dbe8547b82644535a14a

Observation b252d1d3-5e9e-485e-a748-9fc37d3c3057 · outbound

This paper cites Agentic Much? Adoption of Coding Agents on GitHub.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Agentic Much? Adoption of Coding Agents on GitHub

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.666592Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.666592Z digest=sha256:71bbe18aca246ff1e9f1774fe20f590c9abe1ff845794819d346696fd8c248e2

Observation 483f0a05-786e-45ff-b2d0-36526cdc475e · outbound

This paper cites MaPPing Your Model: Assessing the Impact of Adversarial Attacks on LLM-based Programming Assistants.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests MaPPing Your Model: Assessing the Impact of Adversarial Attacks on LLM-based Programming Assistants

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.861189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.861189Z digest=sha256:da2ab0e6ac9dbb26418fe9fa408dc1cdafc091c86ef91fc05e9d3df6723498b0

Observation 7bed2130-f027-49f9-ab0d-c1d6e23eae1f · outbound

This paper cites DeceptPrompt: Exploiting LLM-driven Code Generation via Adversarial Natural Language Instructions.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests DeceptPrompt: Exploiting LLM-driven Code Generation via Adversarial Natural Language Instructions

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.040148Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.040148Z digest=sha256:554b29157952e9a05c773b9b76f5dfbc1149b459cd623a659abc3b2f38b44455

Observation ec30df92-7a97-4f3c-9842-8833e8b5b87e · outbound

This paper cites A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.265611Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.265611Z digest=sha256:7f6f659552667c352d828d73816f0e03f7b392e61b7c0396a5561989ddb6f123

Observation 198d2706-bd01-4d90-9079-d6ca0024ee03 · outbound

This paper cites OW ASP top 10 for large language model applications, version 2025,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests OW ASP top 10 for large language model applications, version 2025,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.461782Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.461782Z digest=sha256:cd592c68ace92f42272fbce99acb157590e23759a318a596672450592571b938

Observation 7a997758-e723-421d-9dd5-1b58ae6e3ac5 · outbound

This paper cites Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.613327Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.613327Z digest=sha256:01617b69532160f5e99ca548cfb7efc207f7356c6e6aa04c50578f87e1ce3f90

Observation 255bddf3-a57d-4035-8dc1-9db6407f4f30 · outbound

This paper cites From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.783801Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.783801Z digest=sha256:b9f17a7871fe6a49603444d10423291d28bf7ee1ed4bdadf5bbc3220b95be323

Observation fb2327e0-a826-48a3-b9f4-16e3a92d28a3 · outbound

This paper cites "Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests "Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.268369Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.268369Z digest=sha256:27dc80e5da120b30fc2884fa85dca1c271767a008fe0e02eb5ff6934497f2369

Observation 11c8738b-c50e-4a4d-9114-085ddc6d4fbd · outbound

This paper cites Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.355109Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.355109Z digest=sha256:eac8836fa739ddc09807ace5c4954b9af59ffcf7aa6ad54a915c03b4a234ccfa

Observation 6845b42b-aa08-4107-aff1-e5a37a9ee1fa · outbound

This paper cites Imprompter: Tricking LLM agents into improper tool use,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Imprompter: Tricking LLM agents into improper tool use,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.413766Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.413766Z digest=sha256:9edd74234bd355dc0e842d35b45ba83a92348d1530e8d38231cd8e0410bd9b3c

Observation 3af8ea01-df22-464a-923a-30fb014c3f6e · outbound

This paper cites PromptPwnd: How AI agents are exploited through prompt injection in ci/cd pipelines,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests PromptPwnd: How AI agents are exploited through prompt injection in ci/cd pipelines,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.464932Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.464932Z digest=sha256:8d7f2888e107b568d866af984383d133e76f9f3c19f0b998bb1aa79cb1ed34fe

Observation c61b477e-ef28-449c-a626-068c409bfcc1 · outbound

This paper cites How hidden prompt injections can hijack AI code assistants,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests How hidden prompt injections can hijack AI code assistants,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.540895Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.540895Z digest=sha256:74851fa05d16c86d6008ae733417fa3d43158242d50b1286abd99a28c4263fa6

Observation efb8fd80-75fc-452a-80e6-8e0c5794b54e · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.619079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.619079Z digest=sha256:5c9a57f23316eb4e1b4dab838bff0d930285b48a401fdc608201338acdd33b88

Observation cdc65bde-9167-4673-b789-f8a20a274502 · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.682081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.682081Z digest=sha256:619e170dbac846d4ae34566271c0002f69508bff53e64e460ce187b7be1dbc99

Observation 52629169-354d-45a5-a8f3-ce5620f2348f · outbound

This paper cites IPIGuard: A novel tool dependency graph-based defense against indirect prompt injection in LLM agents,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests IPIGuard: A novel tool dependency graph-based defense against indirect prompt injection in LLM agents,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.725862Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.725862Z digest=sha256:b8a1b97837cf42742d93a3e9ab60dae65c571652a5781394b19a44f5b1777d11

Observation 6f4f2530-431b-4e61-bbca-253647a51576 · outbound

This paper cites Struq: Defending against prompt injection with structured queries,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Struq: Defending against prompt injection with structured queries,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.939382Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.939382Z digest=sha256:dc96684d8db45aa32ec7d2581d10dca4a7ad1e5d494fb17d9240e55ffa6de7ac

Observation 7d3e33fe-1f19-44a3-b32f-0db76ca222bd · outbound

This paper cites Available: https://arxiv.org/abs/2601.04795.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Available: https://arxiv.org/abs/2601.04795

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.859310Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.859310Z digest=sha256:545ba24526fcd108ca45e46827094758387aef416afce63d5101c4f9017483d9

Observation 5b4c6441-b3db-42e9-82cf-b170672080ef · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.102769Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.102769Z digest=sha256:459065463379e4841a5809dd6464262b76fdc7326c9fc4b57a540729afa44050

Observation 3de13c0f-63cf-41a2-af31-48b1205c52d8 · outbound

This paper cites Defeating Prompt Injections by Design.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Defeating Prompt Injections by Design

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.021596Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.021596Z digest=sha256:c19052d4869d22782e82edc027020147173d251ba0a5b602c395fd078ac58a4d

Observation 48bcac9d-1961-437b-a039-51f235b0dcad · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.290701Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.290701Z digest=sha256:fd713a1ef1a36e30eb5b83be0c360450710fd96b8e42415db089c5eb713fac50

Observation 707e6df5-b157-4010-89ce-b5f06de4baab · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.184109Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.184109Z digest=sha256:e2b789fcef4265c59851f367f9336f7786ef76c13c8d8a72442818edc432c9e3

Observation 23059227-b10b-4c0d-abb6-b1caa83d6d8d · outbound

This paper cites Codex sandboxing documentation,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Codex sandboxing documentation,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.496934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.496934Z digest=sha256:4b5b38848072998c30bd71cc3367decf15c0f62d711ae296f791a8b6d62528b8

Observation a1d80729-15a7-411b-ba9c-4c07d4320186 · outbound

This paper cites Claude code: An agentic cli for software engineering,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Claude code: An agentic cli for software engineering,

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.309796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.309796Z digest=sha256:a46e8fbe5ec67b48b49f4480f6b248cab4b6adfec52d6c008f9fcda0afc22702

Observation 2b8d94ea-8980-4a05-90f6-bc2b8cea42a9 · outbound

This paper cites Available: https://code.claude.com/docs/en/overview.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Available: https://code.claude.com/docs/en/overview

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.374130Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.374130Z digest=sha256:033971b1483214c215aeb859887f2b72dd7962a8298449b05e38a1346453c468

Observation b915b4a1-68ab-4026-88c5-9447d5a03f1b · outbound

This paper cites GPT-5.4 thinking system card,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests GPT-5.4 thinking system card,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.771485Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.771485Z digest=sha256:51860b5056f36ba8d227fbd29f2a715c9aeda5cccebabe735dc506f1dababd11

Observation e0ab4f89-f963-4360-8f29-a7ea3bd049eb · outbound

This paper cites Cursor: The ai code editor,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Cursor: The ai code editor,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.613009Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.613009Z digest=sha256:3339ab433368a8a7cda551fd62f68bf37a5fd8f712a4c6f7e0c15acfda4c6ece

Observation 6fe74853-1433-441a-90d8-5e4cc8a88b4b · outbound

This paper cites Claude sonnet 4.6 system card,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Claude sonnet 4.6 system card,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.717952Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.717952Z digest=sha256:47cfd8a6753a0098a38587606065e543851a2b9d987f70bdccb66a67c18b2b7b

Observation 013174f2-b712-4dd3-a535-f548f7d4c2dd · outbound

This paper cites SG-Bench: Evaluating LLM Safety Generalization Across Diverse Tasks and Prompt Types.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests SG-Bench: Evaluating LLM Safety Generalization Across Diverse Tasks and Prompt Types

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.953664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.953664Z digest=sha256:343e45120efb33fb34fd031c37b2e11a68dcefd81d6dd86f3abe2231e07dfa1e

Observation 956839f1-5243-4392-b802-dd6229126c0f · outbound

This paper cites GPT-5.3-Codex system card,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests GPT-5.3-Codex system card,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.833450Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.833450Z digest=sha256:4618499a3568a3293c4fff081e4b3013b94a3ee26a44578975c15a8fef85134c

Observation 9fd554ef-9132-4800-9897-e54bc269d420 · outbound

This paper cites SWE-agent: Agent-computer interfaces enable automated software engineering,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests SWE-agent: Agent-computer interfaces enable automated software engineering,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.892522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.892522Z digest=sha256:89fa9d715d843613350c246e192fea472a494d2a61b5cba372f2717b98353c32

Observation 77f03a05-7c8b-4407-a4f2-162945b4802f · outbound

This paper cites Design Patterns for Securing LLM Agents against Prompt Injections.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Design Patterns for Securing LLM Agents against Prompt Injections

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:52.016053Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:52.016053Z digest=sha256:679bde5277eb4ad29f8e8a8a9a8dc770ed7c1edec8daed7156913e9cdec7b05d

Observation 39c1ae47-6d2b-49d6-a14d-1faa08503a22 · outbound

This paper cites Available: https://arxiv.org/abs/2601.17548.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Available: https://arxiv.org/abs/2601.17548

Reference 2026

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.095626Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.095626Z digest=sha256:0bab3992c595348d49ae3c3130f4204f88233acca359b81c4a1a1e6e1ad95cf2

Pith citing papers

No inbound Pith citation observations are available.