设置完成,现在你已被攻破:利用设置指令攻击人工智能编码代理
Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents
AI总结:
研究人工智能编码代理在安装包时因不验证依赖项而面临的供应链攻击,通过编辑项目设置文档即可发动攻击。对前沿模型在多场景下测试,发现安装安全性取决于工具与模型组合,还存在多种检测问题,提出预安装检查可弥补大部分安全差距。
AI中文摘要:
人工智能编码代理通过读取文档并安装其中列出的依赖项来设置项目,而不验证其名称、来源或已知漏洞。攻击者只需编辑README、需求文件或Makefile,就能将代理重定向到不可信的注册表、已知易受攻击的版本或看似合理但错误的名称,使文档成为代码执行的载体。我们首次对通过普通项目设置文档进行的包安装时供应链攻击进行了系统评估,在五个攻击类别中的十二个场景下对前沿模型进行了测试。同一模型在一种工具中能检测到攻击,在另一种工具中却会安装攻击内容,安装时的安全性取决于工具与模型的组合。代理能可靠地捕捉明显的仿冒域名,但看似合理的分隔符混淆名称(如azurecore代替azure - core)却会漏过,其出现频率取决于工具与模型的配对。基于源的攻击(如注册表重定向)几乎在所有地方都被遗漏。在npm和Cargo上也存在源盲点,几乎每个模型都会安装不可信的依赖项;名称检测在不同生态系统中的一致性较低。面向安全的提示能弥补部分差距,但仅针对其指定的维度;在任何代码运行前进行确定性的预安装检查,可弥补大部分差距。
英文摘要:
AI coding agents set up projects by reading documentation and installing the dependencies it lists, without verifying their names, sources, or known vulnerabilities. By editing only a README, requirements file, or Makefile, an attacker can redirect the agent to an untrusted registry, a known-vulnerable version, or a wrong-but-plausible name: documentation becomes a vector for code execution. We present the first systematic evaluation of package-install-time supply-chain attacks delivered through ordinary project-setup documentation across production coding-agent harnesses, probing frontier models on twelve scenarios in five attack classes, grounded in documented incidents. The same model catches an attack through one harness and installs it through another: install-time security rests on the harness-model combination, not the model alone. Agents catch blatant typosquats reliably, but plausible separator-confusion names (azurecore for azure-core) slip through, and how often depends on the harness-model pairing. Source-based attacks like registry redirection are missed almost everywhere. The source blind spot recurs on npm and Cargo, where nearly every model installs the untrusted dependency; name detection carries over less consistently across ecosystems. Security-oriented prompts recover part of the gap but only for the dimension they name; a deterministic pre-install check that verifies names, sources, and versions before any code runs closes most of it.