发表机构
Zhejiang University; Tsinghua University(浙江大学; 清华大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究推出首个针对编码代理仓库中毒漏洞的基准CIPR,发现漏洞高度依赖用户提示级配置,任务类型可使攻击成功率产生4.5倍差异,测试执行任务为隐蔽攻击面,不明确或嘈杂提示会间接改变风险。
AI 中文摘要
编码代理越来越多地用于软件工程任务,包括从完整性无法保证的第三方仓库启动项目。先前关于仓库中毒的研究主要关注攻击者控制的注入与伪装,但开发者也会通过日常调用选择塑造风险:委托的任务类型、请求的表述方式、提供的技能或规则。我们将这些用户侧选择称为提示级配置(PLCs),并推出首个系统改变中毒真实仓库中PLCs的基准CIPR(Coding In Poisoned Repos)。CIPR包含20个仓库、4种任务类型、3种社交媒体风格提示、3种技能/规则条件下的1920个实例,通过自动运行时和基于跟踪的预言机测量攻击成功率(ASR)与代理告警率(AR)。评估揭示两个关键见解:(1)漏洞高度依赖上下文,任务类型使ASR产生最高达4.5倍的差异,其中测试执行任务形成隐蔽攻击面(高ASR、低AR);(2)提示表述间接改变风险:不明确的提示通过截断执行深度降低ASR,嘈杂提示则因恶意内容不那么显眼而呈现抑制告警的趋势。这些发现表明,编码代理的漏洞并非静态属性,而是日常用户配置塑造的动态结果。
英文摘要
Coding agents are increasingly used for software engineering tasks, including bootstrapping projects from third-party repositories whose integrity cannot be assumed. Prior work on repository poisoning largely focuses on attacker-controlled injection and disguise, but developers also shape risk through everyday invocation choices: what task to delegate, how to phrase the request, and which skills or rules to supply. We term these user-side choices Prompt-Level Configurations (PLCs) and introduce CIPR (Coding In Poisoned Repos), the first benchmark that systematically varies PLCs in poisoned real-world repositories. CIPR comprises 1,920 instances across 20 repositories, four task types, three social-media-grounded prompt styles, and three skill/rule conditions, and measures attack success rate (ASR) and agent alert rate (AR) using automated runtime and trace-based oracles. Our evaluation reveals two key insights: (1) Vulnerability is highly context-dependent, with task type creating up to a 4.5-fold difference in ASR, with test-execution task forming a silent attack surface (high ASR, low AR). (2) Prompt expression shifts risk indirectly: underspecified prompts reduce ASR by truncating execution depth; noisy prompts exhibit a directional trend toward suppressing alerts by making malicious content less conspicuous. These findings highlight that coding agent vulnerability is not a static property, but a dynamic outcome shaped by everyday user configurations.
Comments30 pages,7 figures, Accepted to EMNLP 2026 Main Conference