3 papers
cs.SE2026
ProfMalPlus: Agent-Coordinated Detection of Malicious NPM Packages via Static-Dynamic Analysis Synergy
Yiheng Huang, Zhijia Zhao, Bihuan Chen +6
Open source software is vulnerable to supply-chain attacks through transitive dependencies, especially malicious code injected into NPM packages. Existing detectors often inadequat…
cs.CR2026
Mitigating Taint-Style Vulnerabilities in MCP Servers via Security-Aware Tool Descriptions
Yang Shi, Jiaheng Fu, Yihe Huang +3
Large language models (LLMs) are increasingly deployed as autonomous agents that interact with external tools and services via the Model Context Protocol (MCP), a standardized inte…
cs.SE2024
Lifting the Veil on Composition, Risks, and Mitigations of the Large Language Model Supply Chain
Kaifeng Huang, Bihuan Chen, You Lu +7
Large language models (LLMs) have sparked significant impact with regard to both intelligence and productivity. Numerous enterprises have integrated LLMs into their applications to…