2 papers
cs.CR2026
SkillShield: Prompt-Space Security Skills for LLM Coding Agents
Xiaodong Wu, Zhimin Zhao, Qi Li +4
A coding agent edits files and executes shell commands with its developer's privileges, allowing malicious requests to translate directly into harmful actions or functional malware…
cs.CR2026
EVOMAL: Self-Poisoning in Self-Evolving Coding Agents
Xiaodong Wu, Yu Shi, Qi Li +5
Self-evolving LLM coding agents write their own tools by imitating retrieved skills from shared skill libraries. We identify a vulnerability in this loop: during authoring, a retri…