---
格式版本: 2
标题: "Beyond the Payload: How User Invocation Shapes Coding Agent Vulnerability to Repository Poisoning"
原文链接: "https://arxiv.org/abs/2608.30686"
发布日期: "2026-08-31"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Mon, 31 Aug 2026 12:26:01 UTC (599 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-09-02T03:56:33+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-09-02T03:54:32+08:00"
入库时间: "2026-09-01T19:56:33.725Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=Oracle&searchtype=all"
匹配关键词:
  []
相关厂家:
  - "Oracle"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 8
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文为编码智能体仓库投毒安全研究，与超节点/AI Rack/机柜级AI基础设施完全无关，无任何相关技术或商业信息。"
AI质检模型: "zj-deepseek-v4-flash"
AI质检时间: "2026-09-02T03:57:02+08:00"
AI主题相关性: 0
AI来源权威性: 2
AI新颖性: 1
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 5
AI摘要: "该研究提出首个系统性变化用户端提示级配置的仓库投毒基准CIPR，包含20个仓库、1920个实例，测量编码智能体的攻击成功率与告警率。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-01T23:06:05.667Z"
采集批次: "2026年9月1日23点56分52秒"
采集批次ID: "20260901-235652-761"
去重键: "https://arxiv.org/abs/2608.30686"
---

## Computer Science > Cryptography and Security

## Title:Beyond the Payload: How User Invocation Shapes Coding Agent Vulnerability to Repository Poisoning

Authors:[Fukang Zhu](https://arxiv.org/search/cs?searchtype=author&query=Zhu,+F), [Binbin Zhao](https://arxiv.org/search/cs?searchtype=author&query=Zhao,+B), [Ruixiao Lin](https://arxiv.org/search/cs?searchtype=author&query=Lin,+R), [Ping He](https://arxiv.org/search/cs?searchtype=author&query=He,+P), [Tianyu Du](https://arxiv.org/search/cs?searchtype=author&query=Du,+T), [Shouling Ji](https://arxiv.org/search/cs?searchtype=author&query=Ji,+S)

[View PDF](https://arxiv.org/pdf/2608.30686) [HTML (experimental)](https://arxiv.org/html/2608.30686v1)

> Abstract:Coding agents are increasingly used for software engineering tasks, including bootstrapping projects from third-party repositories whose integrity cannot be assumed. Prior work on repository poisoning largely focuses on attacker-controlled injection and disguise, but developers also shape risk through everyday invocation choices: what task to delegate, how to phrase the request, and which skills or rules to supply. We term these user-side choices Prompt-Level Configurations (PLCs) and introduce CIPR (Coding In Poisoned Repos), the first benchmark that systematically varies PLCs in poisoned real-world repositories. CIPR comprises 1,920 instances across 20 repositories, four task types, three social-media-grounded prompt styles, and three skill/rule conditions, and measures attack success rate (ASR) and agent alert rate (AR) using automated runtime and trace-based oracles. Our evaluation reveals two key insights: (1) Vulnerability is highly context-dependent, with task type creating up to a 4.5-fold difference in ASR, with test-execution task forming a silent attack surface (high ASR, low AR). (2) Prompt expression shifts risk indirectly: underspecified prompts reduce ASR by truncating execution depth; noisy prompts exhibit a directional trend toward suppressing alerts by making malicious content less conspicuous. These findings highlight that coding agent vulnerability is not a static property, but a dynamic outcome shaped by everyday user configurations.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR); Computation and Language (cs.CL) |
| Cite as: | [arXiv:2608.30686](https://arxiv.org/abs/2608.30686) \[cs.CR\] |
|  | (or [arXiv:2608.30686v1](https://arxiv.org/abs/2608.30686v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.30686](https://doi.org/10.48550/arXiv.2608.30686) |

## Submission history

From: Fukang Zhu \[[view email](https://arxiv.org/show-email/a2e6b9d8/2608.30686)\]  
**\[v1\]** Mon, 31 Aug 2026 12:26:01 UTC (599 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.30686) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
