Skip to content
MediumResearchPeer-reviewedLLM-specific

Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment

Published
Record updated
View JSON

Summary

Researchers ran the first systematic red-teaming of tool invocation in six coding agents: Cursor, Claude Code, Copilot, Windsurf, Cline, and Trae. They introduce ToolLeak, which exfiltrates agent-internal prompts such as system prompts and tool metadata through required tool parameters, and a two-channel prompt injection in the tool description and tool return that achieves remote code execution. The study reports ToolLeak outperforming prompt-leak baselines, with the best pseudo-recall on 18 of 25 agent-LLM pairs.