MediumResearchPeer-reviewedLLM-specific
Red-Teaming Coding Agents from a Tool-Invocation Perspective: An Empirical Security Assessment
- Published
- Record updated
Summary
Researchers ran the first systematic red-teaming of tool invocation in six coding agents: Cursor, Claude Code, Copilot, Windsurf, Cline, and Trae. They introduce ToolLeak, which exfiltrates agent-internal prompts such as system prompts and tool metadata through required tool parameters, and a two-channel prompt injection in the tool description and tool return that achieves remote code execution. The study reports ToolLeak outperforming prompt-leak baselines, with the best pseudo-recall on 18 of 25 agent-LLM pairs.
Topics
Related items
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSimilar attack · Dark Reading