Workspace Topology as an Attack Vector in Agentic Coding Assistants

📅 2026-08-14
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses indirect prompt injection risks in intelligent programming assistants by defining the "workspace topology" attack surface and empirically evaluating the security of open-source models and toolchains across ten programming languages and six engineering domains. We systematically analyze how topological dimensions, including directory depth and modularity, influence attack success rates. Results demonstrate that highly modular codebases and secure context frameworks significantly mitigate attack effectiveness, while underscoring the critical role of contamination-free test environments for reliable evaluation. By revealing this novel attack vector, this work provides essential empirical evidence to inform security testing protocols and defensive design strategies for coding agents.
📝 Abstract
Agentic coding assistants are finding widespread use, not just in new code development but in quickly ingesting and leveraging third-party code. This opens up a risk of malicious code being ingested as these coding tools operate with broad filesystem access inside developer workspaces. In this paper, we extensively study the impact of different dimensions of a novel attack surface we term workspace topology -- defined via directory depth, codebase modularity, in-file injection position and context framing -- on the attack success rate of adversarial prompt injection attempts. We perform an empirical study of indirect prompt injection (IPI) across a diverse set of open-source repositories spanning 10 languages and 6 engineering domains, evaluating three IPI entry points against open-weight models operating open source code harnesses. We find that workspace topology measurably affects IPI success. Specifically, changes in codebase modularity can significantly alter the Attack Success Rate (ASR), with highly modular environments demonstrating significantly lower attack success rates. Furthermore, context framing and introduction of security-cues in the workspace can also alter the ASR. Our findings offer practical value for the evaluation and security testing of coding agents across diverse settings, while underscoring the importance of an uncontaminated testing environment to obtain reliable results and conclusions.
Problem

Research questions and friction points this paper is trying to address.

Agentic coding assistants
Indirect prompt injection
Workspace topology
Attack success rate
Security
Innovation

Methods, ideas, or system contributions that make the work stand out.

Workspace Topology
Indirect Prompt Injection
Agentic Coding Assistants
Codebase Modularity
Security Evaluation
🔎 Similar Papers
No similar papers found.
A
Alexandre G. R. Day
AI Foundations, Capital One
P
Pradeep Yadlapalli
AI Foundations, Capital One
S
Sriram Venkatapathy
AI Foundations, Capital One
T
Thomas Paniagua
AI Foundations, Capital One
N
Nick Raines
AI Foundations, Capital One
Sahil Wadhwa
Sahil Wadhwa
Capital One
Machine LearningNatural Language ProcessingData Visualisation
H
Himanshu Kumar
AI Foundations, Capital One
Andy Luo
Andy Luo
Unknown affiliation
S
Sudeep Panyam
AI Foundations, Capital One
Rikhiya Ghosh
Rikhiya Ghosh
AI Foundations, Capital One
Pranab Mohanty
Pranab Mohanty
Capital One
Generative AILLMSafe AIRecommender SystemDeep Learning
G
Giri Iyengar
AI Foundations, Capital One