Coding Agent is still setting up, but third-party code may have already run
Coding Agent 还在配置环境,第三方代码已经运行了
A preprint shows that asking a coding agent to 'get the project running' already triggers code execution during dependency install. Python setup.py, npm postinstall, and Cargo build.rs can all run code at install time. The authors built 12 scenarios across 5 attack types and tested 9 model–client combos. Obvious typosquatting was mostly caught, but separator tricks, extra registry URLs pointing to attacker-controlled sources, and known-vulnerable old versions often slipped through. The final diff only tracks repo file changes, not what install scripts already executed. The paper recommends pausing before install to inspect package name, source, and version, then running installs in a sandbox. No independent reproduction yet.
Why it matters: A preprint maps coding agent setup as an attack surface with 12 scenarios, 5 attack types, and 9 config tests—dense and specific. The ding is preprint status, no independent repro, and constructed rather than in-the-wild attacks. But the topic hits a real blind spot in agent w...