Public articles linked to the same research event.
arXiv The work builds a ten-mechanism taxonomy across 40 coding agent harnesses and rates 400 harness–mechanism cells (205 confirmed implemented, 83 confirmed absent, 112 unresolved), then introduces HarnessSecurity-Bench, which runs 2,500 trials under GLM-5.2 on 23 tasks across five attack surfaces with separate deterministic oracles for six harnesses, finding that enabling auto-approve raises attack success from 29.2% to 95.6%, that network isolation and read-only mode cut attack success from 57.1% and 8.3% to 0.8% at utility losses of 24.5 and 34.0 percentage points, and that command allowlisting and denylisting reduce attack effects with a small utility loss and a utility gain respectively.
The work builds a ten-mechanism taxonomy across 40 coding agent harnesses and rates 400 harness–mechanism cells (205 confirmed implemented, 83 confirmed absent, 112 unresolved), then introduces HarnessSecurity-Bench, which runs 2,500 trials under GLM-5.2 on 23 tasks across five attack surfaces with separate deterministic oracles for six harnesses, finding that enabling auto-approve raises attack success from 29.2% to 95.6%, that network isolation and read-only mode cut attack success from 57.1% and 8.3% to 0.8% at utility losses of 24.5 and 34.0 percentage points, and that command allowlisting and denylisting reduce attack effects with a small utility loss and a utility gain respectively.
The work builds a ten-mechanism taxonomy across 40 coding agent harnesses and rates 400 harness–mechanism cells (205 confirmed implemented, 83 confirmed absent, 112 unresolved), then introduces HarnessSecurity-Bench, which runs 2,500 trials under GLM-5.2 on 23 tasks across five attack surfaces with separate deterministic oracles for six harnesses, finding that enabling auto-approve raises attack success from 29.2% to 95.6%, that network isolation and read-only mode cut attack success from 57.1% and 8.3% to 0.8% at utility losses of 24.5 and 34.0 percentage points, and that command allowlisting and denylisting reduce attack effects with a small utility loss and a utility gain respectively.
The work builds a ten-mechanism taxonomy across 40 coding agent harnesses and rates 400 harness–mechanism cells (205 confirmed implemented, 83 confirmed absent, 112 unresolved), then introduces HarnessSecurity-Bench, which runs 2,500 trials under GLM-5.2 on 23 tasks across five attack surfaces with separate deterministic oracles for six harnesses, finding that enabling auto-approve raises attack success from 29.2% to 95.6%, that network isolation and read-only mode cut attack success from 57.1% and 8.3% to 0.8% at utility losses of 24.5 and 34.0 percentage points, and that command allowlisting and denylisting reduce attack effects with a small utility loss and a utility gain respectively.