arXiv:2607. 23624v1 Announce Type: cross Abstract: Third-party API routers have become a common layer that unifies access across increasingly diverse LLM providers.
By Donghao Fu, Jingxin Li, Xue Jiang, Yihong Dong
The paper investigates how third‑party API routers, which sit between coding agents and large language model providers, can introduce a control gap by inspecting and modifying requests and responses. Through an empirical study using the SIDEL framework, the authors evaluate four levels of router‑side injection (Response Substitution, Response Append, LLM‑Polished Injection, and LLM‑Polished with Distribution Alignment Injection) across 400 curated samples and four representative coding agents. The results show that router‑side interventions significantly alter repository‑level actions and evade existing client‑side safeguards, achieving a 0% defense success rate without additional mitigations.
By Donghao Fu, Jingxin Li, Xue Jiang, Yihong Dong
arXiv:2606. 09935v1 Announce Type: cross Abstract: AI-powered agents are increasingly embedded in continuous integration and continuous delivery/deployment (CI/CD) pipelines to autonomously review pull requests (PRs), triage issues, and maintain codebases.
By Jafar Isbarov, Umid Suleymanov, Ilia Shumailov, Murat Kantarcioglu
arXiv:2607. 08981v1 Announce Type: cross Abstract: LLM-generated code often compiles, passes tests, and appears correct, yet breaks once deployed.
By Viraaji Mothukuri, Reza M. Parizi
arXiv:2606. 22504v1 Announce Type: cross Abstract: Coding agents often receive broad tool access for an entire task, even when a resource is needed only for one subgoal.
By Igor Santos-Grueiro
arXiv:2605. 26542v2 Announce Type: replace-cross Abstract: Tool-using agents increasingly operate in open-ended deployment environments, where they compose file systems, web APIs, code interpreters, and enterprise services at runtime.
By Xiaochong Jiang, Shiqi Yang, Ziwei Li, Lifei Liu, Haoran Yu, Yichen Liu