Pith. sign in

Paper Citation Record · LEDGER

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests

As of 9 August 2026, this Paper Citation Record lists 34 of 34 outbound references and 0 inbound Pith citation observations for arXiv:2607.20759.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2607.20759 v1

Coverage vector

measured 34 of 34 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-01T09:30:52.016053Z

measured 34 of 34 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-09T06:31:02.800959+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

34 of 34 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved34
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation 00b96736-6621-43b3-96db-d0ecb4c10ff8 · outbound

This paper cites When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests When Developer Aid Becomes Security Debt: A Systematic Analysis of Insecure Behaviors in LLM Coding Agents

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.387916Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.387916Z digest=sha256:4b509880f0f031661012a789c43d952639347f41431816d5151fe04c1add9ec3

Observation 39d17516-ad31-42c7-815d-f9d689553c94 · outbound

This paper cites OpenHands: An Open Platform for AI Software Developers as Generalist Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests OpenHands: An Open Platform for AI Software Developers as Generalist Agents

Reference 2

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.497431Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.497431Z digest=sha256:287155cf535812ea40da8fdcfd97182df09c90b216233ed53a1eef99d8f69355

Observation b252d1d3-5e9e-485e-a748-9fc37d3c3057 · outbound

This paper cites Agentic Much? Adoption of Coding Agents on GitHub.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Agentic Much? Adoption of Coding Agents on GitHub

Reference 3

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.666592Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.666592Z digest=sha256:77bc62516a4cbffabbb6bbb6b15a0fe0ad6a8feb377d7230f8dcb2830e6dc61d

Observation 483f0a05-786e-45ff-b2d0-36526cdc475e · outbound

This paper cites MaPPing Your Model: Assessing the Impact of Adversarial Attacks on LLM-based Programming Assistants.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests MaPPing Your Model: Assessing the Impact of Adversarial Attacks on LLM-based Programming Assistants

Reference 4

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:48.861189Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:48.861189Z digest=sha256:bc6102f77822d1f8ed7d902f4256b6a81e96381902a4e11c6a1ac3d22d022016

Observation 7bed2130-f027-49f9-ab0d-c1d6e23eae1f · outbound

This paper cites DeceptPrompt: Exploiting LLM-driven Code Generation via Adversarial Natural Language Instructions.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests DeceptPrompt: Exploiting LLM-driven Code Generation via Adversarial Natural Language Instructions

Reference 5

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.040148Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.040148Z digest=sha256:da7cd9377c71e15821bb49816246e35a669a1d24ab5db65667a0c600d05e11d9

Observation ec30df92-7a97-4f3c-9842-8833e8b5b87e · outbound

This paper cites A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.265611Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.265611Z digest=sha256:7d904a9808d1348298ecac6e24ffe23f55ecbf5af9bc0f03facb843fb2e5d2be

Observation 198d2706-bd01-4d90-9079-d6ca0024ee03 · outbound

This paper cites OW ASP top 10 for large language model applications, version 2025,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests OW ASP top 10 for large language model applications, version 2025,

Reference 7

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.461782Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.461782Z digest=sha256:1b34de96fd4e8a67e6457823eefa24ba238bc93e09a2ea26c24a9b0418c378e5

Observation 7a997758-e723-421d-9dd5-1b58ae6e3ac5 · outbound

This paper cites Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.613327Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.613327Z digest=sha256:2b8e7125743c23c773663c0c6891cb9d2fa2727fa10fdd86ede4dfa58925abd4

Observation 255bddf3-a57d-4035-8dc1-9db6407f4f30 · outbound

This paper cites From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests From prompt injections to protocol exploits: Threats in LLM-powered AI agents workflows,

Reference 9

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:49.783801Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:49.783801Z digest=sha256:9e557d0040ea6223700c246c502c8e5ff0e299c91094ce4a6b99d8dcb4967cdb

Observation fb2327e0-a826-48a3-b9f4-16e3a92d28a3 · outbound

This paper cites "Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests "Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors

Reference 11

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.268369Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.268369Z digest=sha256:231b5861338964f74d62cbe41f568187f96a99d7d851931b6d4b71cc7dd66a05

Observation 11c8738b-c50e-4a4d-9114-085ddc6d4fbd · outbound

This paper cites Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Injecagent: Benchmark- ing indirect prompt injections in tool-integrated large language model agents,

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.355109Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.355109Z digest=sha256:3a731ca3486fffe1b7c5c78bc22a7446dc8f27ce6ef56e7cc988c561cc633a52

Observation 6845b42b-aa08-4107-aff1-e5a37a9ee1fa · outbound

This paper cites Imprompter: Tricking LLM agents into improper tool use,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Imprompter: Tricking LLM agents into improper tool use,

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.413766Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.413766Z digest=sha256:79f366966618838fee76d1efc6e9163b934bf48d81d31f5988ef1c5902b1f851

Observation 3af8ea01-df22-464a-923a-30fb014c3f6e · outbound

This paper cites PromptPwnd: How AI agents are exploited through prompt injection in ci/cd pipelines,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests PromptPwnd: How AI agents are exploited through prompt injection in ci/cd pipelines,

Reference 14

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.464932Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.464932Z digest=sha256:d889a195c3a77134ffaab9852c1f3913cc1a78c1a1b9e0ecb8931d6c0afe6a0d

Observation c61b477e-ef28-449c-a626-068c409bfcc1 · outbound

This paper cites How hidden prompt injections can hijack AI code assistants,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests How hidden prompt injections can hijack AI code assistants,

Reference 15

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.540895Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.540895Z digest=sha256:4f2572987f4b471458d871cb4f7d57acdc1da1bfeae9a2b6e8f181dff06a1d07

Observation efb8fd80-75fc-452a-80e6-8e0c5794b54e · outbound

This paper cites Defending Against Indirect Prompt Injection Attacks With Spotlighting.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Defending Against Indirect Prompt Injection Attacks With Spotlighting

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.619079Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.619079Z digest=sha256:79092128222a265dd2b8e80de87ab6dd8d1d81ab18d915c767b876e5268d5d8f

Observation cdc65bde-9167-4673-b789-f8a20a274502 · outbound

This paper cites The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests The task shield: Enforcing task alignment to defend against indirect prompt injection in LLM agents,

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.682081Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.682081Z digest=sha256:aed6a77e1032e93232c7c89aa702c31af32bbae5243f04434df439fb45ab43c6

Observation 52629169-354d-45a5-a8f3-ce5620f2348f · outbound

This paper cites IPIGuard: A novel tool dependency graph-based defense against indirect prompt injection in LLM agents,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests IPIGuard: A novel tool dependency graph-based defense against indirect prompt injection in LLM agents,

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.725862Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.725862Z digest=sha256:63a3a3036c8730ea465f4ff4ef2f18133a3c6c79fa1148ed2931e8aad879cffd

Observation 6f4f2530-431b-4e61-bbca-253647a51576 · outbound

This paper cites Struq: Defending against prompt injection with structured queries,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Struq: Defending against prompt injection with structured queries,

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.939382Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.939382Z digest=sha256:ac2b14ee517ee8a71b5e286118de13eb30fc7320363665f087f6f69e8626d010

Observation 7d3e33fe-1f19-44a3-b32f-0db76ca222bd · outbound

This paper cites Available: https://arxiv.org/abs/2601.04795.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Available: https://arxiv.org/abs/2601.04795

Reference 21

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.859310Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.859310Z digest=sha256:f0785550cd2b40c74766d7ac598d3546d68cb1d86a708f3ca3c1a68fea3c5182

Observation 5b4c6441-b3db-42e9-82cf-b170672080ef · outbound

This paper cites LlamaFirewall: An open source guardrail system for building secure AI agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests LlamaFirewall: An open source guardrail system for building secure AI agents

Reference 22

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.102769Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.102769Z digest=sha256:61f37c4c7a91788e983d8b7e85814b1c1b30cc7e719e986e8fcdc660ac7628d0

Observation 3de13c0f-63cf-41a2-af31-48b1205c52d8 · outbound

This paper cites Defeating Prompt Injections by Design.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Defeating Prompt Injections by Design

Reference 23

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.021596Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.021596Z digest=sha256:35053f1d75dc9fb3499045a3d5428fca425ea2a74a10238727a927372c9faa90

Observation 48bcac9d-1961-437b-a039-51f235b0dcad · outbound

This paper cites Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents

Reference 24

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.290701Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.290701Z digest=sha256:5cc5f253c98ec1f46c63d48fdf12fb4d9a61e5ddfc28a9c2c49d84988e8f83b0

Observation 707e6df5-b157-4010-89ce-b5f06de4baab · outbound

This paper cites AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents

Reference 25

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.184109Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.184109Z digest=sha256:b0571182c26e0e924776735fbfcdf60ade848543f0ed638cad2702cb46da4596

Observation 23059227-b10b-4c0d-abb6-b1caa83d6d8d · outbound

This paper cites Codex sandboxing documentation,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Codex sandboxing documentation,

Reference 26

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.496934Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.496934Z digest=sha256:f38a813428698c33568b695eb6c09a9dc624651828275ed87a0957815c37826b

Observation a1d80729-15a7-411b-ba9c-4c07d4320186 · outbound

This paper cites Claude code: An agentic cli for software engineering,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Claude code: An agentic cli for software engineering,

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.309796Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.309796Z digest=sha256:0abb5dbc7ebaabc14c8702019de3f2b6af00f30345dc0a12a6d01975ef7d6919

Observation 2b8d94ea-8980-4a05-90f6-bc2b8cea42a9 · outbound

This paper cites Available: https://code.claude.com/docs/en/overview.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Available: https://code.claude.com/docs/en/overview

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.374130Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.374130Z digest=sha256:bef6b6a91d58a1d6579c5f6973e5df3066515e7501b5dba2c15e0f6af137448e

Observation b915b4a1-68ab-4026-88c5-9447d5a03f1b · outbound

This paper cites GPT-5.4 thinking system card,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests GPT-5.4 thinking system card,

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.771485Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.771485Z digest=sha256:6663302622b6469dc6001d64f0940ce3bcff732b375065ca8499fe00fffc60ee

Observation e0ab4f89-f963-4360-8f29-a7ea3bd049eb · outbound

This paper cites Cursor: The ai code editor,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Cursor: The ai code editor,

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.613009Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.613009Z digest=sha256:d82a9950226fc0ef3ab6272fdb7a8ae366b9d8ad277464715fa802d7a9fb0004

Observation 6fe74853-1433-441a-90d8-5e4cc8a88b4b · outbound

This paper cites Claude sonnet 4.6 system card,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Claude sonnet 4.6 system card,

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.717952Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.717952Z digest=sha256:e02e1a229b568b85b7afe9fd8a7057355493d0e88c736060832c6d0f91c0dcdd

Observation 013174f2-b712-4dd3-a535-f548f7d4c2dd · outbound

This paper cites SG-Bench: Evaluating LLM Safety Generalization Across Diverse Tasks and Prompt Types.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests SG-Bench: Evaluating LLM Safety Generalization Across Diverse Tasks and Prompt Types

Reference 32

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.953664Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.953664Z digest=sha256:3d64284231f091f38b3835eb7deaef47de8f434f5e3449b96a28a8bc6b0b6ba8

Observation 956839f1-5243-4392-b802-dd6229126c0f · outbound

This paper cites GPT-5.3-Codex system card,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests GPT-5.3-Codex system card,

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.833450Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.833450Z digest=sha256:73278f7c3b75a20b8872b44583b6e050f053128109434e448aee5c6643380bd7

Observation 9fd554ef-9132-4800-9897-e54bc269d420 · outbound

This paper cites SWE-agent: Agent-computer interfaces enable automated software engineering,.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests SWE-agent: Agent-computer interfaces enable automated software engineering,

Reference 34

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:51.892522Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:51.892522Z digest=sha256:1840f329c1cc1af85298cdfe36398228fb3cd104cbeef3f19ee5c746cbcdec29

Observation 77f03a05-7c8b-4407-a4f2-162945b4802f · outbound

This paper cites Design Patterns for Securing LLM Agents against Prompt Injections.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Design Patterns for Securing LLM Agents against Prompt Injections

Reference 36

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:52.016053Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:52.016053Z digest=sha256:f13490c6cfb4a0363f78f5ef5d65dba35f7c30ed509a22114bac3298deb1ab51

Observation 39c1ae47-6d2b-49d6-a14d-1faa08503a22 · outbound

This paper cites Available: https://arxiv.org/abs/2601.17548.

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests Available: https://arxiv.org/abs/2601.17548

Reference 2026

Resolution
unresolved
no resolver link, observed 2026-08-01T09:30:50.095626Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:30:50.095626Z digest=sha256:c8c91fe50361e31e5805ee1fafc80b0eccb83150d762c152f363afbc6152bcd2

Pith citing papers

No inbound Pith citation observations are available.