Evidence record 11298 · automatically gathered

Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents

AI coding agents set up projects by reading documentation and installing the dependencies it lists, without verifying their names, sources, or known vulnerabilities. By editing only a README, requirements file, or Makefile, an attacker can redirect the agent to an untrusted registry, a known-vulnerable version, or a wrong-but-plausible name: documentation becomes a vector for code execution. We present the first systematic evaluation of package-install-time supply-chain attacks delivered through

Record details

Published: 16 July 2026
Source: arXiv cs.HC
Category: Research
Topics: Military & security · Agents & autonomy
Retrieved: 17 July 2026

source-onlyevidence status

These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.

How to cite this record

ethics.ai (16 July 2026), “Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents,” evidence record 11298, https://ethics.ai/record/11298 (originally published by arXiv cs.HC).

JSON

Use and limitations

This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.