{
  "id": 11298,
  "url": "https://arxiv.org/abs/2607.15143v1",
  "title": "Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents",
  "summary": "AI coding agents set up projects by reading documentation and installing the dependencies it lists, without verifying their names, sources, or known vulnerabilities. By editing only a README, requirements file, or Makefile, an attacker can redirect the agent to an untrusted registry, a known-vulnerable version, or a wrong-but-plausible name: documentation becomes a vector for code execution. We present the first systematic evaluation of package-install-time supply-chain attacks delivered through",
  "authors": "Aadesh Bagmar, Pushkar Saraf",
  "category": "research",
  "topics": "military-security,agents-autonomy",
  "orgs": null,
  "regions": null,
  "published_at": "2026-07-16T15:47:19.000Z",
  "fetched_at": "2026-07-17T05:10:53.887Z",
  "source_slug": "x-arxiv-cs-hc",
  "source_name": "arXiv cs.HC",
  "source_homepage": "https://arxiv.org/list/cs.HC/recent",
  "ethics_ai_record_url": "https://ethics.ai/record/11298",
  "original_url": "https://arxiv.org/abs/2607.15143v1",
  "evidence_status": "source-only",
  "attribution": "via ethics.ai"
}