Research · curated 26 Jul 2026

IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests

Coverage timeline

26 Jul 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

IssueTrojanBench shows that autonomous coding agents with file and shell access can be induced via poisoned issue requests to execute arbitrary commands and exfiltrate data, exposing a widely-adopted development workflow to indirect prompt injection.

IssueTrojanBench is a benchmark that systematically evaluates AI coding agents (Cursor, Claude Code, Codex Desktop, powered by GPT-5.3/5.4 and Sonnet 4.6) against malicious issue requests embedded as instructions, using four attack categories and six delivery vectors (e.g., PDFs, issue comments). The study finds 66.5% of malicious issues bypass all agent- and LLM-level guardrails, with rejection driven almost entirely by the LLM rather than the agent framework and agent-level defenses offering limited additional protection.