MOSAIC Hits 96.59% Attack Success by Composing Individually-Benign CLI Commands Inside Coding Agents
arXiv:2607.02857 (submitted July 3, 2026; Wu, Wang, Zhang, Nan, Wang) identifies a vulnerability class where CLI commands that are each harmless in isolation form dangerous state relationships when an agent composes them. MOSAIC synthesizes validated exploit patterns from security advisories into realistic developer workflows and reports "a 96.59% attack success rate under benign developer tasks" across five real-world CLI coding agents and five backend LLMs over 2,525 trials. The implication for allowlist-based permission rules is uncomfortable: per-command approval does not constrain a sequence, so deny rules keyed on single commands are the wrong granularity. Older than the usual recency bar — flagged here because it is directly relevant and has not been covered.
Source
↳ Follow the thread