How you lay out your repo changes prompt-injection success: highly modular workspaces measurably lower attack success rate
This is the first empirical study to treat 'workspace topology' - directory depth, codebase modularity, in-file injection position, and context framing - as an attack surface for coding agents that ingest third-party code with broad filesystem access. Across open-source repos spanning 10 languages and 6 engineering domains, testing three indirect-prompt-injection entry points against open-weight models on open-source harnesses, modularity changes significantly shifted attack success rate, with highly modular environments proving significantly harder to hijack; security cues placed in the workspace also moved ASR. Two takeaways for builders: repo structure is a security control you already own, and any coding-agent security benchmark run in a contaminated or non-representative workspace produces unreliable numbers.
↳ Follow the thread