Vibe Coding
CIPR: how you phrase a request changes whether a poisoned repo compromises your coding agent
arXiv 2608.30686 (2026-08-31) introduces Prompt-Level Configurations, the user-side choices of what task to delegate, how to phrase it, and which skills or rules to supply, and benchmarks them with CIPR, 1,920 instances across 20 real poisoned repositories, four task types and three configuration axes. Prior repository-poisoning work studied attacker-controlled injection and disguise; this is the first to hold the payload fixed and vary the invocation. If it holds up, your CLAUDE.md and your prompt wording are part of your attack surface when you point an agent at third-party code.
Source
↳ Follow the thread