Fetching from the wire…
Public story · 2026-07-27 · high
Whitelist controls and LLM review narrowed the damage but neither stopped the injection outright, the paper found.
Why now: Covered in the July 27 briefing, with no separate publication date given.
A compromised router beat every coding agent tested, posting a 0% defense rate across four escalating injection levels, per arXiv 2607.23624.
Third-party routers like OpenRouter sit on the trusted path between an agent and its model. Nothing on that path verifies the response reaching the agent matches what the provider sent, and the agent executes on it anyway.
The researchers built SIDEL, a trace record-replay-inject framework. They tested it against four coding agents, using a 400-sample dataset across four escalating injection levels.
Two mitigations, whitelist-based execution control and LLM-based review, cut into how much damage got done, but the defense success rate held at 0%. Neither restored end-to-end control once the router had tampered with the response.
I've recommended routing through gateways like OpenRouter. This paper is the bill for that advice landing in my own feed.
What I'd want to see next is router-side attestation, something that proves the response reaching the agent is the one the provider actually sent. The framework's code is posted under Riyasushin's SIDE repo on GitHub.
Each link below shares sources, entities, or timing with this story.
LLM uses OpenAI / Shared entities / Earlier coverage
Linked by a graph relationship (LLM uses OpenAI); both cover LLM, OpenRouter; earlier LLM coverage from 2026-06-19.
Simon Willison released LLM / Shared entity: LLM / Shared topic / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; overlapping topics (agent, code, coding).
Hermes Agent supports OpenRouter / Shared entity: OpenRouter / Shared topic / Earlier coverage
Linked by a graph relationship (Hermes Agent supports OpenRouter); both cover OpenRouter; overlapping topics (agent, code).
LLM uses OpenAI / Same source domain / Shared topic / Tension
Linked by a graph relationship (LLM uses OpenAI); reported by the same outlet (arxiv.org); overlapping topics (against, agent).
Simon Willison released LLM / Shared entity: Code / Shared topic / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover Code; overlapping topics (action, code).
Linked by a graph relationship (Simon Willison released LLM); both cover Code; overlapping topics (agent, code).
LLM uses OpenAI / Same source domain / Shared topic
Linked by a graph relationship (LLM uses OpenAI); reported by the same outlet (arxiv.org); overlapping topics (agent, alignment, code).
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.