Fetching from the wire…
Security2026-08-12 · source-backed
PRISMA 2020 review, six databases, 743 records screened, 85 retained from 2023–2025 (arXiv 2608.10530). Perception-layer work (prompt injection, jailbreaking, adversarial perturbation) is 66% of papers. Action-layer vulnerabilities (tool misuse, code injection, sandbox escape) are 4.7%. Code-execution security is 3.5%. That distribution is inverted relative to what actually hurts you in production, where the agent has a shell.
Each link below shares sources, entities, or timing with this story.
Shared entity: Code / Same source domain / Shared topic / Earlier coverage
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (action, agent, code, defense).
Shared entity: Code / Same source domain / Shared topic / Earlier coverage / Tension
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, code).
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, code).
Shared entity: Code / Same source domain / Shared topic / Earlier coverage
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (action, attention, code).
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, attack, code).
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (adversarial, agent, code).
Shared entity: Action / Same source domain / Shared topic / Earlier coverage
Both cover Action; reported by the same outlet (arxiv.org); overlapping topics (action, agent, attack).
Shared entity: Action / Shared topic / Earlier coverage / Downstream implication
Both cover Action; overlapping topics (action, adversarial, code); earlier Action coverage from 2026-02-24.