Skip to content
Open access

THREAT MODELING OF AUTONOMOUS CODING AGENTS IN CORPORATE MOBILE DEVELOPMENT. PART 1: SYSTEM MODEL, ASSETS, TRUST BOUNDARIES, AND ATTACK SURFACES

Jul 2026 · Věda a perspektivy · 0 citations

TL;DR

The aim is to specify the system under analysis and to fix a reproducible threat-modeling methodology on which the remaining parts build, combining a data-flow diagram annotated with trust boundaries, attack-surface.

Abstract

. Autonomous coding agents built on large language models increasingly execute mobile-development tasks directly inside corporate environments, where they access a virtual private network (VPN) with multi-factor authentication (MFA), Jira, GitLab, application-signing keys, Model Context Protocol (MCP) extensions, plugins, git hooks, and isolated git worktrees on macOS workstations. Although individual attack vectors against tool-integrated agents — indirect prompt injection, memory poisoning, supply-chain compromise, secret leakage, and insecure code generation — are well studied in isolation, no integrated model captures the full developer-side agent toolchain as a single system. This article, the first of a four-part series, establishes the methodological and system-model foundation. Its aim is to specify the system under analysis and to fix a reproducible threat-modeling methodology on which the remaining parts build. The methodology is convergent, combining a data-flow diagram (DFD) annotated with trust boundaries, attack-surface

Read PDF

Similar papers

Review Aug 2026

When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling

This survey argues that four properties of that layer (irreversibility, signing authority, continuous autonomy, and sequence-level composition) qualitatively change the threat model, turning the recoverable failures of generic agent security into a standing, irreversible loss.

Rabimba Karanjai, Yang Lu, Nour Diallo et al. · 0 citations
Preprint Aug 2026

Agentic Security: A Systematization of Tools, Failure Modes, and Design Laws for LLM-Driven Penetration Testing

A four-dimensional Integration Friction Index is introduced that separates one-time engineering cost from recurring organisational, legal, and maintenance cost and shows why scope and budget enforcement cannot be delegated to system prompts.

Israt Moyeen Noumi, Tarannum Ahmed Nowshin, Md Mehedi Hasan Nipu et al. · 0 citations
Preprint Sep 2026

Scanning the Harness: An Empirical Study of Supply-Chain Defects in AI Coding-Agent Configurations

AI coding agents such as Claude Code, Cursor, GitHub Copilot, and OpenAI Codex are configured through artifacts developers write and share: instruction files, skills, hooks, MCP server declarations, subagents. This harness is a dependency layer installed from marketplaces and public repositories, running with the devel...

Benjamin Kapner, Carmel Soceanu, A. Petrunin et al. · 0 citations
Preprint Aug 2026

SynChain: Inducing Computer-Use Agent Systems to Construct Their Own Attack Chains

This work introduces SynChain, a self-synthesized attack paradigm utilizing persistence-aware directed supervised fine-tuning to induce agents to create poisoned yet benign-looking artifacts, proving that securing CUAs requires provenance-aware reasoning over cross-task execution trajectories.

Fuyao Zhang, Jiaming Zhang, Che Wang et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.