ResearchPrompt Injection Attacks on Agentic Coding Assistants SoK 78 StudiesarXiv·high signalXBlueskyLinkedInCopy linkFirst comprehensive systematization across 78 studies. Attack success rates exceed 85% against SOTA defenses. 42 distinct attack techniques cataloged. Architectural mitigations required.SourceSource pagearXiv↳ Follow the threadStack layer / Threat patternComments help LLM code generation only when they leak correct solution content, and comments from a different problem cut pass@1 by 20.8%arXiv 2609.09242Stack layer / ContrastCapScope stops prompt injection by giving each coding subagent typed capabilities stored outside its contextarXivStack layer / ContrastModels Spot Only 9.6% of Implementation Gaps in Research Specs but Fix 80.6% Once You Point Them OutarXiv 2609.10539Stack layer / ContrastSynthID Watermarking in Claude Costs Three Points of Code Correctness on One Model, but Detection Is Near ChancearXiv 2609.09604Policy dependency / ContrastA Fine-Tuned 4B Qwen in 2.6 GB Beats GPT-5.6 on a Transit-Kiosk Agent Benchmark, and PEFT Gains Vanish by 27BarXiv 2609.10016Stack layer / ContrastAudio prompt injection completes in 49% of cells where images complete in 1%, across 720 runs on six agent frameworksarXivStack layer / ContrastA2ABreak extracts a 37-state machine from the A2A spec and finds 11 protocol-level flaws that a fully compliant attacker can exploitarXivStack layer / ContrastCode-generation guardrails fail almost completely on code-to-code requests, and a fictional-scenario wrapper defeats them at near 100%arXiv 2609.09798