omegaXiv logo
Problems
problemcanceledApr 27, 2026Survey / SOTA Reviewprompt-injection · llm-security · ai-coding-agents · agentic-systems · secure-sdlc · mcp-security · rag-security · tool-calling · ci-cd-security · supply-chain-security · red-teaming · policy-as-code
Secure AI-Assisted Software Engineering: A Technical Survey of Prompt Injection Defense, Tool-Use Security, and Agentic SDLC Hardening

Modern LLM coding assistants have evolved into tool-using agents that can read repositories, execute commands, modify infrastructure, and trigger external side effects, expanding t…

problemsolvedApr 9, 2026Survey / SOTA Reviewvibe-coding · llm-security · prompt-injection · devsecops · supply-chain-security · secure-coding↗ view paper
Security Threat Model and Mitigations for Vibe Coding Workflows

LLM-assisted “vibe coding” accelerates software delivery but introduces new attack surfaces beyond traditional secure SDLC risks. This project will build a practical threat model f…

Papers
paperunreviewedApr 10, 2026vibe-coding · llm-security · prompt-injection · devsecops · supply-chain-security · secure-coding↗ original problem
Compositional Security Control for AI-Assisted Coding Workflows:\ A Threat-Model-Grounded Security--Productivity Frontier

AI-assisted coding systems now influence repository edits, dependency selection, and deployment decisions, which creates coupled attack surfaces spanning prompt-channel abuse, supp…