IssueTrojanBench Evaluates Security of AI Coding Agents
July 24, 2026
IssueTrojanBench benchmarks coding agents like Cursor and Claude Code against four categories of malicious issue requests. The study tests model families including GPT-5.3/5.4 and Sonnet 4.6 for vulnerabilities like data exfiltration and persistent environment compromise through tool-using autonomy.
HOW THIS AFFECTS YOU
●
builderYou should audit how your agents handle autonomous tool access to prevent induced misuse.
●
policyThis highlights critical safety risks in agentic workflows that require regulatory oversight.