The Risks of Code Assistant LLMs: Harmful Content, Misuse and Deception
ID: 2c6bf51e-1f23-54ba-be43-7cdd71292496
STIX ID: report--2c6bf51e-1f23-54ba-be43-7cdd71292496
Feed Name: Palo Alto Networks Unit 42
This Palo Alto Networks report examines security risks in LLM-based coding assistants, focusing on indirect prompt injection via attached external context, misuse of auto-completion to generate harmful content, and direct model invocation or stolen-session misuse. The authors demonstrate simulated scenarios where contaminated context leads the assistant to insert an obfuscated backdoor that fetches and executes commands from an attacker-controlled C2, discuss auto-complete jailbreaks and LLMJacking risks, and provide mitigations such as manual review, execution control, and tighter context handling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
