Aletheia: Permission-Minimality Testing for Coding-Agent Rules

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the vulnerability of coding agent instruction files to prompt injection attacks that facilitate credential theft, proposing a testing framework grounded in the principle of least privilege. Methodologically, permission requests are formalized as a type language to automatically synthesize sandbox configurations, with functionality verified in restricted environments via incremental removal techniques. Furthermore, this work introduces a novel "exemptibility witness" mechanism that rigorously formalizes the interface conditions between permission synthesis and enforcement constraints. Experimental evaluations demonstrate that the proposed approach successfully detects all 314 AIShellJack attack samples without misclassifying benign inputs, achieving a false positive rate of merely 3.75% on real-world rule sets.
📝 Abstract
Repository instruction files guide coding agents, but also expose them to prompt injection. Malicious rules can request credential access or data transfer while the agent produces a correct patch. We present Aletheia, a framework for permission-minimality testing. Aletheia translates requested authority into a typed language and synthesizes executable sandbox configurations. It runs the unchanged rule and task under full permissions and independent restrictions that remove one permission at a time. Passing independent functional tests under strictly reduced authority provides a dispensability witness, which Aletheia interprets against task context to diagnose suspicious requests. We formalize synthesis and the conditions connecting witnesses to enforced restrictions. On a shared refactoring task, Aletheia executes and detects all 314 AIShellJack attack inputs, with no alarms on five benign templates. Among 80 manually verified benign GHAgentFiles rules, it raises three false positives (3.75%).
Problem

Research questions and friction points this paper is trying to address.

prompt injection
coding agents
permission minimality
repository instruction files
security testing
Innovation

Methods, ideas, or system contributions that make the work stand out.

Permission-Minimality Testing
Prompt Injection
Sandbox Synthesis
Dispensability Witness
Coding Agents