[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84669-en":3,"doc-seo-84669-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},84669,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","MOSAIC Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents","LLM coding agents increasingly complete development tasks by issuing ordinary CLI commands whose cooperation depends on shared operating-system state, allowing one command to write state later commands read. This Unix-style composability introduces an overlooked exploit surface: individually benign commands can form a producer-consumer relation across a command trace, creating CLI command-composition risk (CCR). MOSAIC systematically derives validated command-state behaviors from CVEs, advisories, and PoCs, composes them into exploit paths, and instantiates realistic workflows for blackbox evaluation, achieving a 96.59% attack success rate across 2,525 trials.","MOSAIC: Knowledge-Guided CLI Command Composition Attack in LLM Coding Agents  \nJiangrong Wu Sun Yat-sen University [wujr28@mail2.sysu.edu.cn](wujr28@mail2.sysu.edu.cn)  \nHuaijin Wang Shandong University [huaijinwang@sdu.edu.cn](huaijinwang@sdu.edu.cn)  \nYihao Zhang Peking University [zhangyihao@stu.pku.edu.cn](zhangyihao@stu.pku.edu.cn)  \nYuhong Nan Sun Yat-sen University [nanyh@mail.sysu.edu.cn](nanyh@mail.sysu.edu.cn)  \nShuai Wang Hong Kong University of Science and Technology  \n[shuaiw@cse.ust.hk](shuaiw@cse.ust.hk)  \narXiv :2607 .02857v 1 [ cs .CR] 3 Jul 2026  \nAbstract—LLM coding agents increasingly complete development tasks by issuing ordinary CLI commands. Following the Unix design, these commands cooperate through shared operating-system state: one command may write state that a later command reads. While this composition is benign and intended, it creates an overlooked exploit surface. Existing attacks and defenses mainly target the instruction layer, where malicious intent appears as hostile text. In contrast, we observe that individually benign commands can form a dangerous producerconsumer state relation across the command trace, exposing what we call CLI command-composition risk (CCR).  \nGiven this new attack surface, it is critical to systematically uncover and characterize the impact of CCR in real-world coding agents. However, systematically understanding this risk is quite challenging, because naive command enumeration and end-to-end LLM generation produce mostly invalid workflows. We present MOSAIC, a knowledge-guided framework that distills validated command-state behaviors from CVEs, advisories, and researcher PoCs into reusable summaries, composes them into exploit paths, and instantiates them as realistic developer workflows for blackbox agent evaluation. Across five real-world CLI coding agents and five backend LLMs over 2,525 trials, MOSAIC achieves a 96.59% attack success rate under benign developer tasks.  \nIndex Terms—LLM Coding Agents, CLI Security, Command Composition Risk  \nI. INTRODUCTION  \nLLM coding agents are rapidly upgrading from code assistants into automatic program development agents. A growing number of them run directly in the command-line interface (CLI) and act by issuing ordinary CLI commands, so the LLM coding agent [1]–[5], such as Claude Code and Codex CLI, is becoming the mainstream form. Such an agent operates inside a real development environment, where it clones repositories, inspects project files, installs dependencies, runs tests, edits configuration, and prepares code changes. Its execution substrate is the same CLI layer that human developers use everyday, including command-line such as git, npm, bash, curl. As shown in Figure 1, given a user’s natural-language request, the agent interprets it as a sequence of ordinary CLI commands that serve the user’s intent. These commands are designed to work together, a defining principle of the Unix philosophy in which each command does one sub-task well and passes its output to the next [6],[7] . Each command performs a  \nLLM Coding Agent  \nFig. 1: Among existing LLM coding agents, user tasks are typically handled with combinations of CLI commands.  \nfocused step and passes its result to later commands through the same shared operating-system state, so that a small set of ordinary commands can compose to accomplish complex development tasks. This shared state includes environment variables, the file system, package lifecycle scripts, and hooks. One command can write state that a later command reads, so the commands form a stateful trace whose later steps depend on the state that earlier steps leave behind.  \nIn LLM coding agent, this CLI substrate directly reaches the user’s system and software production environment. Once they are compromised, the security impact falls on highvalue development assets. An attacker can wipe developer and production data [8], exfiltrate proprietary source code and credentials [9], [10], poison the d","cbCaieREAQHLMooD","https://ap.wps.com/l/cbCaieREAQHLMooD","pdf",2442995,1,12,"English","en",105,"# Introduction\n## LLM coding agents and CLI execution model\n## Instruction-layer attacks and defenses\n## CLI command-composition risk","[{\"question\":\"What is CLI command-composition risk (CCR) in LLM coding agents?\",\"answer\":\"CCR is an exploit surface where individually benign CLI commands can form a dangerous producer-consumer state relation across a command trace, due to shared operating-system state.\"},{\"question\":\"Why is understanding CCR challenging for defenders?\",\"answer\":\"Naive command enumeration and end-to-end LLM generation tend to produce mostly invalid workflows, making systematic characterization difficult.\"},{\"question\":\"How does MOSAIC evaluate and generate realistic CCR attacks?\",\"answer\":\"MOSAIC distills validated command-state behaviors from CVEs, advisories, and researcher PoCs into reusable summaries, composes them into exploit paths, and instantiates them as realistic developer workflows for blackbox agent evaluation.\"}]",1784197571,30,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"mosaic-knowledge-guided-cli-command-composition-attack-in-llm-coding-agents","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/mosaic-knowledge-guided-cli-command-composition-attack-in-llm-coding-agents/84669/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is CLI command-composition risk (CCR) in LLM coding agents?","Question",{"text":75,"@type":76},"CCR is an exploit surface where individually benign CLI commands can form a dangerous producer-consumer state relation across a command trace, due to shared operating-system state.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why is understanding CCR challenging for defenders?",{"text":80,"@type":76},"Naive command enumeration and end-to-end LLM generation tend to produce mostly invalid workflows, making systematic characterization difficult.",{"name":82,"@type":73,"acceptedAnswer":83},"How does MOSAIC evaluate and generate realistic CCR attacks?",{"text":84,"@type":76},"MOSAIC distills validated command-state behaviors from CVEs, advisories, and researcher PoCs into reusable summaries, composes them into exploit paths, and instantiates them as realistic developer workflows for blackbox agent evaluation.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":28,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":45,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":45,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":45,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]