[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83997-en":3,"doc-seo-83997-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83997,7971461740909,"Levi","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","The Balkanization of Execution Security Research for AI Coding Agents","AI coding agents now execute repository reads, tool calls, and shell commands with limited oversight, prompting research on whether their execution layers are secure. The literature is fragmented across sandbox isolation, capability and access control, policy enforcement, TOCTOU races, MCP threats, identity delegation, execution provenance, network egress control, and static analysis, with little cross-category citation. This SoK systematizes 39 papers (2023–2026) into 17 mechanism categories, verifies sources directly, confirms four patched CVEs, and derives five crosscutting research gaps plus an agenda.","The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities  \nMohammadreza Rashidi   \nDepartment of Computer Science  \nAI and Media Analysis Lab  \nBerlin, Germany  \n[mohammadreza.rashidi@ue-germany.de](mohammadreza.rashidi@ue-germany.de)  \narXiv :2607 .05743v 1 [ cs .CR] 7 Jul 2026  \nAbstract—AI coding agents now read repositories, call tools, and execute shell commands with limited human oversight, and a fast-growing body of work studies whether the execution layer around them is actually safe. That literature is scattered: papers on sandbox isolation, capability and access control, policy enforcement, time-of-check-to-time-of-use (TOCTOU) races, Model Context Protocol (MCP) threats, identity delegation, execution provenance, network egress control, and static analysis of agent-generated code are published independently, rarely cite one another across categories, and no existing survey organizes them by execution-security mechanism. We systematize 39 papers published between 2023 and 2026 into 17 categories, each verified directly against its source rather than taken from a secondary summary; the same verification protocol also confirms four disclosed, patched CVEs directly affecting production agent harnesses, showing the concern isnot speculative. Reading across categories surfaces five crosscutting gaps that no single paper addresses: isolation architectures and capability models are evaluated against attacker capability, but almost never against one another on a shared benchmark; policy-enforcement studies report failure rates from 69% to 98% of real denylists yet no isolation paper re-evaluates its own defense under that adversarial setting; TOCTOU and MCP threats are analyzed as separate literatures despite both being instances of the same state-validation problem; every enforcement mechanism we review assumesan honest policy author, leaving policy-authoring error itself unaddressed; and a newly measured failure mode, benign but out-of-scope agent actions occurring at rates up to 17.1% under realistic prompting, is addressed by no access-control or capability paper in our corpus. We also find that three existing broader surveys of agentic AI security discuss sandboxing only as one item among many defenses, leaving execution security without a dedicated systematization; this paper is written to fill that specific gap. We conclude with a research agenda directed at the five gaps rather than at restating the individual papers’own stated future work.  \nIndex Terms—AI agents, execution security, sandboxing, access control, systematization of knowledge, Model Context Protocol, TOCTOU  \n1. Introduction  \nAn AI coding agent is only as safe as the environment it executes in. Modern agent harnesses, terminal-based assistants, autonomous coding agents, and browser-use agents, give a language model the ability to read files, run shell commands, call external tools, and in many deployments do so with limited or no human confirmation per action. The last two years have produced a large body of work asking whether the execution layer around these agents is actually safe: whether the sandbox holds, whether the access-control policy is enforced, whether a state check can be invalidated between the time it is made and the time it is acted on, and whether the tool-calling protocol itself carries new attack surface. This is a different question from whether the model’s outputs are aligned or its prompts are safe; it is a systems-security question about the boundary between the agent and the machine it runs on.  \nThat literature is scattered. A paper on container sandbox escape does not cite the paper on denylist fragility; a paper proposing a capability framework for coding agents does not engage with the empirical finding that most production policies fail to hold; a Model Context Protocol threat model and a browser-agent TOCTOU paper describe what is s","cbCaig6OGTZbrqnk","https://ap.wps.com/l/cbCaig6OGTZbrqnk","pdf",1005745,5,1,18,"English","en",105,"# Introduction\n## Systematization of Knowledge (SoK) Approach\n## Execution-Security Scope and Motivation\n## Evidence via Verified CVEs","[{\"question\":\"What security question does this paper focus on for AI coding agents?\",\"answer\":\"Whether the execution layer around AI coding agents is safe—specifically the sandbox boundary, access-control enforcement, state-validation races like TOCTOU, and tool-calling attack surface.\"},{\"question\":\"How does the paper organize the execution-security literature?\",\"answer\":\"It systematizes 39 papers published between 2023 and 2026 into 17 categories based on the execution-security mechanism each paper addresses.\"},{\"question\":\"What evidence does the paper provide that execution-security concerns are real?\",\"answer\":\"During verification, it confirms four disclosed and patched CVEs directly relevant to production agent harnesses, including container-runtime escape and code/data injection issues in agent tooling.\"}]",1784191927,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"the-balkanization-of-execution-security-research-for-ai-coding-agents","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/the-balkanization-of-execution-security-research-for-ai-coding-agents/83997/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What security question does this paper focus on for AI coding agents?","Question",{"text":76,"@type":77},"Whether the execution layer around AI coding agents is safe—specifically the sandbox boundary, access-control enforcement, state-validation races like TOCTOU, and tool-calling attack surface.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the paper organize the execution-security literature?",{"text":81,"@type":77},"It systematizes 39 papers published between 2023 and 2026 into 17 categories based on the execution-security mechanism each paper addresses.",{"name":83,"@type":74,"acceptedAnswer":84},"What evidence does the paper provide that execution-security concerns are real?",{"text":85,"@type":77},"During verification, it confirms four disclosed and patched CVEs directly relevant to production agent harnesses, including container-runtime escape and code/data injection issues in agent tooling.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]