May 2026Unreviewed
Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks
Yubin Qu, Ying Zhang, Yanjun Zhang, Gelei Deng, Yuekang Li, Leo Yu Zhang, Yi Liu
Abstract
Coding agents now run autonomously with shell, file, and network privileges. When a user issues a benign request, the agent sometimes does more than asked: it deletes unrelated files, wipes a stale credentials backup, or rewrites configuration the user never mentioned. We call these scope expansions overeager actions, an authorization problem distinct from capability failures, prompt injection, or sandbox escapes. We present OverEager-Gen, a benchmark dedicated to overeager behavior on benign ta
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{qu2026overeager,
title = {{Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks}},
author = {Yubin Qu and Ying Zhang and Yanjun Zhang and Gelei Deng and Yuekang Li and Leo Yu Zhang and Yi Liu},
year = {2026},
month = may,
eprint = {2605.18583},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.18583}
}