Skip to content
Search
paperSeptember 2026Unreviewed

A Blind Trust, the Bloody Thrust: When Attacker-Controlled Hook Updates Steer AI Agent Harnesses towards Malicious Behaviors

Pengxun Li, Litian Zhang, Jianwei Hou, Shujiang Wu, Song Li, Zifeng Kang, Xi Zhang

Abstract

Modern AI agent harnesses expose lifecycle hooks that bind shell commands to runtime events such as session start, tool calls, and file edits. These commands run with host privileges yet ship as lifecycle-hook configuration and may fire at times the LLM never observes. We identify the lifecycle-hook update path, which harnesses trust blindly, as a new attack surface. Under a supply-chain threat model in which an attacker controls only plugin metadata and lifecycle-hook configuration, a benign ve

Categories

Cite

@misc{li2026blind,
  title = {{A Blind Trust, the Bloody Thrust: When Attacker-Controlled Hook Updates Steer AI Agent Harnesses towards Malicious Behaviors}},
  author = {Pengxun Li and Litian Zhang and Jianwei Hou and Shujiang Wu and Song Li and Zifeng Kang and Xi Zhang},
  year = {2026},
  month = sep,
  eprint = {2609.03884},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.03884}
}