One Issue Breaks Through 79% of the Time: The Trust Boundary Coding Agents Need
IssueTrojanBench shows coding-agent guardrails failing up to 79% of the time against issues that hide instructions in plain sight — here's the trust-boundary checklist that follows.
- IssueTrojanBench found 79.2% of disguised issues bypassed Codex Desktop, 66.5% bypassed Cursor, and 41.1% bypassed Claude Code.
- In a real incident Microsoft confirmed, a missing isolation layer on the Read tool let an issue-borne instruction exfiltrate the ANTHROPIC_API_KEY.
- The Agents Rule of Two, least-privilege tokens, and approval gates on state-changing actions cut the odds of a benchmark number becoming a real incident.





























































































































