Topowatch: Audits the Attack Success Rate of your workspace against indirect injection.
Tu agente de código lee tu workspace. Un archivo envenenado en cualquier rincón puede llevar instrucciones que el agente ejecuta. ¿Sabes qué fracción de tu workspace tiene que leer para que eso ocurra? topowatch mide eso. El problema no es el prompt, es la topología El paper Workspace Topology as an Attack Vector in Agentic Coding Assistants (arXiv:2608.14876, Day et al., 2026) demostró algo que…
Researchers have found that the topology of a workspace can affect the success rate of indirect injection attacks on coding assistants. A tool called topowatch has been developed to measure this success rate under different topology configurations. According to tests on a reference fixture, modular and deeply nested topologies show a significantly lower attack success rate than flat, monolithic ones.
Topowatch is available on GitHub under the AGPL-3.0-or-later license, and its author is Pedro Sordo Martínez. The tool's current version provides a modularity recommendation, with future versions planned to include measurements against real coding assistants.
Written by urgent.news from Dev.to's report — not a translation of it. Machine-written — may contain errors; check the original before relying on it.