Trust but Verify? Uncovering the Security Debt of Autonomous Coding Agents
This paper presents a large-scale empirical study using the AIDev dataset to systematically characterize security code smells in agent-generated pull requests (PRs), finding that human collaborators are responsible for introducing 67.6% of genuine leaked secrets within these agent-assisted workflows.