cs.SEMar 9, 2026

Arbiter: Detecting Interference in LLM Agent System Prompts

Authors: Tony Mason

Organizations: the University of British Columbia · the Georgia Institute of Technology

Abstract

System prompts for LLM-based coding agents are software artifacts that govern agent behavior, yet lack the testing infrastructure applied to conventional software. We present Arbiter, a framework combining formal evaluation rules with multi-model LLM scouring to detect interference patterns in system prompts. Applied to three major coding agent system prompts: Claude Code (Anthropic), Codex CLI (OpenAI), and Gemini CLI (Google), we identify 152 findings across the undirected scouring phase and 21 hand-labeled interference patterns in directed analysis of one vendor. We show that prompt architecture (monolithic, flat, modular) strongly correlates with observed failure class but not with severity, and that multi-model evaluation discovers categorically different vulnerability classes than single-model analysis. One scourer finding was structural data loss in Gemini CLI's memory system was consistent with an issue filed and patched by Google, which addressed the symptom without addressing the schema-level root cause identified by the scourer. Total cost of cross-vendor analysis: $0.27 USD.

Figures & tables

Appendix figures & tables5 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Just Ask: Curious Code Agents Reveal System Prompts in Frontier LLMs

    Jan 29, 2026Xiang Zheng, Yutao Wu, Hanxun Huang +5Prompt InjectionAI Coding Agents

  2. IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests

    Jul 22, 2026Ankur Singh, Jinqiu Yang, Tse-Hsun ChenAI Coding AgentsAI Agent Security