New benchmark evaluation: Kavach vs. real prompt-injection attacks (KavachBench) An independent researcher's first paper, KavachBench, evaluated Kavach, a policy-enforcement runtime for AI coding agents, against IssueTrojanBench's corpus of 42 malicious tool-call actions drawn from GitHub issue payloads. The researcher reported that Kavach's coverage came from adapter canonicalization under a default-deny policy rather than benchmark-specific policy tuning, a distinction the researcher said matters for anyone evaluating similar guardrails. The researcher is seeking a cs.CR arXiv endorser for the first submission to arXiv. Sharing my first research paper as an independent researcher — I evaluated Kavach, a policy-enforcement runtime for AI coding agents, against IssueTrojanBench’s real prompt-injection attack corpus 42 malicious tool-call actions from GitHub issue payloads . Key finding: coverage comes from adapter canonicalization under a default-deny policy, not from benchmark-specific policy tuning — a distinction that matters for anyone evaluating similar guardrails. Feedback welcome, and if anyone can point me to a cs.CR arXiv endorser, that’d help a lot — this is my first submission there.