Skip to content
#software testing Dataset Open access

Artifact for "Prompt Pipelines as Engineered Artifacts: Regression-Testing a Multi-Agent Threat-Modeling Pipeline"

Aug 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

Replication and verification material for the PROMPTOPS 2026 paper "Prompt Pipelines asEngineered Artifacts: Regression-Testing a Multi-Agent Threat-Modeling Pipeline",presented at the 1st International Workshop on PromptOps and Vibe Coding, co-located withthe 41st IEEE/ACM International Conference on Automated Software Engineering (ASE 2026),Munich, 12-16 October 2026. The paper reports engineering experience from treating a multi-agent STRIDE threat-modelingpipeline as a set of versioned, regression-tested prompt artifacts: modular role prompts,typed inter-stage contracts, pipeline hyperparameters promoted out of code into versionedconfiguration, and a fixed corpus of 24 system architectures with 745 expert-curatedreference threats acting as a regression oracle with cost-aware metrics. This deposit contains: - 24 system architectures across five domains, normalised to a unified YAML schema, and their 745 expert-curated reference threats;- raw output for 8 pipeline variants across all 24 architectures (192 runs), including per-agent and per-stage run metadata;- the aggregate evaluation data behind Table 1 of the paper;- the prompt artifacts: category-agent, retrieval-query, auditor, corrector and risk-scoring prompts, per variant;- a code-only snapshot of the pipeline framework;- verify/verify_claims.py, which recomputes every quantitative claim in the paper and reports PASS, FAIL, or UNSUPPORTED for each. The verification script is the point of the deposit. It currently reports 29 passed, 1failed and 2 unsupported, and that result is intentional: it exposes two reporting defectsthat the paper's camera-ready text addresses in the open, rather than leaving a reader tofind them. UNSUPPORTED marks a claim the retained archive cannot establish. Two limitations of the archive are load-bearing and are documented in MANIFEST.md ratherthan left to be discovered. Risk scoring was enabled for only 7 of the 24 architectures, sothe risk-calibration column aggregates 6 or 7 cells per variant rather than 24. The trialruns that decided the removal of the chunk-filtered retrieval stage were not retained, andneither were the curated extended reference lists; the aggregate values and the outputs theexpansion was drawn from survive, the promotion decisions do not. Not included: the retrieval knowledge base built over CVE, CWE, MITRE CAPEC and ATT&CK, andOWASP material, whose redistribution terms differ from this deposit's licence.framework/KNOWLEDGE_BASE.md records its contents, the provenance of each source, and thecommand that rebuilds the index. No API credentials are included; build_package.py scansthe assembled package for credentials and personal data and fails if it finds any. Licence: the code is MIT. The architecture descriptions and reference threat lists areaggregated from open repositories of published threat-modeling examples and retain theirupstream terms; per-architecture provenance is in dataset/README.md. Reproducing a pipeline run end to end requires an OpenRouter API key and a rebuiltknowledge base. Note that LLM output varies between runs even at the pinned inferencesettings, so a fresh run will not reproduce the archived outputs exactly. The archive holdsone run per (architecture, variant) cell; this single-run limitation is discussed in thepaper.

View source

Similar papers

#computer vision Review Sep 2017

Agile Software Development Methods: Review and Analysis

Agile - denoting "the quality of being agile, readiness for motion, nimbleness, activity, dexterity in motion" - software development methods are attempting to offer an answer to the eager business community asking for lighter weight along with faster and nimbler software development processes. This is especially the case with the rapidly growing and volatile Internet software industry as well as for the emerging mobile application environment. The new agile methods have evoked substantial amount of literature and debates. However, academic research on the subject is still scarce, as most of existing publications are written by practitioners or consultants. The aim of this publication is to begin filling this gap by systematically reviewing the existing literature on agile software development methodologies. This publication has three purposes. First, it proposes a definition and a classification of agile software development approaches. Second, it analyses ten software development methods that can be characterized as being "agile" against the defined criterion. Third, it compares these methods and highlights their similarities and differences. Based on this analysis, future research needs are identified and discussed.

P. Abrahamsson, O. Salo, Jussi Ronkainen et al. · 728 citations · ⚡54
#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

Context: Software startups are newly created companies with no operating history and fast in producing cutting-edge technologies. These companies develop software under highly uncertain conditions, tackling fast-growing markets under severe lack of resources. Therefore, software startups present a unique combination of characteristics which pose several challenges to software development activities. Objective: This study aims to structure and analyze the literature on software development in startup companies, determining thereby the potential for technology transfer and identifying software development work practices reported by practitioners and researchers. Method: We conducted a systematic mapping study, developing a classification schema, ranking the selected primary studies according their rigor and relevance, and analyzing reported software development work practices in startups. Results: A total of 43 primary studies were identified and mapped, synthesizing the available evidence on software development in startups. Only 16 studies are entirely dedicated to software development in startups, of which 10 result in a weak contribution (advice and implications (6); lesson learned (3); tool (1)). Nineteen studies focus on managerial and organizational factors. Moreover, only 9 studies exhibit high scientific rigor and relevance. From the reviewed primary studies, 213 software engineering work practices were extracted, categorized and analyzed. Conclusion: This mapping study provides the first systematic exploration of the state-of-art on software startup research. The existing body of knowledge is limited to a few high quality studies. Furthermore, the results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#computer vision Open access Jul 2017

What happens when software developers are (un)happy

The growing literature on affect among software developers mostly reports on the linkage between happiness, software quality, and developer productivity. Understanding happiness and unhappiness in all its components -- positive and negative emotions and moods -- is an attractive and important endeavor. Scholars in industrial and organizational psychology have suggested that understanding happiness and unhappiness could lead to cost-effective ways of enhancing working conditions, job performance, and to limiting the occurrence of psychological disorders. Our comprehension of the consequences of (un)happiness among developers is still too shallow, being mainly expressed in terms of development productivity and software quality. In this paper, we study what happens when developers are happy and unhappy while developing software. Qualitative data analysis of responses given by 317 questionnaire participants identified 42 consequences of unhappiness and 32 of happiness. We found consequences of happiness and unhappiness that are beneficial and detrimental for developers' mental well-being, the software development process, and the produced artifacts. Our classification scheme, available as open data enables new happiness research opportunities of cause-effect type, and it can act as a guideline for practitioners for identifying damaging effects of unhappiness and for fostering happiness on the job.

D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al. · 236 citations · ⚡13
#computer vision Open access Oct 2004

Mobile-D: an agile approach for mobile application development

Mobile phones have been closed environments until recent years. The change brought by open platform technologies such as the Symbian operating system and Java technologies has opened up a significant business opportunity for anyone to develop application software such as games for mobile terminals. However, developing mobile applications is currently a challenging task due to the specific demands and technical constraints of mobile development. Furthermore, at the moment very little is known about the suitability of the different development processes for mobile application development. Due to these issues, we have developed an agile development approach called Mobile-D. The Mobile-D approach is briefly outlined here and the experiences gained from four case studies are discussed.

P. Abrahamsson, Antti Hanhineva, H. Hulkko et al. · 225 citations · ⚡18

Related blog posts

MIT News · Artificial Intelligence Aug 17, 2026

Q&A: Rethinking how innovation happens

In his latest book, Professor Eugene Fitzgerald examines the forces that turn breakthroughs into value — and why innovation resists simple formulas.