paper-with-me

홈 › Papers

Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry

2026-05-12 · Shoumik Saha, Kazem Faghih, Soheil Feizi arxiv

Autonomous AI agents increasingly extend their capabilities through Agent Skills: modular filesystem packages whose SKILL.md files describe when and how agents should use them. While this design enables scalable, on-demand capability expansion, it also introduces a semantic supply-chain risk in which natural-language metadata and instructions can affect which skills are admitted, surfaced, selected, and loaded. We study SKILL.md - only attacks across three registry-facing stages of the Agent Skill lifecycle, using real ClawHub skills and realistic registry mechanisms. In Discovery, short textual triggers can manipulate embedding-based retrieval and improve adversarial skill visibility, achieving up to 86% pairwise win rate and 80% Top-10 placement. In Selection, description-only framing biases agents toward functionally equivalent adversarial variants, which are selected in 77.6% of paired trials on average. In Governance, semantic evasion strategies cause malicious skills to avoid a blocking verdict in 36.5%-100% of cases. Overall, our results show that SKILL.md is not passive documentation but operational text that shapes which third-party capabilities agents find, trust, and use.

📄 PDF Abstract BibTeX arXiv:2605.11418

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Formal Analysis and Supply Chain Security for Agentic AI Skills

2026-02-27 · Varun Pratap Bhardwaj arxiv

The rapid proliferation of agentic AI skill ecosystems -- exemplified by OpenClaw (228,000 GitHub stars) and Anthropic Agent Skills (75,600 stars) -- has introduced a critical supply chain attack surface. The ClawHavoc c…

Benchmarking Security Risk Detection and Verification in Open Agentic Skill Ecosystems

2026-05-30 · Ismail Hossain, Sai Puppala, Zhuoran Lu, Sajedul Talukder 외 arxiv

Open agent platforms allow community contributors to publish reusable skills that agents can invoke at runtime. This extensibility also creates a supply-chain risk: malicious contributors can hide harmful behavior inside…

BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning

2026-04-10 · Guiyao Tie, Jiawen Shi, Pan Zhou, Lichao Sun arxiv

Agent ecosystems increasingly rely on installable skills to extend functionality, and some skills bundle learned model artifacts as part of their execution logic. This creates a supply-chain risk that is not captured by …

Decoding excellence: Mapping the demand for psychological traits of operations and supply chain professionals through text mining

2024-03-26 · S. Di Luozzo, A. Fronzetti Colladon, M. M. Schiraldi

The current study proposes an innovative methodology for the profiling of psychological traits of Operations Management (OM) and Supply Chain Management (SCM) professionals. We use innovative methods and tools of text mi…

Management

Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems

2026-04-03 · Yubin Qu, Yi Liu, Tongcheng Geng, Gelei Deng 외 arxiv

LLM-based coding agents extend their capabilities via third-party agent skills distributed through open marketplaces without mandatory security review. Unlike traditional packages, these skills are executed as operationa…