Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation
Sanket Badhe, Priyanka Tiwari
cs.CR
Submitted: 2026-07-15
Code: https://github.com/openai/openai-agents
License: http://creativecommons.org/licenses/by/4.0/
The gist: Reusable skills are becoming a fundamental building block of Large Language Model (LLM) agents, enabling capabilities to be packaged, shared, and reused across diverse applications.
Terminology
Abstract
Reusable skills are becoming a fundamental building block of Large Language Model (LLM) agents, enabling capabilities to be packaged, shared, and reused across diverse applications. However, existing security research primarily focuses on prompt injection and runtime execution, leaving security risks throughout the broader skill lifecycle largely unexplored. In this paper, we present SkillSec-Eval, a lifecycle-aware framework for systematically evaluating the security of reusable agent skills. We first characterize the skill lifecycle and develop a threat taxonomy spanning repository admission, semantic retrieval, planner selection, execution, and skill evolution. We then instantiate this taxonomy in SkillSec-Eval and conduct a comprehensive empirical evaluation using a repository of 327 real-world skills. Our study demonstrates that vulnerabilities arise at multiple lifecycle stages beyond execution, highlighting the need for lifecycle-aware security analysis of reusable agent skills.
Sources
- Formal Analysis and Supply Chain Security for Agentic AI Skills
- AgentBound: Securing Execution Boundaries of AI Agents
- SkillProbe: Security Auditing for Emerging Agent Skill Marketplaces via Multi-Agent Collaboration
- Exploiting LLM Agent Supply Chains via Payload-less Skills
- "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild
- Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
- Backstabber's Knife Collection: A Review of Open Source Software Supply Chain Attacks
- Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
- Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks
- ReAct: Synergizing Reasoning and Acting in Language Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs