Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems
cs.AI
Submitted: 2026-09-24
Updated: 2026-09-24
Code: https://github.com/cisco-ai-defense/defenseclaw
Terminology
Sources
- Defeating Prompt Injections by Design
- SkillProbe: Security Auditing for Emerging Agent Skill Marketplaces via Multi-Agent Collaboration
- Defending Against Indirect Prompt Injection Attacks With Spotlighting
- SkillJect: Effectively Automating Skill-Based Prompt Injection for Skill-Enabled Agents
- Kimi K2.5: Visual Agentic Intelligence
- SHADE-Arena: Evaluating Sabotage and Monitoring in LLM Agents
- STAC: When Innocent Tools Form Dangerous Chains for LLM Agents
- AgentDoG: A Diagnostic Guardrail Framework for AI Agent Safety and Security
- "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the Wild
- Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
- Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis of Vulnerabilities in Skills, Tools, and Protocol Ecosystems
- Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
- Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections
- Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks
- Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
- BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
- SkillTester: Benchmarking Utility and Security of Agent Skills
- Qwen3 Technical Report
- ClawGuard: A Runtime Security Framework for Tool-Augmented LLM Agents Against Indirect Prompt Injection
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection