arXiv AI

Defenses & Enablers For Skill Injection Attacks on Terminal Based Agents

arXiv:2606. 01567v1 Announce Type: cross Abstract: Large language model (LLM) agents increasingly rely on reusable skills i.

arXiv AI
Sep 10

AgentLeak: Cloning Stronger LLM Agent Capabilities onto Weaker Agents Beyond Skill Stealing

The paper introduces AgentLeak, a black‑box attack that clones the task‑solving capabilities of a strong LLM agent onto a weaker one by exploiting differences between successful and failed executions. Unlike prior skill‑stealing methods that only recover explicit skill artifacts, AgentLeak identifies and incorporates missing procedural behaviors, boosting task pass rates by over 40% and closing more than 80% of the capability gap across 20 scenarios. The study demonstrates that observable execution behavior can leak proprietary procedural knowledge, posing a confidentiality risk for LLM agents.

By Xiaoting Lyu, Yuhong Wu, Yufei Han, Shichang Liu, Liang Zhang, Bin Wang, Bin Wang, Xiaobo Ma, Wei Wang
arXiv Computation and Language
Aug 25

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

The paper "SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents" investigates how agent skills—task‑specific instructions, scripts, and resources—can be exploited to create a trusted instruction channel that enables token amplification attacks. It introduces a two‑phase framework, SkillBloat, which first screens a library of attack‑type conditions across multiple amplification mechanisms and then refines the strongest candidate through LLM‑guided full‑document skill rewriting. Evaluated on a real‑world skill benchmark, SkillBloat achieves an average best amplification of 5.4184×–10.1455× across multiple coding‑agent target configurations, and an ablation study shows that the second‑stage refinement consistently improves performance over the initial screening alone.

By Yuanjin Zheng, Jingbang Chen
arXiv AI
2d ago

Chaining Skills to Hijack LLM Agents

arXiv:2610.01564v1 Announce Type: cross Abstract: LLM agents use skills to improve performance on specialized tasks. To complete a user request, an agent may invoke several skills in sequence, allowi...

By Tian Dong, Zixuan Ma, Haodong Zhao, Huaien Zhang, Shaofeng Li, Hao Chen
arXiv AI
Aug 28

Daydreaming: Stealing Hidden Agent Skills through Black-Box Task Interaction

Daydreaming is an execution‑only attack that steals multi‑file agent skills by interacting with a black‑box task service. By adaptively crafting tasks and analyzing the returned results, the attacker reconstructs the hidden skill without ever requesting or revealing it. In experiments on seven skills and four victim models, Daydreaming recovers 86.8% of the original capability using only 32 victim calls on average, outperforming prior methods and demonstrating that hiding skill files and filtering direct disclosure are insufficient defenses.

By Yu-Lin Tsai, Yu-An Lu, Ci-Yang Tsai, Muxi Lyu, Raluca Ada Popa, Chia-Mu Yu