When Skills Lie: Hidden-Comment Injection in LLM Agents
Fuente:
arXiv
Salvato in:
| Autori principali: | Wang, Qianli, Ma, Boyang, Xu, Minghui, Zhang, Yue |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
di: Wang, Yihan, et al.
Pubblicazione: (2025)
di: Wang, Yihan, et al.
Pubblicazione: (2025)
The Agent Economy: A Blockchain-Based Foundation for Autonomous AI Agents
di: Xu, Minghui
Pubblicazione: (2026)
di: Xu, Minghui
Pubblicazione: (2026)
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
di: Ma, Boyang, et al.
Pubblicazione: (2026)
di: Ma, Boyang, et al.
Pubblicazione: (2026)
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
di: Wang, Reachal, et al.
Pubblicazione: (2025)
di: Wang, Reachal, et al.
Pubblicazione: (2025)
AgentDID: Trustless Identity Authentication for AI Agents
di: Xu, Minghui, et al.
Pubblicazione: (2026)
di: Xu, Minghui, et al.
Pubblicazione: (2026)
SkillJect: Effectively Automating Skill-Based Prompt Injection for Skill-Enabled Agents
di: Jia, Xiaojun, et al.
Pubblicazione: (2026)
di: Jia, Xiaojun, et al.
Pubblicazione: (2026)
Black-Box Skill Stealing Attack from Proprietary LLM Agents: An Empirical Study
di: Wang, Zihan, et al.
Pubblicazione: (2026)
di: Wang, Zihan, et al.
Pubblicazione: (2026)
Prompt Injection Attack to Tool Selection in LLM Agents
di: Shi, Jiawen, et al.
Pubblicazione: (2025)
di: Shi, Jiawen, et al.
Pubblicazione: (2025)
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
di: Ying, Zonghao, et al.
Pubblicazione: (2026)
di: Ying, Zonghao, et al.
Pubblicazione: (2026)
Beyond Model Jailbreak: Systematic Dissection of the "Ten DeadlySins" in Embodied Intelligence
di: Huang, Yuhang, et al.
Pubblicazione: (2025)
di: Huang, Yuhang, et al.
Pubblicazione: (2025)
Don't believe everything you read: Understanding and Measuring MCP Behavior under Misleading Tool Descriptions
di: Li, Zhihao, et al.
Pubblicazione: (2026)
di: Li, Zhihao, et al.
Pubblicazione: (2026)
When Scanners Lie: Evaluator Instability in LLM Red-Teaming
di: Erez, Lidor, et al.
Pubblicazione: (2026)
di: Erez, Lidor, et al.
Pubblicazione: (2026)
Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
di: Huang, Yuhang, et al.
Pubblicazione: (2026)
di: Huang, Yuhang, et al.
Pubblicazione: (2026)
Assessing Deanonymization Risks with Stylometry-Assisted LLM Agent
di: Zhang, Boyang, et al.
Pubblicazione: (2026)
di: Zhang, Boyang, et al.
Pubblicazione: (2026)
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
di: Liu, Shi, et al.
Pubblicazione: (2026)
di: Liu, Shi, et al.
Pubblicazione: (2026)
Everything You Wanted to Know About LLM-based Vulnerability Detection But Were Afraid to Ask
di: Li, Yue, et al.
Pubblicazione: (2025)
di: Li, Yue, et al.
Pubblicazione: (2025)
Silent Egress: When Implicit Prompt Injection Makes LLM Agents Leak Without a Trace
di: Lan, Qianlong, et al.
Pubblicazione: (2026)
di: Lan, Qianlong, et al.
Pubblicazione: (2026)
The Landscape of Prompt Injection Threats in LLM Agents: From Taxonomy to Analysis
di: Wang, Peiran, et al.
Pubblicazione: (2026)
di: Wang, Peiran, et al.
Pubblicazione: (2026)
When Your Reviewer is an LLM: Biases, Divergence, and Prompt Injection Risks in Peer Review
di: Zhu, Changjia, et al.
Pubblicazione: (2025)
di: Zhu, Changjia, et al.
Pubblicazione: (2025)
I'm Spartacus, No, I'm Spartacus: Measuring and Understanding LLM Identity Confusion
di: Li, Kun, et al.
Pubblicazione: (2024)
di: Li, Kun, et al.
Pubblicazione: (2024)
We Urgently Need Privilege Management in MCP: A Measurement of API Usage in MCP Ecosystems
di: Li, Zhihao, et al.
Pubblicazione: (2025)
di: Li, Zhihao, et al.
Pubblicazione: (2025)
When Safe Skills Collide: Measuring Compositional Risk in Agent Skill Ecosystems
di: Wang, Su, et al.
Pubblicazione: (2026)
di: Wang, Su, et al.
Pubblicazione: (2026)
PINA: Prompt Injection Attack against Navigation Agents
di: Liu, Jiani, et al.
Pubblicazione: (2026)
di: Liu, Jiani, et al.
Pubblicazione: (2026)
To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
di: Wang, Zhilong, et al.
Pubblicazione: (2025)
SAGE: Signal-Amplified Guided Embeddings for LLM-based Vulnerability Detection
di: Shan, Zhengyang, et al.
Pubblicazione: (2026)
di: Shan, Zhengyang, et al.
Pubblicazione: (2026)
Do Skill Descriptions Tell the Truth? Detecting Undisclosed Security Behaviors in Code-Backed LLM Skills
di: He, Wenhui, et al.
Pubblicazione: (2026)
di: He, Wenhui, et al.
Pubblicazione: (2026)
Keeping an Eye on LLM Unlearning: The Hidden Risk and Remedy
di: Ren, Jie, et al.
Pubblicazione: (2025)
di: Ren, Jie, et al.
Pubblicazione: (2025)
SkillTester: Benchmarking Utility and Security of Agent Skills
di: Wang, Leye, et al.
Pubblicazione: (2026)
di: Wang, Leye, et al.
Pubblicazione: (2026)
The Trust Paradox in LLM-Based Multi-Agent Systems: When Collaboration Becomes a Security Vulnerability
di: Xu, Zijie, et al.
Pubblicazione: (2025)
di: Xu, Zijie, et al.
Pubblicazione: (2025)
The Vulnerability of LLM Rankers to Prompt Injection Attacks
di: Yin, Yu, et al.
Pubblicazione: (2026)
di: Yin, Yu, et al.
Pubblicazione: (2026)
Don't Let the Claw Grip Your Hand: A Security Analysis and Defense Framework for OpenClaw
di: Shan, Zhengyang, et al.
Pubblicazione: (2026)
di: Shan, Zhengyang, et al.
Pubblicazione: (2026)
Breaking Agents: Compromising Autonomous LLM Agents Through Malfunction Amplification
di: Zhang, Boyang, et al.
Pubblicazione: (2024)
di: Zhang, Boyang, et al.
Pubblicazione: (2024)
Credential Leakage in LLM Agent Skills: A Large-Scale Empirical Study
di: Chen, Zhihao, et al.
Pubblicazione: (2026)
di: Chen, Zhihao, et al.
Pubblicazione: (2026)
Dataset Ownership in the Era of Large Language Models
di: Li, Kun, et al.
Pubblicazione: (2025)
di: Li, Kun, et al.
Pubblicazione: (2025)
LogJack: Indirect Prompt Injection Through Cloud Logs Against LLM Debugging Agents
di: Shah, Harsh
Pubblicazione: (2026)
di: Shah, Harsh
Pubblicazione: (2026)
ARGUS: Defending LLM Agents Against Context-Aware Prompt Injection
di: Weng, Shihao, et al.
Pubblicazione: (2026)
di: Weng, Shihao, et al.
Pubblicazione: (2026)
AgentTrap: Measuring Runtime Trust Failures in Third-Party Agent Skills
di: Zhuang, Haomin, et al.
Pubblicazione: (2026)
di: Zhuang, Haomin, et al.
Pubblicazione: (2026)
Low Rank Comes with Low Security: Gradient Assembly Poisoning Attacks against Distributed LoRA-based LLM Systems
di: Dong, Yueyan, et al.
Pubblicazione: (2026)
di: Dong, Yueyan, et al.
Pubblicazione: (2026)
SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
di: Wu, Jiangrong, et al.
Pubblicazione: (2026)
di: Wu, Jiangrong, et al.
Pubblicazione: (2026)
SINCon: Mitigate LLM-Generated Malicious Message Injection Attack for Rumor Detection
di: Zhang, Mingqing, et al.
Pubblicazione: (2025)
di: Zhang, Mingqing, et al.
Pubblicazione: (2025)
Documenti analoghi
-
AegisAgent: An Autonomous Defense Agent Against Prompt Injection Attacks in LLM-HARs
di: Wang, Yihan, et al.
Pubblicazione: (2025) -
The Agent Economy: A Blockchain-Based Foundation for Autonomous AI Agents
di: Xu, Minghui
Pubblicazione: (2026) -
What Breaks Embodied AI Security:LLM Vulnerabilities, CPS Flaws,or Something Else?
di: Ma, Boyang, et al.
Pubblicazione: (2026) -
ObliInjection: Order-Oblivious Prompt Injection Attack to LLM Agents with Multi-source Data
di: Wang, Reachal, et al.
Pubblicazione: (2025) -
AgentDID: Trustless Identity Authentication for AI Agents
di: Xu, Minghui, et al.
Pubblicazione: (2026)