Credential Leakage in LLM Agent Skills: A Large-Scale Empirical Study
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Chen, Zhihao, Zhang, Ying, Liu, Yi, Deng, Gelei, Li, Yuekang, Zhang, Yanjun, Ning, Jianting, Zhang, Leo Yu, Ma, Lei, Li, Zhiqiang |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
"Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills
von: Liu, Yi, et al.
Veröffentlicht: (2026)
von: Liu, Yi, et al.
Veröffentlicht: (2026)
Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
von: Liu, Yi, et al.
Veröffentlicht: (2026)
von: Liu, Yi, et al.
Veröffentlicht: (2026)
Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
von: Qu, Yubin, et al.
Veröffentlicht: (2026)
von: Qu, Yubin, et al.
Veröffentlicht: (2026)
SNARE: Adaptive Scenario Synthesis for Eliciting Overeager Behavior in Coding Agents
von: Qu, Yubin, et al.
Veröffentlicht: (2026)
von: Qu, Yubin, et al.
Veröffentlicht: (2026)
Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks
von: Qu, Yubin, et al.
Veröffentlicht: (2026)
von: Qu, Yubin, et al.
Veröffentlicht: (2026)
What Makes a Good LLM Agent for Real-world Penetration Testing?
von: Deng, Gelei, et al.
Veröffentlicht: (2026)
von: Deng, Gelei, et al.
Veröffentlicht: (2026)
MasterKey: Automated Jailbreak Across Multiple Large Language Model Chatbots
von: Deng, Gelei, et al.
Veröffentlicht: (2023)
von: Deng, Gelei, et al.
Veröffentlicht: (2023)
Pandora: Jailbreak GPTs by Retrieval Augmented Generation Poisoning
von: Deng, Gelei, et al.
Veröffentlicht: (2024)
von: Deng, Gelei, et al.
Veröffentlicht: (2024)
Membership Inference Attacks Against Video Large Language Models
von: Song, Wei, et al.
Veröffentlicht: (2026)
von: Song, Wei, et al.
Veröffentlicht: (2026)
A Comprehensive Study of Jailbreak Attack versus Defense for Large Language Models
von: Xu, Zihao, et al.
Veröffentlicht: (2024)
von: Xu, Zihao, et al.
Veröffentlicht: (2024)
Beyond Denial-of-Service: The Puppeteer's Attack for Fine-Grained Control in Ranking-Based Federated Learning
von: Chen, Zhihao, et al.
Veröffentlicht: (2026)
von: Chen, Zhihao, et al.
Veröffentlicht: (2026)
Leakage-abuse Attack Against Substring-SSE with Partially Known Dataset
von: Ba, Xijie, et al.
Veröffentlicht: (2025)
von: Ba, Xijie, et al.
Veröffentlicht: (2025)
MIRAGE: Context-Aware Prompt Injection against Mobile GUI Agents via User-Generated Content
von: Guo, Ruoqi, et al.
Veröffentlicht: (2026)
von: Guo, Ruoqi, et al.
Veröffentlicht: (2026)
TombRaider: Entering the Vault of History to Jailbreak Large Language Models
von: Ding, Junchen, et al.
Veröffentlicht: (2025)
von: Ding, Junchen, et al.
Veröffentlicht: (2025)
Anamorphic Encryption with CCA Security: A Standard Model Construction
von: Wang, Shujun, et al.
Veröffentlicht: (2026)
von: Wang, Shujun, et al.
Veröffentlicht: (2026)
Uncovering Logit Suppression Vulnerabilities in LLM Safety Alignment
von: Li, Yuxi, et al.
Veröffentlicht: (2024)
von: Li, Yuxi, et al.
Veröffentlicht: (2024)
IllusionCAPTCHA: A CAPTCHA based on Visual Illusion
von: Ding, Ziqi, et al.
Veröffentlicht: (2025)
von: Ding, Ziqi, et al.
Veröffentlicht: (2025)
A Rusty Link in the AI Supply Chain: Detecting Evil Configurations in Model Repositories
von: Ding, Ziqi, et al.
Veröffentlicht: (2025)
von: Ding, Ziqi, et al.
Veröffentlicht: (2025)
Oedipus: LLM-enchanced Reasoning CAPTCHA Solver
von: Deng, Gelei, et al.
Veröffentlicht: (2024)
von: Deng, Gelei, et al.
Veröffentlicht: (2024)
PentestGPT: An LLM-empowered Automatic Penetration Testing Tool
von: Deng, Gelei, et al.
Veröffentlicht: (2023)
von: Deng, Gelei, et al.
Veröffentlicht: (2023)
Continuous Embedding Attacks via Clipped Inputs in Jailbreaking Large Language Models
von: Xu, Zihao, et al.
Veröffentlicht: (2024)
von: Xu, Zihao, et al.
Veröffentlicht: (2024)
Black-Box Skill Stealing Attack from Proprietary LLM Agents: An Empirical Study
von: Wang, Zihan, et al.
Veröffentlicht: (2026)
von: Wang, Zihan, et al.
Veröffentlicht: (2026)
Digger: Detecting Copyright Content Mis-usage in Large Language Model Training
von: Li, Haodong, et al.
Veröffentlicht: (2024)
von: Li, Haodong, et al.
Veröffentlicht: (2024)
Beyond the Hype: A Large-Scale Empirical Analysis of On-Chain Transactions in NFT Scams
von: Li, Wenkai, et al.
Veröffentlicht: (2025)
von: Li, Wenkai, et al.
Veröffentlicht: (2025)
Demystifying RCE Vulnerabilities in LLM-Integrated Apps
von: Liu, Tong, et al.
Veröffentlicht: (2023)
von: Liu, Tong, et al.
Veröffentlicht: (2023)
When Skills Lie: Hidden-Comment Injection in LLM Agents
von: Wang, Qianli, et al.
Veröffentlicht: (2026)
von: Wang, Qianli, et al.
Veröffentlicht: (2026)
Prompt Injection attack against LLM-integrated Applications
von: Liu, Yi, et al.
Veröffentlicht: (2023)
von: Liu, Yi, et al.
Veröffentlicht: (2023)
Image-Based Geolocation Using Large Vision-Language Models
von: Liu, Yi, et al.
Veröffentlicht: (2024)
von: Liu, Yi, et al.
Veröffentlicht: (2024)
IRCopilot: Automated Incident Response with Large Language Models
von: Lin, Xihuan, et al.
Veröffentlicht: (2025)
von: Lin, Xihuan, et al.
Veröffentlicht: (2025)
Fluent: Round-efficient Secure Aggregation for Private Federated Learning
von: Li, Xincheng, et al.
Veröffentlicht: (2024)
von: Li, Xincheng, et al.
Veröffentlicht: (2024)
Separating Secrets from Placeholders: A Hybrid CNN-CodeBERT Framework for Three-Class Credential Leakage Detection
von: Baby, Maksuda Bilkis, et al.
Veröffentlicht: (2026)
von: Baby, Maksuda Bilkis, et al.
Veröffentlicht: (2026)
Backdoor Attacks and Defenses in Computer Vision Domain: A Survey
von: Abbasi, Bilal Hussain, et al.
Veröffentlicht: (2025)
von: Abbasi, Bilal Hussain, et al.
Veröffentlicht: (2025)
SkCC: Portable and Secure Skill Compilation for Cross-Framework LLM Agents
von: Ouyang, Yipeng, et al.
Veröffentlicht: (2026)
von: Ouyang, Yipeng, et al.
Veröffentlicht: (2026)
Good News for Script Kiddies? Evaluating Large Language Models for Automated Exploit Generation
von: Jin, David, et al.
Veröffentlicht: (2025)
von: Jin, David, et al.
Veröffentlicht: (2025)
SAVANT: Vulnerability Detection in Application Dependencies through Semantic-Guided Reachability Analysis
von: Lingxiang, Wang, et al.
Veröffentlicht: (2025)
von: Lingxiang, Wang, et al.
Veröffentlicht: (2025)
When Search Goes Wrong: Red-Teaming Web-Augmented Large Language Models
von: Ou, Haoran, et al.
Veröffentlicht: (2025)
von: Ou, Haoran, et al.
Veröffentlicht: (2025)
Your Code Secret Belongs to Me: Neural Code Completion Tools Can Memorize Hard-Coded Credentials
von: Huang, Yizhan, et al.
Veröffentlicht: (2023)
von: Huang, Yizhan, et al.
Veröffentlicht: (2023)
AgentSys: Secure and Dynamic LLM Agents Through Explicit Hierarchical Memory Management
von: Wen, Ruoyao, et al.
Veröffentlicht: (2026)
von: Wen, Ruoyao, et al.
Veröffentlicht: (2026)
DECEIVE-AFC: Adversarial Claim Attacks against Search-Enabled LLM-based Fact-Checking Systems
von: Ou, Haoran, et al.
Veröffentlicht: (2026)
von: Ou, Haoran, et al.
Veröffentlicht: (2026)
Less Is More -- Until It Breaks: Security Pitfalls of Vision Token Compression in Large Vision-Language Models
von: Zhang, Xiaomei, et al.
Veröffentlicht: (2026)
von: Zhang, Xiaomei, et al.
Veröffentlicht: (2026)
Ähnliche Einträge
-
"Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills
von: Liu, Yi, et al.
Veröffentlicht: (2026) -
Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
von: Liu, Yi, et al.
Veröffentlicht: (2026) -
Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
von: Qu, Yubin, et al.
Veröffentlicht: (2026) -
SNARE: Adaptive Scenario Synthesis for Eliciting Overeager Behavior in Coding Agents
von: Qu, Yubin, et al.
Veröffentlicht: (2026) -
Overeager Coding Agents: Measuring Out-of-Scope Actions on Benign Tasks
von: Qu, Yubin, et al.
Veröffentlicht: (2026)