SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wu, Jiangrong, Nan, Yuhong, Lin, Yixi, Wang, Huaijin, Xiao, Yuming, Wang, Shuai, Zheng, Zibin
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909020511535104
author Wu, Jiangrong
Nan, Yuhong
Lin, Yixi
Wang, Huaijin
Xiao, Yuming
Wang, Shuai
Zheng, Zibin
author_facet Wu, Jiangrong
Nan, Yuhong
Lin, Yixi
Wang, Huaijin
Xiao, Yuming
Wang, Shuai
Zheng, Zibin
contents Agent Skills have become a practical way to extend LLM agents by packaging metadata, natural-language instructions, and executable resources into reusable capability bundles. However, this growing Skill ecosystem introduces a new compliance risk: a Skill may perform high-impact actions that exceed the minimum necessary scope of the user's current task, thereby violating least-privilege. Existing skill detection approaches are insufficient for this problem because it is inherently task-conditioned: the same action may be necessary under one user prompt but over-privileged under another. In this paper, we present SkillScope, a framework for fine-grained least-privilege enforcement in Agent Skills. SkillScope adopts a graph-based analysis approach that models instruction-level procedures and code-level operations as fine-grained action nodes. It extracts potential over-privilege candidates, validates them under graph-instantiated user tasks through replay-based analysis, and constrains validated over-privileged actions via control-flow privilege constraining. We evaluate SkillScope through effectiveness experiments and large-scale real-world measurement. SkillScope achieves 94.53% F1 for skill over-privilege detection. In the wild, SkillScope validates 7,039 Skills with over-privileged behaviors, showing that least-privilege violations are prevalent in current Skill ecosystems. In the privilege-constraining evaluation, SkillScope reduces triggered over-privileged action-in-task instances by 88.56% while preserving legitimate task completion.
format Preprint
id arxiv_https___arxiv_org_abs_2605_05868
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
Wu, Jiangrong
Nan, Yuhong
Lin, Yixi
Wang, Huaijin
Xiao, Yuming
Wang, Shuai
Zheng, Zibin
Cryptography and Security
Agent Skills have become a practical way to extend LLM agents by packaging metadata, natural-language instructions, and executable resources into reusable capability bundles. However, this growing Skill ecosystem introduces a new compliance risk: a Skill may perform high-impact actions that exceed the minimum necessary scope of the user's current task, thereby violating least-privilege. Existing skill detection approaches are insufficient for this problem because it is inherently task-conditioned: the same action may be necessary under one user prompt but over-privileged under another. In this paper, we present SkillScope, a framework for fine-grained least-privilege enforcement in Agent Skills. SkillScope adopts a graph-based analysis approach that models instruction-level procedures and code-level operations as fine-grained action nodes. It extracts potential over-privilege candidates, validates them under graph-instantiated user tasks through replay-based analysis, and constrains validated over-privileged actions via control-flow privilege constraining. We evaluate SkillScope through effectiveness experiments and large-scale real-world measurement. SkillScope achieves 94.53% F1 for skill over-privilege detection. In the wild, SkillScope validates 7,039 Skills with over-privileged behaviors, showing that least-privilege violations are prevalent in current Skill ecosystems. In the privilege-constraining evaluation, SkillScope reduces triggered over-privileged action-in-task instances by 88.56% while preserving legitimate task completion.
title SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
topic Cryptography and Security
url https://arxiv.org/abs/2605.05868