Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry
Fuente:
arXiv
Guardado en:
| Autores principales: | Saha, Shoumik, Faghih, Kazem, Feizi, Soheil |
|---|---|
| Formato: | Preprint |
| Publicado: |
2026
|
| Materias: | |
| Acceso en línea: | |
| Etiquetas: |
Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
|
Ejemplares similares
Fast Adversarial Attacks on Language Models In One GPU Minute
por: Sadasivan, Vinu Sankar, et al.
Publicado: (2024)
por: Sadasivan, Vinu Sankar, et al.
Publicado: (2024)
Breaking the Code: Security Assessment of AI Code Agents Through Systematic Jailbreaking Attacks
por: Saha, Shoumik, et al.
Publicado: (2025)
por: Saha, Shoumik, et al.
Publicado: (2025)
Tool Preferences in Agentic LLMs are Unreliable
por: Faghih, Kazem, et al.
Publicado: (2025)
por: Faghih, Kazem, et al.
Publicado: (2025)
No Attack Required: Semantic Fuzzing for Specification Violations in Agent Skills
por: Li, Ying, et al.
Publicado: (2026)
por: Li, Ying, et al.
Publicado: (2026)
Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
por: Qu, Yubin, et al.
Publicado: (2026)
por: Qu, Yubin, et al.
Publicado: (2026)
SkillTrojan: Backdoor Attacks on Skill-Based Agent Systems
por: Feng, Yunhao, et al.
Publicado: (2026)
por: Feng, Yunhao, et al.
Publicado: (2026)
BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
por: Tie, Guiyao, et al.
Publicado: (2026)
por: Tie, Guiyao, et al.
Publicado: (2026)
IConMark: Robust Interpretable Concept-Based Watermark For AI Images
por: Sadasivan, Vinu Sankar, et al.
Publicado: (2025)
por: Sadasivan, Vinu Sankar, et al.
Publicado: (2025)
Almost AI, Almost Human: The Challenge of Detecting AI-Polished Writing
por: Saha, Shoumik, et al.
Publicado: (2025)
por: Saha, Shoumik, et al.
Publicado: (2025)
MergeGuard: Efficient Thwarting of Trojan Attacks in Machine Learning Models
por: Shabgahi, Soheil Zibakhsh, et al.
Publicado: (2025)
por: Shabgahi, Soheil Zibakhsh, et al.
Publicado: (2025)
SkillSieve: A Hierarchical Triage Framework for Detecting Malicious AI Agent Skills
por: Hou, Yinghan, et al.
Publicado: (2026)
por: Hou, Yinghan, et al.
Publicado: (2026)
AI-Powered Hybrid Intrusion Detection Framework for Cloud Security Using Novel Metaheuristic Optimization
por: Alhusseini, Maryam Mahdi, et al.
Publicado: (2026)
por: Alhusseini, Maryam Mahdi, et al.
Publicado: (2026)
Automatically Attacking Software Reverse Engineering AI Agents
por: Crawford, Brian, et al.
Publicado: (2026)
por: Crawford, Brian, et al.
Publicado: (2026)
Securing AI Agents Against Prompt Injection Attacks
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
por: Ramakrishnan, Badrinath, et al.
Publicado: (2025)
Emerging Cyber Attack Risks of Medical AI Agents
por: Qiu, Jianing, et al.
Publicado: (2025)
por: Qiu, Jianing, et al.
Publicado: (2025)
When Backdoors Go Beyond Triggers: Semantic Drift in Diffusion Models Under Encoder Attacks
por: Chen, Shenyang, et al.
Publicado: (2026)
por: Chen, Shenyang, et al.
Publicado: (2026)
Securing GenAI Multi-Agent Systems Against Tool Squatting: A Zero Trust Registry-Based Approach
por: Narajala, Vineeth Sai, et al.
Publicado: (2025)
por: Narajala, Vineeth Sai, et al.
Publicado: (2025)
ATAG: AI-Agent Application Threat Assessment with Attack Graphs
por: Gandhi, Parth Atulbhai, et al.
Publicado: (2025)
por: Gandhi, Parth Atulbhai, et al.
Publicado: (2025)
SkillTester: Benchmarking Utility and Security of Agent Skills
por: Wang, Leye, et al.
Publicado: (2026)
por: Wang, Leye, et al.
Publicado: (2026)
Bypassing AI Control Protocols via Agent-as-a-Proxy Attacks
por: Isbarov, Jafar, et al.
Publicado: (2026)
por: Isbarov, Jafar, et al.
Publicado: (2026)
SkillJect: Effectively Automating Skill-Based Prompt Injection for Skill-Enabled Agents
por: Jia, Xiaojun, et al.
Publicado: (2026)
por: Jia, Xiaojun, et al.
Publicado: (2026)
Defenses & Enablers For Skill Injection Attacks on Terminal Based Agents
por: Fujinuma, Yoshinari, et al.
Publicado: (2026)
por: Fujinuma, Yoshinari, et al.
Publicado: (2026)
Attacker's Noise Can Manipulate Your Audio-based LLM in the Real World
por: Sadasivan, Vinu Sankar, et al.
Publicado: (2025)
por: Sadasivan, Vinu Sankar, et al.
Publicado: (2025)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
por: Zhu, Kaijie, et al.
Publicado: (2025)
por: Zhu, Kaijie, et al.
Publicado: (2025)
When Convenience Becomes Risk: A Semantic View of Under-Specification in Host-Acting Agents
por: Lu, Di, et al.
Publicado: (2026)
por: Lu, Di, et al.
Publicado: (2026)
Semantic Intent Fragmentation: A Single-Shot Compositional Attack on Multi-Agent AI Pipelines
por: Ahad, Tanzim, et al.
Publicado: (2026)
por: Ahad, Tanzim, et al.
Publicado: (2026)
SOK: A Taxonomy of Attack Vectors and Defense Strategies for Agentic Supply Chain Runtime
por: Jiang, Xiaochong, et al.
Publicado: (2026)
por: Jiang, Xiaochong, et al.
Publicado: (2026)
HarmfulSkillBench: How Do Harmful Skills Weaponize Your Agents?
por: Jiang, Yukun, et al.
Publicado: (2026)
por: Jiang, Yukun, et al.
Publicado: (2026)
Behavioral Integrity Verification for AI Agent Skills
por: Wu, Yuhao, et al.
Publicado: (2026)
por: Wu, Yuhao, et al.
Publicado: (2026)
AI Agents Under Threat: A Survey of Key Security Challenges and Future Pathways
por: Deng, Zehang, et al.
Publicado: (2024)
por: Deng, Zehang, et al.
Publicado: (2024)
Secret Stealing Attacks on Local LLM Fine-Tuning through Supply-Chain Model Code Backdoors
por: Li, Zi, et al.
Publicado: (2026)
por: Li, Zi, et al.
Publicado: (2026)
Architecting Secure AI Agents: Perspectives on System-Level Defenses Against Indirect Prompt Injection Attacks
por: Xiang, Chong, et al.
Publicado: (2026)
por: Xiang, Chong, et al.
Publicado: (2026)
AgentTrap: Measuring Runtime Trust Failures in Third-Party Agent Skills
por: Zhuang, Haomin, et al.
Publicado: (2026)
por: Zhuang, Haomin, et al.
Publicado: (2026)
Security of Internet of Agents: Attacks and Countermeasures
por: Wang, Yuntao, et al.
Publicado: (2025)
por: Wang, Yuntao, et al.
Publicado: (2025)
Your Semantic-Independent Watermark is Fragile: A Semantic Perturbation Attack against EaaS Watermark
por: Fei, Zekun, et al.
Publicado: (2024)
por: Fei, Zekun, et al.
Publicado: (2024)
Technical Report: Exploring the Emerging Threats of the Agent Skill Ecosystem
por: Beurer-Kellner, Luca, et al.
Publicado: (2026)
por: Beurer-Kellner, Luca, et al.
Publicado: (2026)
Structured Security Auditing and Robustness Enhancement for Untrusted Agent Skills
por: Lv, Lijia, et al.
Publicado: (2026)
por: Lv, Lijia, et al.
Publicado: (2026)
AttackPilot: Autonomous Inference Attacks Against ML Services With LLM-Based Agents
por: Wu, Yixin, et al.
Publicado: (2025)
por: Wu, Yixin, et al.
Publicado: (2025)
Is Monitoring Enough? Strategic Agent Selection For Stealthy Attack in Multi-Agent Discussions
por: Xiang, Qiuchi, et al.
Publicado: (2026)
por: Xiang, Qiuchi, et al.
Publicado: (2026)
CheatAgent: Attacking LLM-Empowered Recommender Systems via LLM Agent
por: Ning, Liang-bo, et al.
Publicado: (2025)
por: Ning, Liang-bo, et al.
Publicado: (2025)
Ejemplares similares
-
Fast Adversarial Attacks on Language Models In One GPU Minute
por: Sadasivan, Vinu Sankar, et al.
Publicado: (2024) -
Breaking the Code: Security Assessment of AI Code Agents Through Systematic Jailbreaking Attacks
por: Saha, Shoumik, et al.
Publicado: (2025) -
Tool Preferences in Agentic LLMs are Unreliable
por: Faghih, Kazem, et al.
Publicado: (2025) -
No Attack Required: Semantic Fuzzing for Specification Violations in Agent Skills
por: Li, Ying, et al.
Publicado: (2026) -
Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
por: Qu, Yubin, et al.
Publicado: (2026)