$npx skillfedfor your agent

Skill security 42 papers

a skillfed research direction · page 3 of 3

Attacks on and defenses for skill files — malicious skills, injection, supply chains.

Every note, newest paper first

26.1% of Marketplace Agent Skills Carry a Vulnerability
Liu et al. · Jul 2026 · arXiv 2601.10338

Researchers scraped 42,447 agent skills off two live marketplaces — skills.rest and skillsmp.com — and ran 31,132 unique packages through SkillScan, a three-stage detector chaining static/regex analysis, an LLM-Guard input screen, and a Claude 3.5 Sonnet classifier tuned to flag security patterns. The corpus got split three ways to keep the taxonomy honest: one slice built the pattern taxonomy, one calibrated detection rules, one validated it. Against 200 skills hand-labeled by two researchers with penetration-testing backgrounds (inter-annotator agreement κ=0.83), SkillScan hit 86.7% precision and 82.5% recall.

claims checked against the paper
26.1%Skills with at least one…
One Approval, Zero Further Checks
Schmotz, Abdelnabi & Andriushchenko · Jul 2026 · arXiv 2510.26328

Researchers turned Anthropic's own Agent Skills framework against itself. Agent Skills let a coding agent pull task-specific knowledge into its context at runtime from a SKILL.md markdown file plus any scripts it references — no code-review step, no separate trust channel from the rest of the model's instructions. The authors took Anthropic's own published PowerPoint-editing skill, inserted an instruction calling a disguised "backup" script, and ran the attack two ways: inside Claude Code, and inside Claude's web interface once its skill-upload feature was live there too.

claims checked against the paper
0Extra prompts after first…

Other directions

Skill evolution · 88 Skill retrieval · 30 Agentic benchmarks · 26 Frontier & other · 5 The field map →