← Back to search
paper llmsec-2026-00096

No Attack Required: Semantic Fuzzing for Specification Violations in Agent Skills

Ying Li, Hongbo Wen, Yanju Chen, Hanzhi Liu, Yuan Tian, Yu Feng

2026-05

Abstract

LLM-powered agents can silently delete documents, leak credentials, or transfer funds on a routine user request, not because the agent was attacked, but because the skill it invoked broke its own declared safety rules. We call these specification violations: benign inputs cause a skill to breach the natural-language guardrails in its own specification, typically because the guardrail's semantics are undefined for autonomous execution, or because the implementation silently ignores the documented

Categories

Cite This Resource

@article{llmsec202600096,
  title = {No Attack Required: Semantic Fuzzing for Specification Violations in Agent Skills},
  author = {Ying Li and Hongbo Wen and Yanju Chen and Hanzhi Liu and Yuan Tian and Yu Feng},
  year = {2026},
  url = {https://arxiv.org/abs/2605.13044},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.13044