Skip to content
Search
paperJune 2026Unreviewed

SkillMutator: Benchmarking and Defending Language-and-Code Cross-modal Attacks on LLM Agent Skills

Youngduk Kim, Minkyoo Song, Seungwon Shin

Abstract

Large language model (LLM) agents increasingly extend their capabilities at runtime by loading Agent Skills, which pair natural-language specifications (SKILL.md) with executable scripts and resources. Because a skill's behavior relies on both natural-language instructions and executable code, assessing its safety requires cross-modal reasoning, creating a new language-and-code attack surface. Attackers can present a benign workflow in SKILL.md while embedding implicit directives that steer the

Categories

Cite

@misc{kim2026skillmutator,
  title = {{SkillMutator: Benchmarking and Defending Language-and-Code Cross-modal Attacks on LLM Agent Skills}},
  author = {Youngduk Kim and Minkyoo Song and Seungwon Shin},
  year = {2026},
  month = jun,
  eprint = {2606.14154},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.14154}
}