June 2026Unreviewed
Detecting Malicious Agent Skills in the Wild using Attention
Bacem Etteib, Daniele Lunghi, Tégawendé F. Bissyandé
Abstract
LLM agents increasingly load skills, file-based packages of natural-language instructions written by third parties and distributed through marketplaces, that execute with the user's privileges. A single malicious skill can exfiltrate data, hijack the agent, or persist as a supply-chain foothold, which turns the skill marketplace into a new attack surface for agentic systems. Prompt-injection defenses do not carry over to this setting. They rely on a boundary between trusted instructions and untr
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{etteib2026detecting,
title = {{Detecting Malicious Agent Skills in the Wild using Attention}},
author = {Bacem Etteib and Daniele Lunghi and Tégawendé F. Bissyandé},
year = {2026},
month = jun,
eprint = {2606.23416},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.23416}
}