July 2026Unreviewed
Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation
Sanket Badhe, Priyanka Tiwari
Abstract
Reusable skills are becoming a fundamental building block of Large Language Model (LLM) agents, enabling capabilities to be packaged, shared, and reused across diverse applications. However, existing security research primarily focuses on prompt injection and runtime execution, leaving security risks throughout the broader skill lifecycle largely unexplored. In this paper, we present SkillSec-Eval, a lifecycle-aware framework for systematically evaluating the security of reusable agent skills. W
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{badhe2026agent,
title = {{Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation}},
author = {Sanket Badhe and Priyanka Tiwari},
year = {2026},
month = jul,
eprint = {2607.13987},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.13987}
}