August 2026Unreviewed
Behavioral Skill Reconstruction: Reconstructing Hidden Functionality from LLM Agent Skills
Peichun Hua, Haoxuan Xu, Mengyuan Li
Abstract
Closed source agent skills may encode proprietary instructions, scripts, constants, and data. Providers may offer their capabilities as services while keeping the underlying packages hidden. Prior work focuses on prompt injection attacks that directly disclose these artifacts, and existing defenses accordingly aim to prevent such leakage. However, preventing file disclosure does not prevent users from recovering the functionality those files implement. This raises a fundamental question: can a u
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{hua2026behavioral,
title = {{Behavioral Skill Reconstruction: Reconstructing Hidden Functionality from LLM Agent Skills}},
author = {Peichun Hua and Haoxuan Xu and Mengyuan Li},
year = {2026},
month = aug,
eprint = {2608.04192},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.04192}
}