Skip to content
Search
paperAugust 2026Unreviewed

Behavioral Skill Reconstruction: Reconstructing Hidden Functionality from LLM Agent Skills

Peichun Hua, Haoxuan Xu, Mengyuan Li

Abstract

Closed source agent skills may encode proprietary instructions, scripts, constants, and data. Providers may offer their capabilities as services while keeping the underlying packages hidden. Prior work focuses on prompt injection attacks that directly disclose these artifacts, and existing defenses accordingly aim to prevent such leakage. However, preventing file disclosure does not prevent users from recovering the functionality those files implement. This raises a fundamental question: can a u

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{hua2026behavioral,
  title = {{Behavioral Skill Reconstruction: Reconstructing Hidden Functionality from LLM Agent Skills}},
  author = {Peichun Hua and Haoxuan Xu and Mengyuan Li},
  year = {2026},
  month = aug,
  eprint = {2608.04192},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.04192}
}