Skip to content
Search
paperAugust 2026Unreviewed

CompoSkill: Compositional Skill Chain Attacks from Individually Scanner-Passing LLM Agent Skills

Mingxiao Liu, Zhoumian Jiang, Jianan Ma, Jian Zhang, Jialuo Chen, Xinhao Deng, Zhen Wang

Abstract

Autonomous AI agents tackling Long Horizon Tasks depend on marketplace skills that are certified one at a time: a scanner returns a safety verdict for each skill and declares the ecosystem safe if every package passes. We show that this assumption fails under skill composition. A skill may pass the per-skill scanner individually yet participate in a risky composition when an agent connects its outputs, capabilities, or side effects with those of other scanner-passing skills. This makes skill com

Categories

Cite

@misc{liu2026composkill,
  title = {{CompoSkill: Compositional Skill Chain Attacks from Individually Scanner-Passing LLM Agent Skills}},
  author = {Mingxiao Liu and Zhoumian Jiang and Jianan Ma and Jian Zhang and Jialuo Chen and Xinhao Deng and Zhen Wang},
  year = {2026},
  month = aug,
  eprint = {2608.16246},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.16246}
}