August 2026Unreviewed
CompoSkill: Compositional Skill Chain Attacks from Individually Scanner-Passing LLM Agent Skills
Mingxiao Liu, Zhoumian Jiang, Jianan Ma, Jian Zhang, Jialuo Chen, Xinhao Deng, Zhen Wang
Abstract
Autonomous AI agents tackling Long Horizon Tasks depend on marketplace skills that are certified one at a time: a scanner returns a safety verdict for each skill and declares the ecosystem safe if every package passes. We show that this assumption fails under skill composition. A skill may pass the per-skill scanner individually yet participate in a risky composition when an agent connects its outputs, capabilities, or side effects with those of other scanner-passing skills. This makes skill com
Categories
Cite
@misc{liu2026composkill,
title = {{CompoSkill: Compositional Skill Chain Attacks from Individually Scanner-Passing LLM Agent Skills}},
author = {Mingxiao Liu and Zhoumian Jiang and Jianan Ma and Jian Zhang and Jialuo Chen and Xinhao Deng and Zhen Wang},
year = {2026},
month = aug,
eprint = {2608.16246},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.16246}
}