August 2026Unreviewed
EVOMAL: Self-Poisoning in Self-Evolving Coding Agents
Xiaodong Wu, Yu Shi, Qi Li, Zhimin Zhao, Xiang-Man Li, Bram Adams, Ahmed E. Hassan, Jianbing Ni
Abstract
Self-evolving LLM coding agents write their own tools by imitating retrieved skills from shared skill libraries. We identify a vulnerability in this loop: during authoring, a retrieved malicious skill can become the template for a new skill that preserves the payload. We call this self-poisoning: the agent authors, stores, and runs the resulting malicious skill. We exploit it through EvoMal, an attack that amplifies self-poisoning by wrapping an interchangeable payload in a banner, a set of beni
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
Suggested from the entry's categories.
Cite
@misc{wu2026evomal,
title = {{EVOMAL: Self-Poisoning in Self-Evolving Coding Agents}},
author = {Xiaodong Wu and Yu Shi and Qi Li and Zhimin Zhao and Xiang-Man Li and Bram Adams and Ahmed E. Hassan and Jianbing Ni},
year = {2026},
month = aug,
eprint = {2608.25776},
archivePrefix = {arXiv},
url = {https://www.semanticscholar.org/paper/dade8d85d8cec69350866993be15d982dda27435}
}