Skip to content
Search
paperAugust 2026Unreviewed

EVOMAL: Self-Poisoning in Self-Evolving Coding Agents

Xiaodong Wu, Yu Shi, Qi Li, Zhimin Zhao, Xiang-Man Li, Bram Adams, Ahmed E. Hassan, Jianbing Ni

Abstract

Self-evolving LLM coding agents write their own tools by imitating retrieved skills from shared skill libraries. We identify a vulnerability in this loop: during authoring, a retrieved malicious skill can become the template for a new skill that preserves the payload. We call this self-poisoning: the agent authors, stores, and runs the resulting malicious skill. We exploit it through EvoMal, an attack that amplifies self-poisoning by wrapping an interchangeable payload in a banner, a set of beni

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{wu2026evomal,
  title = {{EVOMAL: Self-Poisoning in Self-Evolving Coding Agents}},
  author = {Xiaodong Wu and Yu Shi and Qi Li and Zhimin Zhao and Xiang-Man Li and Bram Adams and Ahmed E. Hassan and Jianbing Ni},
  year = {2026},
  month = aug,
  eprint = {2608.25776},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/dade8d85d8cec69350866993be15d982dda27435}
}