← Back to Computation and Language
cs.CL

How hackers hijack AI agent skills to cause delayed damage

Yuting Ning, Zhehao Zhang, Yash Kumar Lal, Boyu Gou, Junyi Li, Weitong Ruan, Chentao Ye, Rahul Gupta, Diyi Yang, Yu Su, Huan Sun

June 1, 2026

Agents rely on third-party skills as building blocks, creating a security blind spot. This work maps the full lifecycle of skill-based attacks—from immediate poisoning to time-delayed sabotage that mutates itself—and categorizes 12 risk types across data, system, and autonomy layers. They built an automated pipeline to generate 879 adversarial examples across 71 real skills; most current defenses fail, and many apparent successes are false: agents simply ignore the poisoned file rather than resist it.
Published as SkillHarm: Lifecycle-Aware Skill-Based Attacks via Automated Construction arXiv:2606.02540
Read the original paper →