Installable agent skills can inherit user authority without adequate checks

TrustProbe found skill-controlled content reaching sensitive operations across 11 open-source agents, including 15 vulnerabilities that researchers successfully weaponized.

Research Lab
Yan Wang · Zhihao Zhang · Ke Chen · Kai Chen · Yaqin Zhang · Duohe Ma · +2 more

Institute of Information Engineering, Chinese Academy of Sciences · Worcester Polytechnic Institute · School of Cyberspace Security, University of Chinese Academy of Sciences

Research Digest··3 min read
Wang et al.

The authors built TrustProbe to test how content from installable agent skills propagates through an agent framework.

Why this paper

From Institute of Information Engineering, Chinese Academy of Sciences and 2 others

In one line

Skill-based LLM agents allow malicious skills to reach security-sensitive operations due to systematic trust failures.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ·No benchmark numbers found

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.