AI RESEARCH
Malicious Agent Skills in the Wild: A Large-Scale Security Empirical Study
arXiv CS.AI
•
ArXi:2602.06547v2 Announce Type: replace-cross Third-party agent skills extend LLM-based agents with instruction files and executable code that run on users' machines. Skills execute with user privileges and are distributed through community registries with minimal vetting, but no ground-truth dataset exists to characterize the resulting threats. We construct the first labeled dataset of malicious agent skills by behaviorally verifying 98,380 skills from two community registries, confirming 157 malicious skills with 632 vulnerabilities. These attacks are not incidental.