SkillSecurer: Detecting and Patching Prompt-Injection Vulnerabilities in AI Agent Skills

📅 2026-09-12
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
针对AI代理技能中的提示注入漏洞问题,提出SkillSecurer框架,通过红蓝代理生成、检测、定位并修复安全风险。
📝 Abstract
Agent skills extend AI agents with reusable instructions, scripts, and configuration, but are also open to new attacks to influence an agent's decisions and actions. To address these risks, we present SkillSecurer, a fully agentic framework for generating, detecting, localising, and remediating security risks in agent skills. Its red agent generates context-compatible injections across nine threat types while recording the exact modification; its blue agent analyses complete skill packages, produces grounded evidence, and proposes patches. For controlled instances, a verifier compares findings and patches with the recorded injection, enabling injection-level evaluation. We thoroughly evaluate SkillSecurer by selecting the best backend LLM, comparing it with competitors, and manually cross-validating each evaluation stage. With its best performing backend, SkillSecurer is the only scanner to achieve a 100% injection detection rate. Next, we analyse popular skills from skills.sh, finding latent vulnerabilities in more than 17% of the skills examined. Testing some of those skills, we trigger actual incidents, showing the risks of running unverified skills. Our results show that context-aware LLM analysis can provide reliable injection localisation and actionable remediation beyond skill-level flagging alone.
Problem

Research questions and friction points this paper is trying to address.

AI Agent Skills
Prompt-Injection Vulnerabilities
Security Risks
Innovation

Methods, ideas, or system contributions that make the work stand out.

context-aware LLM analysis
injection detection and localization
automated remediation
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
D
Donato Mecca
Politecnico di Torino
A
Alberto Verna
Politecnico di Torino
Y
Youness Bouchari
Politecnico di Torino
N
Nikhil Jha
Politecnico di Torino
Marco Mellia
Marco Mellia
Politecnico di Torino, italy
Computer networksMachine LearningCybersecurityData Science