SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

📅 2026-08-22
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文研究通过技能注入在编码代理中进行令牌放大攻击的问题,提出SkillBloat框架,采用两阶段方法筛选并优化攻击条件,显著提高令牌消耗。
📝 Abstract
Agent skills extend coding agents with task-specific instructions, scripts, and resources, but they also create a trusted instruction channel that can be abused beyond conventional security attacks. This paper studies token amplification through skill injection: an economic resource-abuse threat in which a malicious skill causes an agent to consume substantially more tokens than needed for normal task execution. We present SkillBloat, a two-phase framework that first screens a library of diverse attack-type conditions across multiple amplification mechanisms and then refines the strongest candidate through LLM-guided full-document skill rewriting. Evaluated on a real-world skill benchmark, SkillBloat achieves 5.4184x-10.1455x average best amplification across multiple coding-agent target configurations. An ablation shows that the second-stage refinement loop consistently improves average best amplification over Phase 1 attack-type screening alone, demonstrating that iterative optimization provides additional benefit beyond initial attack-type selection. These results show that skill ecosystems expose a practical resource-amplification attack surface that is orthogonal to existing security-oriented skill poisoning.
Problem

Research questions and friction points this paper is trying to address.

Skill Injection
Token Amplification
Coding Agents
Resource-Abuse Threat
Innovation

Methods, ideas, or system contributions that make the work stand out.

SkillBloat
Token Amplification
Skill Injection
LLM-guided Optimization
Resource-abuse Threat
🔎 Similar Papers
No similar papers found.