Towards a Risk Assessment of Malicious Skill Files in Coding Agents

2026-08-07T08:51:40Z9623dc5a63b2f607b8d7ff125919e8b187ed5acb3ba754fe2c7daf2dc9d1ab1c
AI securityLLM securityMITRE ATT&CKagent skillsautonomous agentscoding agentscommand executiondeveloper toolsmalicious filesprompt injectionsecurity assessmentsoftware supply chain

What happened

This collection primarily covers software engineering research. The main security-relevant work assesses malicious skill files loaded by autonomous coding agents, showing that natural-language skill interfaces can conceal shell commands and enable agent compromise. The study reports high exploitation rates across Gemini CLI and Qwen Code, low explicit safety recognition, a benchmark mapped to 11 MITRE ATT&CK tactics, and recommends enterprise risk assessment and mitigation before adopting coding agents. Other papers address debugging, WebAssembly discrepancy repair, software validation, test生成

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arxiv_cs_se
Record identifier
9623dc5a63b2f607b8d7ff125919e8b187ed5acb3ba754fe2c7daf2dc9d1ab1c
Enrichment time
2026-08-07T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Towards a Risk Assessment of Malicious Skill Files in Coding Agents · Baitaphish