通过仓库上下文分析,发现46.8%误判率源于忽略项目背景。
Context Matters: Repository-Aware Security Analysis of the Agent Skill Ecosystem
- 结合代码仓库上下文评估技能安全性,而非孤立判断。
- 经上下文分析后仅0.52%技能仍可疑,远低于扫描器报告的46.8%。
- 揭示废弃仓库被劫持等新型攻击路径,适合安全研究人员参考。
AI代理技能扩展了本地智能代理(如Claude Code和OpenClaw)的功能,其流行催生了类似移动应用商店的专用市场及自动化扫描工具,用以判断技能是否恶意。然而,单个市场的扫描报告将高达46.8%的技能标记为恶意,引发误报担忧。本文开展迄今规模最大的代理技能生态安全实证分析,从三大分发平台及GitHub收集238,180个唯一技能,分析其内容、行为与仓库上下文。不同于现有扫描工具孤立评估,我们的仓库感知分析检查可疑技能是否与其所在GitHub项目一致。结果显示,结合上下文后,仅0.52%技能仍被视为可疑。这表明忽略仓库上下文会显著高估恶意风险。同时,我们识别出此前未记录的真实攻击向量,包括托管于废弃仓库中的技能被劫持。整体结果为代理技能生态当前风险面提供了更稳健的视图,并强调需采用上下文感知的安全评估方法。
原文摘要 · Abstract (English)
Agent skills extend local AI agents, such as Claude Code and OpenClaw, with additional functionality. Their growing popularity has led to dedicated marketplaces resembling mobile app stores, as well as automated scanners that assess whether skills are benign or malicious. However, scanner reports from individual marketplaces classify up to 46.8% of skills as malicious, raising concerns about false positives. We present the largest empirical security analysis of the AI agent skill ecosystem to date. We collect 238,180 unique skills from three major distribution platforms and GitHub, and analyze their contents, behavior, and repository context. Unlike existing scanner-based assessments, which evaluate skills largely in isolation, our repository-aware analysis checks whether a flagged skill is consistent with its surrounding GitHub project. This context substantially reduces the number of suspicious skills: only 0.52% remain suspicious after repository-aware analysis. Our results show that existing scanners can substantially overestimate maliciousness when repository context is ignored. At the same time, we identify previously undocumented real-world attack vectors, including the hijacking of skills hosted in abandoned GitHub repositories. Overall, our findings provide a more robust view of the agent-skill ecosystem's current risk surface and highlight the need for context-aware security evaluation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。