首次系统分析代理技能框架安全风险,揭示其核心设计缺陷。
Towards Secure Agent Skills: Architecture, Threat Taxonomy, and Security Analysis
- 按创建、分发、部署、执行四阶段划分攻击面
- 发现7类17种威胁,多源于框架自身结构缺陷
- 适合平台开发者与安全研究人员参考
Agent Skills 是一种新兴的开放标准,采用模块化、基于文件系统的打包格式,使大模型驱动的代理能够按需获取领域专长。尽管已在多个智能体平台广泛采用,并催生大型社区市场,其安全性尚未得到系统研究。本文首次对 Agent Skills 框架进行全面安全分析。我们定义了代理技能全生命周期的四个阶段——创建、分发、部署和执行——并识别各阶段引入的结构性攻击面。基于此,构建了一个包含七类、十七个场景的威胁分类体系,涵盖三个攻击层级,依据架构分析与真实事件证据。通过分析五个已确认的安全事件验证该分类体系。基于研究结果,我们为每类威胁提出防御方向,指出开放研究挑战,并提供给利益相关方的可操作建议。分析表明,最严重威胁源于框架自身结构特性,包括缺乏数据-指令边界、单次审批的持久信任机制、以及市场强制安全审查缺失,仅靠渐进式缓解无法解决。
原文摘要 · Abstract (English)
Agent Skills is an emerging open standard that defines a modular, filesystem-based packaging format enabling LLM-based agents to acquire domain-specific expertise on demand. Despite rapid adoption across multiple agentic platforms and the emergence of large community marketplaces, the security properties of Agent Skills have not been systematically studied. This paper presents the first comprehensive security analysis of the Agent Skills framework. We define the full lifecycle of an Agent Skill across four phases -- Creation, Distribution, Deployment, and Execution -- and identify the structural attack surface each phase introduces. Building on this lifecycle analysis, we construct a threat taxonomy comprising seven categories and seventeen scenarios organized across three attack layers, grounded in both architectural analysis and real-world evidence. We validate the taxonomy through analysis of five confirmed security incidents in the Agent Skills ecosystem. Based on these findings, we discuss defense directions for each threat category, identify open research challenges, and provide actionable recommendations for stakeholders. Our analysis reveals that the most severe threats arise from structural properties of the framework itself, including the absence of a data-instruction boundary, a single-approval persistent trust model, and the lack of mandatory marketplace security review, and cannot be addressed through incremental mitigations alone.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。