PAPER / ARXIV:2609.13353
Yuxin Tian, Zenghao Duan, Liang Pang, Zhiyi Yin, Xueqi Cheng
RESUMO
Agent skills are reusable units for language-model agents, but their risks emerge through model decisions, user context, tool calls, and execution feedback rather than through stable signatures. We present SkillAtlas, a hosted attack trace library converting private agent-skill security report bundles into reviewed, redacted, and searchable public cases. The library contains 3,014 cases, 6,589 traces, 151,131 steps, 233 affected skills, and 8 risk categories; trajectory-grounded labels improve pre-execution guard accuracy to 0.77.
NO MESMO MAPA