LATIDIA · Ciberseguridad
SKILLLITE: Auditoría de habilidades maliciosas guiadas por evidencia con LLM compactos
arXiv: 2609.36879v1Tipo de anuncio: nuevo Resumen: A medida que los agentes basados en LLM realizan tareas cada vez más complejas, las habilidades del agente se han convertido en un mecanismo flexible para ampliar sus capacidades. Una habilidad de agente empaqueta el lenguaje de tareas
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.36879v1 Announce Type: new Abstract: As LLM-based agents perform increasingly complex tasks, Agent Skills have emerged as a flexible mechanism for extending their capabilities. An Agent Skill packages task-specific instructions with executable components and auxiliary resources to provide specialized functionalities. However, the growing adoption of third-party Skills introduces a new supply-chain attack surface. Malicious Skills can embed harmful behaviors that abuse agent privileges and compromise the agent execution environment or accessible resources. Although recent LLM-based malicious Skill auditing approaches have achieved promising performance, they often rely on capable commercial LLMs. How to achieve effective auditing with compact, locally deployable LLMs in security-sensitive and resource-constrained settings remains largely unexplored. Our investigation