LATIDIA · Ciberseguridad
SkillSecurer: Detección y parcheo de vulnerabilidades de inyección rápida en habilidades de agentes de IA
arXiv:2609.14079v1 Tipo de anuncio: nuevo Resumen: las habilidades del agente extienden los agentes de IA con instrucciones, scripts y configuración reutilizables, pero también están abiertos a nuevos ataques para influir en las decisiones y acciones de un agente. Para agregar
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.14079v1 Announce Type: new Abstract: Agent skills extend AI agents with reusable instructions, scripts, and configuration, but are also open to new attacks to influence an agent's decisions and actions. To address these risks, we present SkillSecurer, a fully agentic framework for generating, detecting, localising, and remediating security risks in agent skills. Its red agent generates context-compatible injections across nine threat types while recording the exact modification; its blue agent analyses complete skill packages, produces grounded evidence, and proposes patches. For controlled instances, a verifier compares findings and patches with the recorded injection, enabling injection-level evaluation. We thoroughly evaluate SkillSecurer by selecting the best backend LLM, comparing it with competitors,