cs.CRAug 9, 2026

SkillsMetric: Mapping the Detection Boundary of Static Analysis for Malicious Agent Skills

Authors: Xinze ChenChi ZhangPing JiYimin Liu

Organizations: The Graduate Center, City University of New York · New York, NY, USA · Hunter College, City University of New York · The Ohio State University · Columbus, OH, USA

Abstract

Agent Skills---structured packages of instructions and scripts that augment LLM-based agents---are rapidly proliferating, yet their security properties remain under-explored. We present \textsc{SkillsMetric}, a five-stage static analysis framework that scores skill packages along pattern density, statistical anomaly, dataflow taint, import anomaly, and capability mismatch dimensions. We construct an adversarial evaluation dataset of 2{,}266 skills spanning 16~attack types across code-level, system-level, and semantic-level threats, and evaluate on the full SkillMD-138K corpus. Our framework achieves an AUC of 0.93 and 5-fold cross-validated F1 of 73.4%±\pm0.5%, with strong detection of data exfiltration (93%) and steganographic payloads (93%). Crucially, we identify fundamental blind spots: \emph{host destruction} attacks using common shell commands evade all five stages (0% detection), and \emph{prompt injection} via natural-language manipulation achieves only 42% detection. These findings establish that static analysis alone is insufficient for skill security, motivating defense-in-depth architectures that combine fast static pre-screening with semantic review.

Explore similar work

CardsList
  1. Detecting Malicious Agent Skills in the Wild using Attention

    Jun 22, 2026Bacem Etteib, Daniele Lunghi, Tégawendé F. BissyandéMalicious CodeIndirect Prompt Injection