cs.AISep 23, 2026

Progressive Skill Discovery as Access Control for Tool-Using LLM Agents: Structural Governance through Role-Scoped Capability Delivery

Authors: Michael Stettler, Benjamin Girardet, Jonas Canton, Nicolas Corod

Organizations: Skilder

Abstract

Large Language Model (LLM) agents struggle to scale safely when exposed to vast enterprise toolsets. Providing an agent with access to every internal tool leads to oversized context windows, degraded tool selection, and severe governance vulnerabilities - as system policies defined purely in prompts remain probabilistic advice rather than hard constraints. Existing mitigations, such as multi-agent domain delegation, decentralize audit logs and fail to guarantee policy compliance across sessions. We introduce skilder, a framework that packages capabilities into roles: bundles of skills, tools, and instructions, together with the limits that bound them. An agent begins with a minimal role catalog, learns the roles a task requires, and receives each role's skills, instructions, and tools through a single MCP server. Because tools reach the agent only inside learned skills, the same server enforces the scope of what was learned deterministically. We evaluate skilder against flat-context tool selection and multi-agent orchestration across 13 tasks using six models (10 runs each). Our results show that, when models completed discovery and issued a governed call, the skilder simulated authorization layer enforced governance boundaries: no unauthorized tool call or parameter violation (e.g., a spending-limit breach) executed. Aggregate task pass rates also reflect whether each model followed the discovery protocol and satisfied response-quality checks; those misses are not authorization failures. Furthermore, by allowing agents to dynamically acquire cross-role capabilities mid-task, skilder preserves problem-solving flexibility while providing hard system-level enforcement.

Figures & tables

Appendix figures & tables9 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Skill-Use: Can LLMs Actually Use Skills in Agentic Harnesses?

    Aug 5, 2026Jinyi Han, Yuanjian Xu, Ying Liao +6SkillsAgent Harness

  2. Reachability-Based Capability Confinement for LLM Agents under Indirect Prompt Injection

    Aug 30, 2026Wujie Xiong, Rabimba Karanjai, Yang Lu +2LLM Defense MechanismsLarge Language Model Agents

  3. SkillJuror: Measuring How Agent Skill Organization Changes Runtime Behavior

    Jun 10, 2026Zhiyu Chen, Zihan Guo, Bo Huang +4Agent Skill RetrievalSkills