cs.CRSep 28, 2026

PrivacySkills: How Privacy Guidance Shapes Source Selection in LLM Agents

Authors: Lucas Biechy, Cédric Eichler, Héber H. Arcolezi, Nicolas Anciaux

Organizations: Petscraft, Inria · Université Paris-Saclay · INSA CVL · Université d’Orléans · LIFO · ÉTS Montréal

Abstract

While prior work has documented privacy failures in LLM agents, it remains unclear how the presentation of privacy guidance influences their choice of information sources. We introduce PrivacySkills, a controlled framework for evaluating how agents choose among acquisition pathways that provide the same task-relevant value: consulting publicly available personal information, accessing confidential sources, or interacting with the user. The evaluation framework comprises 55 synthetic tasks spanning 11 categories of personal information, with 169 associated skills that describe the available acquisition pathways. We consider privacy guidance through system-level instructions, skill-level metadata labels, or both. Separately, we vary user availability and urgency framing. With users available and no privacy guidance, agents access confidential sources in 30% of valid runs on average across five open-weight models, despite sufficient alternatives. This rate increases to 45% when users are unavailable, whereas urgency framing has no detectable effect. System-level privacy instructions alone have limited effects on confidential access, while skill-level intrusiveness labels produce a modest reduction (24% on average), but combining the two roughly halves confidential access. Our findings motivate incorporating privacy annotations into skill specifications and evaluating their effectiveness alongside system-level instructions.

Figures & tables

Appendix figures & tables6 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. PrivacyPeek: Auditing What LLM-Based Agents Acquire, Not Just What They Say

    May 29, 2026Mingxuan Zhang, Jiahui Han, Dadi Guo +5PrivacyAttacker Large Language Model

  2. PrivacyAlign: Contextual Privacy Alignment for LLM Agents

    Jun 19, 2026Manveer Singh Tamber, Abhay Puri, Marc-Etienne Brunet +3Large Language Model AgentsPrivacy

  3. Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents

    Jun 25, 2026Nada Lahjouji, Ashwin Gerard ColacoPrivacyLarge Language Model Agents