Skills
A poisoned agent can write its own future attack chain into a benign-looking artifact and wait
SynChain uses persistence-aware directed supervised fine-tuning to make a computer-use agent produce artifacts that pass vetting yet hide malicious influence in their structural redundancies, so the payload survives internal state updates and reactivates in a later workflow with no new external input. Tested on OpenClaw, Codex, and Claude Code via CUAChain — 30 benign task chains and three attack objectives — it achieved high success against four defense settings and beat adapted baselines. The authors' conclusion is the actionable part: point-in-time artifact scanning cannot catch this, and defense requires provenance-aware reasoning over cross-task execution trajectories.
↳ Follow the thread