Research
ColluSkill Splits One Malicious Intent Across Several Benign-Looking Agent Skills, Hitting 96.0% Attack Success Against Six Skill Scanners
Published 2026-08-10, ColluSkill shows that today's agent-skill scanners inspect skills one at a time, so an attacker can decompose a malicious workflow into interdependent sub-payloads packaged as separately-plausible skills that only become harmful when composed through artifact passing and execution handoffs. Against six representative scanners the average attack success rate is 96.0%. The authors' defense, ChainGuard, jointly analyzes a candidate skill against skills already installed and cuts ASR to 22.5% while passing 99.5% of benign workflows — the practical takeaway is that per-skill review is structurally insufficient for any marketplace-style skill ecosystem.
↳ Follow the thread