Agents
SkillBloat turns a poisoned agent skill into a 5.4x to 10.1x token bill, with no data exfiltration involved
SkillBloat frames skill injection as economic resource abuse rather than a security compromise: a malicious skill makes a coding agent burn far more tokens than the task needs. The two-phase framework screens a library of amplification mechanisms then refines the strongest candidate through LLM-guided full-document skill rewriting, hitting 5.4184x to 10.1455x average best amplification across coding-agent target configurations on a real-world skill benchmark. This attack surface is orthogonal to skill poisoning, so scanners looking for exfiltration or dangerous commands will not flag it.
Source
↳ Follow the thread