Borrowed Authority: Agent Skills Carry No Typed Way to Reject a Permission Claim, and Edge Skillguard Rejects 60/60 Attacks
Zhan and Haddadi name the gap between two documented attack classes, malicious skills compromising cloud software and jailbroken LLM-controlled robots causing physical harm: because the Skills format gives a receiving agent no typed mechanism to reject an inter-agent permission claim, a malicious skill can attach one and drive real actuation. Their argument is that self-evolving skill harnesses generate more advisory orchestration but no policy, so scaling skill generation scales the gap rather than the safety. Their Edge Skillguard co-packages a typed authority layer inside the skill artifact with guards over world state and sensor evidence, rejecting 60/60 borrowed-authority requests across five attack variants without blocking benign traffic, holding at 5x scale and across hosts.
↳ Follow the thread