Research
Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
Researchers demonstrate that LLM coding agents using third-party skills from open marketplaces are vulnerable to supply-chain attacks that hijack the agent's action space — including file writes, shell commands, and network requests. Unlike traditional package attacks, malicious skills execute as operational directives with system-level privileges, meaning a single poisoned skill can fully compromise the host agent. This is the first study to empirically test supply-chain hijacking of agent action spaces despite existing safeguards.
Source
↳ Follow the thread