Fetching from the wire…
Public story · 2026-08-05 · high
Detection accuracy falls from 98.5% to 11.4%, and 80% of the poisoned skills survive after the source record is deleted.
Why now: Tencent published the SkillJack findings and proof-of-concept code together, so the attack is already reproducible instead of just described.
Self-evolving agents can turn a single poisoned experience into a skill they keep forever, per Tencent's SkillJack paper on arXiv.
That's what matters for anyone letting an agent write and reuse its own skills. Standard poisoned-data detection works 98.5% of the time on raw experience, but only 11.4% once that behavior is baked into a skill file.
The attack worked 56.2% of the time against the SkillX extraction system and 89.2% against Anything2Skill, per the paper's benchmarks.
Researchers deleted the original poisoned experience after an agent had already extracted a skill from it. 80% of those implanted skills survived anyway.
Most anti-poisoning defenses check inputs: prompts, training experience, tool outputs. SkillJack targets what an agent produces afterward, a skill file that becomes its own artifact with its own lifecycle. Tencent posted proof-of-concept code for the attack on GitHub, at github.com/Tencent/AI-Infra-Guard. That leaves provenance tracking on the skill itself, not just the experience that produced it, as the gap worth closing.
Each link below shares sources, entities, or timing with this story.
Tencent released Hy3 / Shared entity: Tencent / Earlier coverage
Linked by a graph relationship (Tencent released Hy3); both cover Tencent; earlier Tencent coverage from 2026-07-15.
Shared entities / Same source domain / Shared topic / Earlier coverage
Both cover Code, Tencent; reported by the same outlet (arxiv.org); overlapping topics (code, tencent).
Shared entity: Poisoned / Same source domain / Shared topic / Earlier coverage / Tension
Both cover Poisoned; reported by the same outlet (arxiv.org); overlapping topics (agent, attack, during).
Shared entity: Code / Same source domain / Shared topic / Earlier coverage / Tension
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, code).
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, code).
Shared entity: Code / Same source domain / Shared topic / Earlier coverage
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, become, code).
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, code, skill).
Both cover Code; reported by the same outlet (arxiv.org); overlapping topics (agent, code, skill).