Fetching from the wire…
Public story · 2026-08-25 · high
A poisoned skill can inflate a coding agent's token use with no exfiltration or dangerous commands, so scanners built to catch those miss it entirely.
Why now: The finding was current as of August 25, 2026.
A poisoned skill can push a coding agent's token use up to 10.1 times higher without tripping exfiltration or command scanners, per the SkillBloat paper. Across coding-agent configurations tested on a real-world skill benchmark, the researchers measured average best-case amplification between 5.4184x and 10.1455x.
Coding agents that run against a subscription quota instead of a metered API key have no dollar alert to catch that kind of multiplier. The task runs slower until the quota runs dry, with no fraudulent charge and no unusual-spend flag to trigger.
Skill-security scanners are built to catch a different crime. They look for data exfiltration and dangerous shell commands. A benchmark this cleanly built around token waste alone means that category of tooling has nothing to check for here.
The paper doesn't say what makes a skill trigger the amplification, or whether skills like it are already circulating in public marketplaces. That gap is the one worth watching before the finding turns into an incident.
Each link below shares sources, entities, or timing with this story.
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, benchmark, best); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (agent, amplification, attack, token); pushes against this story (but).
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, attack, benchmark); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, benchmark, best); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, benchmark, skill); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, attack, benchmark); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, benchmark, skill); pushes against this story (against).
Same source domain / Shared topic
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, benchmark, best, skill).