Fetching from the wire…
Public story · 2026-08-11 · high
The attack hides malicious intent across separate skills that only turn dangerous when they pass work to each other, and a fix cuts success to 22.5%.
Why now: The paper posted August 10 and built its case by testing scanners that inspect one skill at a time, the design ChainGuard argues is not enough.
ColluSkill breaks agent-skill security by splitting one malicious workflow into several skills that look harmless alone, per researchers behind the August 10 paper. That matters for any marketplace reviewing skills one at a time: six representative scanners let the attack through 96.0% of the time on average.
The trick is decomposition. Instead of packaging an attack as one bad skill, ColluSkill breaks it into pieces that each pass as a normal, single-purpose skill. The payload only turns harmful once those pieces hand off artifacts and execution to each other in sequence. That's exactly the moment a scanner built to judge one skill at a time stops looking.
The researchers also built a fix. ChainGuard checks a candidate skill against the skills already installed, rather than reviewing it alone, and cuts the attack success rate to 22.5% while still passing 99.5% of legitimate workflows, per the paper.
The shape of the problem isn't new to agent security. A related report on StepJack found that splitting a single prompt injection across three web pages nearly doubles its success rate against computer-use agents. Same logic: defenses built around one artifact, one page, one skill, miss attacks engineered to cross that boundary.
Each link below shares sources, entities, or timing with this story.
Same source domain / Semantically similar
Reported by the same outlet (arxiv.org); covers closely related ground (similarity 0.82).
Reported by the same outlet (arxiv.org); covers closely related ground (similarity 0.80).
Reported by the same outlet (arxiv.org); covers closely related ground (similarity 0.77).
Reported by the same outlet (arxiv.org); covers closely related ground (similarity 0.76).
Same source
Cite the same source (arXiv 2608.09732).
Cite the same source (arXiv 2608.09732).
Same source domain / Semantically similar
Reported by the same outlet (arxiv.org); covers closely related ground (similarity 0.75).
Reported by the same outlet (arxiv.org); covers closely related ground (similarity 0.75).