[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83653-en":3,"doc-seo-83653-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83653,3848291630094,"Emma Wilson","https://eur-avatar.wpscdn.com/davatar_085a072bc5b1113ac321206ff7593b45",8,"Research & Report","Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware","LLM coding agents increasingly depend on third-party agent skills from public marketplaces, expanding software supply-chain risk: a malicious skill executes with the agent’s privileges and can steal credentials, exfiltrate source code, or plant backdoors. Static skill scanners based on pattern matching or LLM-as-judge analysis may fail under adaptive evasion. The work introduces SKILLCLOAK to preserve malicious semantics while transforming payload appearance and SKILLDETONATE, a behavior-centric runtime auditor using sandbox execution and OS-boundary information-flow evidence for high-accuracy detection.","Cloak and Detonate: Scanner Evasion and Dynamic Detection of Agent Skill Malware  \nZimo Ji 1 , Congying Xu 1,2,* , Zongjie Li 1 , Yudong Gao 1 , Xin Wei 1 , Shuai Wang 1,* , Shing-Chi Cheung 1,2  \n1Hong Kong University of Science and Technology 2 Guangzhou HKUST Fok Ying Tung Research Institute, China  \n{zjiag, zligo, shuaiw, [scc}@cse.ust.hk](scc}@cse.ust.hk), {congying.xu, ygaodj, [xweiba}@connect.ust.hk](xweiba}@connect.ust.hk)  \n* Corresponding authors  \narXiv :2607 .02357v2 [ cs .CR] 3 Jul 2026  \nAbstract—LLM coding agents increasingly rely on third-party agent skills from public marketplaces, which execute with the agent’s privileges and create a software supply-chain attack surface: a malicious skill can steal credentials, exfiltrate source code, or install backdoors. Existing defenses use static skill scanners based on pattern matching or LLM-as-judge analysis, but it remains unclear whether they withstand adaptive evasions that preserve malicious behavior while changing payload appearance.  \nThis paper first presents an adversarial study of existing skill scanners through SKILLCLOAK, a payload-preserving evasion framework that keeps the attack semantics intact while transforming their visible form. SKILLCLOAK uses two complementary strategies: Structural Obfuscation, which rewrites visible payload indicators into semantically equivalent forms, and Self-Extracting Skill (SFS) Packing, which hides malicious components from the install-time view and restores them during agent execution. Across eight scanners and 1,613 in-the-wild malicious skills, SFS Packing bypasses every scanner at over 90%, while Structural Obfuscation bypasses over 80% on most static scanners and reaches 96% on a hybrid scanner, showing that appearance-based auditing is insufficient.  \nMotivated by this finding, we propose SKILLDETONATE, a behavior-centric runtime auditor that executes skills in a sandbox and detects malicious effects through OS-boundary information-flow evidence rather than install-time appearance. SKILLDETONATE combines on-demand closure lift, which observes instructions materialized during execution, with markerbased taint analysis, which tracks sensitive-data flows across the agent context, files, processes, and network operations. The results show that SKILLDETONATE detects 97% of attacks at a 2% false-positive rate and sustains 87% detection on real-world malicious skills.  \nIndex Terms—LLM agents, agent skills, software supply chain, dynamic analysis, information-flow tracking, evasion attacks  \nI. INTRODUCTION  \nLLM agents are rapidly moving from demonstrations to realworld deployment across domains, including software engineering (e.g.,“vibe coding” assistants [1]), cybersecurity [2], and autonomous driving [3] . A key enabler of this transition is the emergence of Agent Skills: modular packages that allow agents such as Claude Code [4] and OpenAI Codex [5] to acquire new capabilities on demand. A skill is typically distributed asa structured directory containing natural-language instructions (e.g., [SKILL.md](SKILL.md)), executable scripts or code blocks, and auxiliary resources that an agent can load and invoke during task execution [6] . Because skills are model-agnostic, composable, and shareable as ordinary files, they are increasingly becoming a unit of capability distribution for agentic systems, with public  \nskill marketplaces growing rapidly [6], [7] . The scale of this ecosystem is already substantial: within months of the open standard being introduced in late 2025, a single marketplace had accumulated over 40,000 publicly listed skills [8], the overwhelming majority of which are community-contributed and unvetted.  \nThis extensibility, however, introduces a new software supply-chain risk. Once installed, a skill is interpreted and executed by an agent that may have access to the developer’s workspace, local files, credentials, package managers, terminals, and external services. A malicious skill can therefore a","cbCaieWDvmDiB8Dd","https://ap.wps.com/l/cbCaieWDvmDiB8Dd","pdf",1846401,2,1,12,"English","en",105,"# Introduction\n## Problem and motivation\n## Adversarial study motivation\n# Proposed methods\n## SKILLCLOAK\n## SKILLDETONATE\n# Results and evaluation\n## Scanner bypass effectiveness\n## Runtime detection performance","[{\"question\":\"What risk do third-party agent skills introduce for LLM coding agents?\",\"answer\":\"Third-party skills execute with the agent’s inherited privileges, enabling malicious actions such as credential theft, source-code exfiltration, backdoor installation, and destructive operations.\"},{\"question\":\"How does SKILLCLOAK evade existing static skill scanners?\",\"answer\":\"SKILLCLOAK preserves attack semantics while changing visible form via structural obfuscation of payload indicators and Self-Extracting Skill (SFS) packing that hides malicious components until execution.\"},{\"question\":\"What detection approach does SKILLDETONATE use and how is it different from static scanners?\",\"answer\":\"SKILLDETONATE runs skills in a sandbox and detects malicious effects through runtime, OS-boundary information-flow evidence using on-demand closure lift and marker-based taint analysis rather than install-time appearance.\"}]",1784189532,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"cloak-and-detonate-scanner-evasion-and-dynamic-detection-of-agent-skill-malware","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/cloak-and-detonate-scanner-evasion-and-dynamic-detection-of-agent-skill-malware/83653/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What risk do third-party agent skills introduce for LLM coding agents?","Question",{"text":75,"@type":76},"Third-party skills execute with the agent’s inherited privileges, enabling malicious actions such as credential theft, source-code exfiltration, backdoor installation, and destructive operations.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does SKILLCLOAK evade existing static skill scanners?",{"text":80,"@type":76},"SKILLCLOAK preserves attack semantics while changing visible form via structural obfuscation of payload indicators and Self-Extracting Skill (SFS) packing that hides malicious components until execution.",{"name":82,"@type":73,"acceptedAnswer":83},"What detection approach does SKILLDETONATE use and how is it different from static scanners?",{"text":84,"@type":76},"SKILLDETONATE runs skills in a sandbox and detects malicious effects through runtime, OS-boundary information-flow evidence using on-demand closure lift and marker-based taint analysis rather than install-time appearance.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]