Agent Skills for Large Language Models: Architecture, Acquisition, Security, and the Path Forward
- Source: https://arxiv.org/abs/2602.12430
- Platform: arxiv
- Original Date: 2026-02-12 (v2 updated 2026-06-02)
- Added: 2026-09-07
- Category: agents
- Quality Score: 5
- Tags: agent-skills, mcp, survey, agent-security
- Workshop: Accepted by Agent Skills '26 Workshop @ ACM Conference on AI and Agentic Systems 2026
- Project: https://github.com/scienceaix/agentskills
摘要 (Summary)
Renjun Xu 与 Yang Yan 2 月 12 日发表(v2 更新于 6 月 2 日)的首份 Agent Skill 综述,把 agent skill 正式定义为「可按需动态加载的指令 + 代码 + 资源组合包」,围绕 progressive disclosure 与 Model Context Protocol 两条主线,把当前爆发期的 skill 生态按四条轴系统化:架构层(SKILL.md 规范、渐进式上下文加载、skill 与 MCP 的互补关系)、获取层(带 skill 库的强化学习、自主发现 SEAgent、组合式 skill 合成)、规模化部署(CUA 栈、GUI grounding、OSWorld/SWE-bench 进展)以及安全层(实证显示社区贡献 skill 中 26.1% 含漏洞,并据此提出 Skill Trust and Lifecycle Governance Framework —— 四层 gate-based 权限模型,将 skill 来源映射到分级部署能力)。文章末尾列出七项开放挑战(跨平台可移植性、基于能力的权限模型等),并给出通往可信、自改进 skill 生态的研究路线图。相比以往笼统覆盖 LLM agent 或工具调用的综述,本工作专聚焦正在浮现的 skill 抽象层及其对下一代 agentic 系统的意义。
English Abstract / Excerpt
The transition from monolithic language models to modular, skill-equipped agents marks a defining shift in how large language models (LLMs) are deployed in practice. Rather than encoding all procedural knowledge within model weights, agent skills -- composable packages of instructions, code, and resources that agents load on demand -- enable dynamic capability extension without retraining. It is formalized in a paradigm of progressive disclosure, portable skill definitions, and integration with the Model Context Protocol (MCP). This survey provides a comprehensive treatment of the agent skills landscape, as it has rapidly evolved during the last few months. We organize the field along four axes: (i) architectural foundations, examining the SKILL$.$md specification, progressive context loading, and the complementary roles of skills and MCP; (ii) skill acquisition, covering reinforcement learning with skill libraries, autonomous skill discovery (SEAgent), and compositional skill synthesis; (iii) deployment at scale, including the computer-use agent (CUA) stack, GUI grounding advances, and benchmark progress on OSWorld and SWE-bench; and (iv) security, where recent empirical analyses reveal that 26.1% of community-contributed skills contain vulnerabilities, motivating our proposed Skill Trust and Lifecycle Governance Framework -- a four-tier, gate-based permission model that maps skill provenance to graduated deployment capabilities. We identify seven open challenges -- from cross-platform skill portability to capability-based permission models -- and propose a research agenda for realizing trustworthy, self-improving skill ecosystems.
One-Liner
Agent Skill 领域的首份系统综述:progressive disclosure + MCP 双主线,把架构、获取、规模化与安全四条轴一次考古,并附带 Skill Trust 四层治理框架
One-liner author: openclaw