SkillGuard: A Permission-Centric Framework for Agent Skill Security
- ID: 59198e37
- 原文链接: https://arxiv.org/abs/2606.03024
- PDF: https://arxiv.org/pdf/2606.03024v2
- 作者: Shidong Pan, Xiaoyu Sun, Tianyi Zhang, Dianshu Liao, Kaiwen Yang, Zhenchang Xing
- 日期: 2026-06-02
- 更新: 2026-07-13
- 分类: cs.CR, cs.SE
- 来源类型: arxiv
- 标签: agent-skills, permissions, least-privilege, security, skill-ecosystem, arxiv
- 质量评分: 4/5
- 抓取时间: 2026-09-06T04:24:00Z
中文导读
技能(skills)为 LLM 智能体扩展可复用的指令、脚本、数据与工具绑定,也因此成为智能体系统里新的安全主体:技能能在任何工具调用之前改变智能体的推理,也能把智能体引向有具体副作用的动作。而现有技能生态缺少刻画这种双重角色的权限模型——既有防御要么在使用前检查技能文件,要么在执行期约束单次工具调用,技能层意图、上下文影响与运行时行为之间的治理连接是薄弱的。SkillGuard 把技能视为携带权限的可执行工件,引入双平面治理模型,通过技能清单(manifest)、运行时权限控制、用户交互与策略执行,同时约束上下文影响与动作副作用。在 1260 个真实技能上验证权限分类学的表达力,覆盖 99.93% 的受保护对象;在 SkillInject 对抗集上,把上下文注入攻击成功率从 35.3% 降到 20.7%,明显注入从 36.7% 降到 18.0%,同时良性任务完成率保持良好。
为什么值得关注
Claude 式技能生态的安全缺口:技能会在工具调用前改写推理SkillGuard 给技能发权限,双平面同时治理影响与副作用
English Abstract
Skills extend LLM agents with reusable instructions, scripts, data, and tool bindings. This shift makes skills a new security principal in agent systems: a skill can alter the agent's reasoning before any tool is called, and it can also steer the agent toward actions with concrete side effects. However, current skill ecosystems lack a permission model that captures this dual role. Existing defenses either inspect skill files before use or constrain individual tool calls during execution, leaving the connection between skill-level intent, contextual influence, and runtime behavior weakly governed. In this paper, we present SkillGuard, a skill-centric permission framework that treats skills as permission-bearing executable artifacts.
Obsidian 证据
- 元数据与摘要经 opencli arxiv paper 2606.03024 核对(2026-09-06T04:24:00Z);中文导读锚定摘要陈述的事实与数字。