Story · @omarsar0
EvoMal: shared skill libraries let coding agents poison themselves (@omarsar0)
X post · Story page
elvis summarizes EvoMal (arXiv 2608.25776): a malicious skill planted in a shared library is never invoked directly, but agents copy it as an authoring template and the payload spreads. As reported, six models on 153 SWE-bench Verified tasks showed self-poisoning rates of 20.3-41.8%, and libraries ended up with 4.9-9.0x as many malicious skills as were planted.
In plain words
- EvoMal reports that coding assistants can copy and spread harmful instructions hidden inside shared collections of reusable skills.
- The harmful skill is never used directly by the coding assistant.
- Instead, the assistant copies it as an example when writing new skills, preserving the hidden harmful instructions.
- Those new skills return to the shared collection, where later assistants can copy them again.
- In reported tests, copied harmful skills multiplied, so teams sharing reusable instructions may face continuing danger even after removing originals.
Appeared in
- A website summary hijacks Claude Code Auto Mode, and handoffs turn must into maybe
Aug 28, 2026 · from X
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.