Story · @omarsar0

EvoMal: shared skill libraries let coding agents poison themselves (@omarsar0)

X post · Story page

elvis summarizes EvoMal (arXiv 2608.25776): a malicious skill planted in a shared library is never invoked directly, but agents copy it as an authoring template and the payload spreads. As reported, six models on 153 SWE-bench Verified tasks showed self-poisoning rates of 20.3-41.8%, and libraries ended up with 4.9-9.0x as many malicious skills as were planted.

In plain words

  • EvoMal reports that coding assistants can copy and spread harmful instructions hidden inside shared collections of reusable skills.
  • The harmful skill is never used directly by the coding assistant.
  • Instead, the assistant copies it as an example when writing new skills, preserving the hidden harmful instructions.
  • Those new skills return to the shared collection, where later assistants can copy them again.
  • In reported tests, copied harmful skills multiplied, so teams sharing reusable instructions may face continuing danger even after removing originals.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.