Story · arXiv
Towards a Risk Assessment of Malicious Skill Files in Coding Agents (arXiv)
paper · Story page

The paper treats third-party skill files as the supply-chain risk they are: a 2,826-skill benchmark of malicious skills concealing shell commands, mapped to 11 MITRE ATT&CK tactics, with high reported exploitation rates for Gemini CLI and Qwen Code.
In plain words
- Researchers created 2,826 harmful instruction files designed to hide commands that can attack a computer.
- The files look like ordinary written guidance but conceal commands that coding tools may execute.
- The researchers grouped the hidden commands into 11 kinds of attacker behavior and tested them across thousands of completed runs.
- Gemini’s command-line coding tool and Qwen Code showed high rates of successful attacks.
- People adding third-party instruction files could unknowingly give harmful commands to their coding tools.
Appeared in
- Claude Code turns auto mode on for everyone; reward-hack monitors catch 28%
Aug 11, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
