SkillJack targets the experience-to-skill pipeline of self-evolving agents, turning poisoned interaction trajectories into reusable malicious skills rather than relying on poisoned context retrieval. The authors evaluate the attack on SkillX and Anything2Skill using 150 trajectories across four policy-risk categories. Reported results show that SkillX safety detection falls from 98.5% on poisoned trajectories to 11.4% on extracted skills, while attack success reaches 56.2% and 89.2% on the two systems. Moreover, 80.0% of skill-mediated attacks reportedly survive deletion of the original poisoned records, and some implanted skills activate on benign queries.
No heat snapshots are available in the last 24 hours.