Skip to main content
LLM Security Database
Skip to research details
Back to research findings
LMVD-ID: bd2784f6
Paper published August 22, 2026
Entry analyzed September 9, 2026
Paper-reported evidence
Confidence: Source-linked

The LMVD-ID is an internal research identifier, not an official CVE identifier.

Poisoned agent skills amplify coding-agent token use

Third-party skills can inflate coding-agent resource use while an otherwise legitimate task remains functional.

Read primary paperBibTeX citation

Paper-evaluated models(4)

  • GLM-4.7-Flash
  • GLM-5
  • GPT-5.4-mini
  • GPT-5.5

Description

Third-party skills can inflate coding-agent resource use while an otherwise legitimate task remains functional.

Examples

See the primary evaluation (opens in a new tab).

Impact

The authors report 5.42–10.15 times average best token amplification across four configurations. These are selected best runs on limited skill/task pairs, not typical attack incidence. The Claude Code configurations use GLM backends; the client name does not identify an Anthropic model.

Affected Systems

  • Evaluated Claude Code and Codex skill workflows.

Mitigation Steps

  • Review and pin skills and bundled resources.
  • Enforce per-task token, runtime, spending and tool-call limits.
  • Investigate unexplained resource increases after skill updates.

Evidence

Research context and confidence

Evidence and verification
Paper-reported; independent reproduction is not documented.
Primary source plus a dedicated evidence section.
Severity
Not rated by this catalog.
Source and publication type
arXiv · Research preprint.
Peer-review status is not provided by this source.
Author and publication status
Author metadata is not stored; see the primary paper.
Threat model and attacker access
Ability to influence untrusted model inputs or connected content.
Related deployment categories
Agent workflows; Coding agents
Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
Affected systems
Evaluated Claude Code and Codex skill workflows.

Research Paper

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.

View Paper