The LMVD-ID is an internal research identifier, not an official CVE identifier.
Poisoned agent skills amplify coding-agent token use
Third-party skills can inflate coding-agent resource use while an otherwise legitimate task remains functional.
Paper-evaluated models(4)
- GLM-4.7-Flash
- GLM-5
- GPT-5.4-mini
- GPT-5.5
Description
Third-party skills can inflate coding-agent resource use while an otherwise legitimate task remains functional.
Examples
See the primary evaluation (opens in a new tab).
Impact
The authors report 5.42–10.15 times average best token amplification across four configurations. These are selected best runs on limited skill/task pairs, not typical attack incidence. The Claude Code configurations use GLM backends; the client name does not identify an Anthropic model.
Affected Systems
- Evaluated Claude Code and Codex skill workflows.
Mitigation Steps
- Review and pin skills and bundled resources.
- Enforce per-task token, runtime, spending and tool-call limits.
- Investigate unexplained resource increases after skill updates.
Evidence
Research context and confidence
- Evidence and verification
- Paper-reported; independent reproduction is not documented.
- Primary source plus a dedicated evidence section.
- Severity
- Not rated by this catalog.
- Source and publication type
- arXiv · Research preprint.
- Peer-review status is not provided by this source.
- Author and publication status
- Author metadata is not stored; see the primary paper.
- Threat model and attacker access
- Ability to influence untrusted model inputs or connected content.
- Related deployment categories
- Agent workflows; Coding agents
- Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
- Affected systems
- Evaluated Claude Code and Codex skill workflows.
Research Paper
SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents
Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.
View PaperRelated research
- Context privilege escalation in AI agent harnesses
Published September 1, 2026 · application-layer, prompt-layer, injection
- Persistent Agent Memory Poisoning and Incomplete Repair
Published July 29, 2026 · application-layer, prompt-layer, injection
- Workspace Agent Runtime Safety Failures Across Risk Carriers
Published July 29, 2026 · application-layer, prompt-layer, injection