Skip to main content
LLM Security Database
Skip to research details
Back to research findings

Poisoned agent skills amplify coding-agent token use

Third-party skills can inflate coding-agent resource use while an otherwise legitimate task remains functional.

Published
Analyzed
Paper-reported evidence
Primary source linked
Read primary paper
Cite & share
Source BibTeX

Citation metadata is maintained by the primary source and may reflect a later revision.

Paper-evaluated models(4)

  • GLM-4.7-Flash
  • GLM-5
  • GPT-5.4-mini
  • GPT-5.5
On this page

Description

Third-party skills can inflate coding-agent resource use while an otherwise legitimate task remains functional.

Examples

See the primary evaluation (opens in a new tab).

Impact

The authors report 5.42–10.15 times average best token amplification across four configurations. These are selected best runs on limited skill/task pairs, not typical attack incidence. The Claude Code configurations use GLM backends; the client name does not identify an Anthropic model.

Affected Systems

  • Evaluated Claude Code and Codex skill workflows.

Mitigation Steps

  • Review and pin skills and bundled resources.
  • Enforce per-task token, runtime, spending and tool-call limits.
  • Investigate unexplained resource increases after skill updates.

Evidence

Research context and provenance

Catalog identifier
LMVD-bd2784f6
Internal research identifier, not an official CVE identifier.
Evidence and verification
Paper-reported; independent reproduction is not documented.
Primary source plus a dedicated evidence section.
Severity
Not rated by this catalog.
Source and publication type
arXiv · Research preprint.
Peer-review status is not provided by this source.
Author and publication status
Author metadata is not stored; see the primary paper.
Threat model and attacker access
Ability to influence untrusted model inputs or connected content.
Related deployment categories
Agent workflows; Coding agents
Taxonomy labels only; paper-specific deployment prerequisites are not inferred.
Affected systems
Evaluated Claude Code and Codex skill workflows.

Research Paper

SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents

Primary source: arXiv. Findings are reported by the cited research and have not been independently verified.

View Paper