Research
SkillSecurer Finds Latent Prompt-Injection Vulnerabilities in More Than 17% of Popular Published Agent Skills
SkillSecurer pairs a red agent that generates context-compatible injections across nine threat types (recording the exact modification) with a blue agent that analyses complete skill packages and proposes patches, so a verifier can score detection and remediation at injection level rather than skill level. With its best backend it is the only scanner in the comparison to reach a 100% injection detection rate. Applied to popular published skills, it found latent vulnerabilities in more than 17% of those examined, and triggered real incidents when those skills were run.
↳ Follow the thread