ResearchAgent Skills in the Wild 42447 Skills Audited 26% VulnerablearXiv·high signalXBlueskyLinkedInCopy linkLargest MCP/skill security study. 42,447 skills, 26.1% contain vulnerabilities across 14 patterns. SkillScan detection framework.SourceSource pagearXiv↳ Follow the threadStack layer / Threat patternLLMVul: 21,430 LLM-Generated C/C++ Functions Mined From 226 Production Repos, 1,540 Vulnerable Across 17 CWEsarXiv 2609.10945Stack layer / Threat patternSkill optimization via contextual bandits cut optimization cost 55-58% using only 50 examples per benchmarkarXiv 2609.11682Stack layer / Threat patternA Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full SetarXiv 2609.11814Policy dependency / Stack layerHolding Back Ready Agent Turns Instead of Releasing Them Eagerly Cuts P95 Workflow Latency up to 3.50xarXiv 2609.10964Threat patternReDoS Bugs Are Now Far More Likely to Be Exploited Than Other Vulnerabilities, and Five Detection Tools Disagree on Which Regexes Are VulnerablearXiv 2609.10294Threat patternUnder Accumulating Disruption, Agents Shift From Self-Recovery to Human Dependence While Their Text Hides the StrainarXiv 2609.10724Stack layer / Threat patternEvoSafeHarness searches policies and code together to build a per-model safety harness, cutting attack success from 45.6% to 10.0%arXiv (2609.05903)Threat patternRanking agents by cross-path consistency between forward and backward reasoning beats voting and LLM judges when agents disagreearXiv