Fetching from the wire…
Public story · 2026-08-05 · high
AntiSkillBench tested four defenses against the leak and every one broke once the researchers swapped the underlying model.
Why now: AntiSkillBench landed in the August 5 briefing as the paper to read before you ship a portable persona.
AntiSkillBench found that persona skills leak private details across unrelated conversations in all three frontier agents tested, per the paper posted to arXiv. That's a risk for anyone building products that compress a user into a reusable artifact. The leakage went beyond explicit attributes into communication style and personality traits, drawn from 7,500 dialogue traces built off 50 profiles.
The researchers tested four defenses meant to stop the leak. All four were distillation-dependent, and none held up once the underlying model changed. The paper doesn't say how the compression step decides what to keep, which is the exact point where the leakage starts.
Persona portability and privacy protection are pulling in opposite directions. A file compact enough to carry someone's history between agents is compact enough to carry the parts you didn't mean to hand over. Nothing tested here stops that once you swap in a different model. Watch for a defense that survives a model swap. None does yet, on this evidence.
Each link below shares sources, entities, or timing with this story.
arXiv 2607.25936 shows models maintain an assigned role and reproduce its behaviors even when doing so produces wildly inefficient reasoning. RolePlay constructs adaptive personas that induce coherent but computationally expensive output, averaging 7.64x token amplification wi...
Thinkingbox is an MCP-compatible sandbox with isolated sessions, full execution traces, and outcome evaluation against terminal backend state, carrying 507 policy-conditioned workflows across retail, hospitality, auto insurance, neobank internal IT and consulting support (arXi...
First systematic comparative security analysis of four major agent communication protocols. Essential reading for builders choosing between them for multi-agent systems. arXiv 2602.11327
OpenAI Devs announced on August 26 that WebMCP works in the ChatGPT desktop app's built-in browser and in ChatGPT Sites, so ChatGPT and Codex can call a site's declared tools directly. WebMCP is an experimental web standard adding navigator.modelContext to the browser, letting...
Agents routinely declare tasks complete before actually finishing. They submit duplicates. They drift from goals. There's now a formal benchmark to measure this, and the results should worry anyone deploying agents in production. Researchers introduced Quantitative Goal Persis...
The first systematic comparative security analysis of MCP, A2A, Agora, and ANP. Key finding: identity forgery is a cross-protocol vulnerability — MCP relies on free-text names without cryptographic binding, A2A's JWT-based auth is vulnerable to agent card forgery, ANP's DID sy...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.