2 papers
cs.CR2026
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
Shi Liu, Xuehai Tang, Xikang Yang +4
The rise of tool-using Large Language Model (LLM) agents, standardized by protocols like the Model Context Protocol (MCP), has unlocked unprecedented autonomous execution capabilit…
cs.CR2026
RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents
Wenjie Xiao, Xuehai Tang, Biyu Zhou +2
Agent skills introduce a new and more severe form of indirect injection for LLM agents: unlike traditional indirect prompt injection, attackers can hide malicious instructions insi…