4 papers
Semia: Auditing Agent Skills via Constraint-Guided Representation Synthesis
Hongbo Wen, Ying Li, Hanzhi Liu +4
An agent skill is a configuration package that equips an LLM-driven agent with a concrete capability, such as reading email, executing shell commands, or signing blockchain transac…
Synthesizing Multi-Agent Harnesses for Vulnerability Discovery
Hanzhi Liu, Chaofan Shou, Xiaonan Liu +4
LLM agents have begun to find real security vulnerabilities that human auditors and automated fuzzers missed for decades, in source-available targets where the analyst can build an…
Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
Hanzhi Liu, Chaofan Shou, Hongbo Wen +3
Large language model (LLM) agents increasingly rely on third-party API routers to dispatch tool-calling requests across multiple upstream providers. These routers operate as applic…
Automated Repair of OpenID Connect Programs (Extended Version)
Tamjid Al Rahat, Yanju Chen, Yu Feng +1
OpenID Connect has revolutionized online authentication based on single sign-on (SSO) by providing a secure and convenient method for accessing multiple services with a single set…