2 papers
cs.CR2026
When Agents Learn to Be You: Benchmarking Privacy Leakage, Impersonation Risk, and Defenses in Persona Skills
Yongli Xiang, Zhifang Zhang, Bojun Yang +4
Persona skills distill personal interaction histories into portable and executable artifacts for downstream agents. While enabling flexible personalization, this process concentrat…
cs.CR2026
Poise: Position-Aware One-Instruction Skill Injection for Silent Execution on LLM Agents
Haochang Hao, Dehai Min, Zhifang Zhang +4
Agent skills extend general-purpose agents, but their open format enables skill poisoning: a tampered skill can make an agent run an attacker's command while completing the user's…