技术报告:探索智能体技能生态系统的新兴威胁
密码学与安全
2026-05-28 v1 人工智能
摘要
我们分析了来自主要市场的3,984个AI智能体技能,发现了76个确认的恶意有效载荷,包括凭证盗窃、后门安装和数据外窃。13.4%的所有技能至少包含一个关键级安全问题,且至少8个已确认的恶意技能仍在clawhub.ai上公开可用。本报告记录了我们的 methodology,基于真实世界样本提出了威胁分类法,并详细描述了我们观察到的攻击模式。随着技能市场的快速增长以及AI智能体获取敏感凭证和系统访问权限,自动化安全分析已不再是可选任务。
引用
@article{arxiv.2605.28588,
title = {Technical Report: Exploring the Emerging Threats of the Agent Skill Ecosystem},
author = {Luca Beurer-Kellner and Aleksei Kudrinskii and Marco Milanta and Kristian Bonde Nielsen and Hemang Sarkar and Liran Tal},
journal= {arXiv preprint arXiv:2605.28588},
year = {2026}
}
备注
10 pages, technical report