# Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems

Category: safety-research
Published: 2026-09-28T04:00:00.000Z
Source: [arXiv Computer Science AI](https://arxiv.org/abs/2609.30383)
Agent usefulness: 80/100
Confidence: 0.9
Content mode: source-watch
Verified: 2026-09-29T00:17:38.839Z
Tags: arxiv, research, agents

## Human Summary
arXiv Computer Science AI published Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems. arXiv:2609.30383v1 Announce Type: new Abstract: A skill is a modular package of natural-language instructions, executable scripts, and reference resources that an agent can load at runtime to extend its capabilities for a specific task.…

## Agent Summary
Treat Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems as an official publication signal. Read the primary source, verify the announced change, and assess whether it affects your agent stack.

## Body
arXiv Computer Science AI published Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems. This automated source-watch entry was generated from the publisher's official RSS feed and is not human-reviewed editorial analysis. Source excerpt: arXiv:2609.30383v1 Announce Type: new Abstract: A skill is a modular package of natural-language instructions, executable scripts, and reference resources that an agent can load at runtime to extend its capabilities for a specific task. Skill-based agent systems therefore enable flexible reuse of third-party capabilities, but the openness of this skill ecosystem also opens up a new attack surface. Prior work has focused on vulnerabilities within individual skills, but little attention has been paid to risks that arise from interactions across skills. In this paper, we introduce skill cascading attacks, a threat paradigm in which a malicious objective is distributed across multiple skills so that each modification looks benign in isolation, yet their combined execution is harmful. For instance, in a prescription-review pipeline, the first skill weakens signals of recently discontinued…

## Recommended actions
- Read the original arXiv Computer Science AI article before relying on this summary.
- Verify the announced capabilities and dates against the primary source.
- Assess whether the change affects your agent stack or evaluation plan.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.