SkillBloat: Token Amplification Attacks via Skill Injection in LLM Coding Agents
Abstract
Agent skills extend coding agents with task-specific instructions, scripts, and resources. They can enhance coding agents while they may cause unnecessary computation and huge token consumption if agents follow malicious ones. This paper studies token amplification through skill injection: an economic resource-abuse threat in which an adversarial skill induces substantially higher token consumption than execution with the original benign skill. We present SkillBloat, a two-phase framework to produce malicious skills that amplify resource usage while preserving task completion. Across real-world coding-agent tasks, SkillBloat achieves up to 75.86× token amplification on individual tasks, with average best amplification ranging from 5.42× to 10.15× across multiple agent–model configurations. Unlike prior skill-poisoning attacks that target security consequences such as data exfiltration and file tampering, our work shows that skill poisoning can also cause economic resource abuse, which warrants broader research community attention toward resource-aware defenses in agent skill ecosystems.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.