acceptodds
Under review as a conference paper at ICLR 2027

SkillDOS: Token Amplification Attacks via Poisoned Skills in LLM Agents

Abstract

Skills enable LLM-based agents to follow reusable workflows, invoke external tools, and complete complex tasks, but they also introduce a new attack surface. Existing research on agent-skill security has primarily focused on prompt injection, data exfiltration, and unauthorized actions, while resource-exhaustion attacks through poisoned skills remain comparatively underexplored. We introduce SkillDOS (Skill-based Denial of Service), an automated framework that amplifies an agent's output-token consumption through poisoned skills. Rather than causing explicit failures or non-terminating execution, SkillDOS induces additional bounded, task-relevant work while preserving the final user-visible answer. SkillDOS decomposes a poisoned skill into an Inducer, which promotes adoption of an injected workflow, and an Amplifier, which scales workload through repetition, grounded work-unit expansion, and per-unit elaboration. A one-way two-stage optimizer first refines the Inducer until execution evidence confirms a distinctive Amplifier mechanism, then freezes the Inducer and searches Amplifier configurations for greater output-token amplification under an answer-preservation constraint. We evaluate SkillDOS on 100 real-world skills across three agent frameworks and four backend models using a sandboxed paired-baseline protocol. The results demonstrate substantial output-token amplification across diverse agent-model configurations while maintaining high task preservation. These findings reveal a practical and underexplored resource-exhaustion risk in skill-enabled LLM agents.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.