acceptodds
Under review as a conference paper at ICLR 2027

SkillLineage: Black-Box Provenance Auditing of Agent Skills Across Language Models

Abstract

Agent skills package procedures, scripts, and reference materials for reuse across language models, but this portability makes their origin difficult to audit once they are copied, rewritten, or reconstructed behind another agent’s API. We study black-box skill provenance auditing: determining whether an opaque deployment derives from a protected skill or its outputs, rather than from an independently developed solution to the same task. The challenge is that provenance is easily confounded by two effects: independent same-task skills can exhibit similar functionality, while the same skill can appear different when deployed on another model. We introduce SKILLLINEAGE, to our knowledge the first passive fingerprinting framework for black-box agent skill provenance auditing, based on local behavioral correspondence. Using an owner-controlled model, it selects skill-sensitive contexts and queries the suspect with matching response prefixes. The resulting profile records continuation agreement at selected response positions and is compared with references generated with and without the protected skill. The audit uses only returned text, without prior modification of the protected skill or knowing its host model. Across five released skills, 240 deployments on three open-source models, and four black-box APIs, SKILLLINEAGE achieves a 0.9977 AUROC on the three primary skills using only Llama-based references.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.