Can Useful Work Be the Attack? CUCKOO SKILLS: PARASITIC TOKEN-COST ATTACKS ON LLM AGENTS
Abstract
Reusable skills guide LLM agents through workflows, but can introduce resource-use risks that final output quality alone may not reveal. Existing token-cost attacks induce excess steps, but agents may skip costly instructions, and aggregate token counts alone cannot distinguish amplification across instances from isolated expensive failures. We revisit skill-guided execution and observe that intermediate preparation can substantially increase computation while producing artifacts compatible with task completion. Based on this observation, we propose CUCKOO SKILLS, a token-cost attack framework that couples feedback-guided skill construction with constrained candidate selection. Autonomy-Preserving Structured Construction (APSC) uses routing feedback to guide skill adoption and execution feedback to refine optional work and its outputs for subsequent task steps. Budget-Exhaustive Risk-Sensitive Selection (BERS) uses paired executions to assess task utility and cross-instance amplification, prioritizing qualified candidates and ranking them by aggregate cost. Across ARC-Challenge, LegalBench, and -bench with two backbone models, CUCKOO SKILLS consumes 3.34–94.50 as many completion tokens as clean execution, with amplification ratios 2.57–6.90 times those of the strongest evaluated baseline in each setting. Across all three datasets, reasoning accounts for 66.08–99.01% of completion tokens, and substantial amplification coexists with useful task outputs. These findings highlight resource risks that evaluations based only on final-answer quality may overlook.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.