Study reveals hiding agent skill files is ineffective, achieving 86.8% recovery rate

dair_ai · x · 2026-08-30

A new paper investigates whether hiding agent skill files actually protects them, with concerning results. Attackers can reconstruct multi-file skills using only data from ordinary tasks, without asking the victim to reveal the skill or grade a reconstruction, bypassing disclosure filters.

At the weakest access level, where the attacker sees only the final response and returned files, the method recovers 86.8% of the original skill's capability across 7 skills and 4 victim models. This is roughly 4x better than SigLeak, with a median of just 32 victim calls per skill, even with disclosure defenses enabled.

Original post →

More from Safety

Safety channel →