{"id":8111,"date":"2026-01-21T05:34:00","date_gmt":"2026-01-20T20:34:00","guid":{"rendered":"https:\/\/devneko.jp\/wordpress\/?p=8111"},"modified":"2026-01-18T14:37:35","modified_gmt":"2026-01-18T05:37:35","slug":"agent-skills-in-the-wild-an-empirical-study-of-security-vulnerabilities-at-scale","status":"publish","type":"post","link":"https:\/\/devneko.jp\/wordpress\/?p=8111","title":{"rendered":"Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale"},"content":{"rendered":"\n<ul class=\"wp-block-list\">\n<li><strong>Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale\u00a0<\/strong>[26.8]<br>AI\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u306e\u53f0\u982d\u306f\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u30b9\u30ad\u30eb\u3001\u547d\u4ee4\u3092\u542b\u3080\u30e2\u30b8\u30e5\u30fc\u30eb\u30d1\u30c3\u30b1\u30fc\u30b8\u3001\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u6a5f\u80fd\u3092\u52d5\u7684\u306b\u62e1\u5f35\u3059\u308b\u5b9f\u884c\u53ef\u80fd\u306a\u30b3\u30fc\u30c9\u3092\u5c0e\u5165\u3057\u305f\u3002 \u3053\u306e\u30a2\u30fc\u30ad\u30c6\u30af\u30c1\u30e3\u306f\u5f37\u529b\u306a\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3092\u53ef\u80fd\u306b\u3059\u308b\u304c\u3001\u30b9\u30ad\u30eb\u306f\u6697\u9ed9\u306e\u4fe1\u983c\u3068\u6700\u5c0f\u9650\u306e\u62d2\u5426\u306b\u3088\u3063\u3066\u5b9f\u884c\u3055\u308c\u3001\u91cd\u8981\u306a\u304c\u4e0d\u9069\u5408\u306a\u30a2\u30bf\u30c3\u30af\u30b5\u30fc\u30d5\u30a7\u30b9\u3092\u751f\u307f\u51fa\u3059\u3002 2\u3064\u306e\u4e3b\u8981\u306a\u5e02\u5834\u304b\u308942,447\u306e\u30b9\u30ad\u30eb\u3092\u53ce\u96c6\u3057\u3001\u3053\u306e\u65b0\u8208\u30a8\u30b3\u30b7\u30b9\u30c6\u30e0\u306e\u6700\u521d\u306e\u5927\u898f\u6a21\u306a\u7d4c\u9a13\u7684\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5206\u6790\u3092\u884c\u3044\u307e\u3059\u3002<br><a href=\"http:\/\/arxiv.org\/abs\/2601.10338v1\">\u8ad6\u6587<\/a>\u00a0\u00a0<a href=\"https:\/\/fugumt.com\/fugumt\/paper_check\/2601.10338v1\">\u53c2\u8003\u8a33\uff08\u30e1\u30bf\u30c7\u30fc\u30bf\uff09<\/a>\u00a0 \u00a0(Thu, 15 Jan 2026 12:31:52 GMT)<\/li>\n\n\n\n<li>\u300cWe conduct the first large-scale empirical security analysis of this emerging ecosystem, collecting 42,447 skills from two major mar- ketplaces and systematically analyzing 31,132 using SkillScan, a multi-stage detection framework integrating static analysis with LLM-based semantic classification. Our findings reveal pervasive security risks: 26.1% of skills contain at least one vulnerability, spanning 14 distinct patterns across four categories\u2014prompt injection, data exfiltration, privilege escalation, and supply chain risks. Data exfiltration (13.3%) and privilege escalation (11.8%) are most prevalent, while 5.2% of skills exhibit high-severity patterns strongly suggesting malicious intent.\u300d\u3068\u306a\u304b\u306a\u304b\u885d\u6483\u7684\u306a\u5831\u544a\u3002\u3002<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[352],"class_list":["post-8111","post","type-post","status-publish","format-standard","hentry","category-arxiv","tag-security"],"_links":{"self":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/8111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8111"}],"version-history":[{"count":1,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/8111\/revisions"}],"predecessor-version":[{"id":8112,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/8111\/revisions\/8112"}],"wp:attachment":[{"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devneko.jp\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}