← Back to brief
ResearchOfficialPreprintarXiv Cryptography and Security

SkillGate: Screening Malicious Skill Files in AI Coding Agents

A new arXiv preprint introduces SkillGate, a security gateway designed to detect malicious skill files in AI coding agents such as Cursor and GitHub Copilot. SkillGate combines regex-based prefiltering with LLM-based judgment, achieving an F1 score of 0.817 and reducing LLM input tokens by 77% on the SkillsBench benchmark. The tool addresses a recently identified supply-chain attack vector involving skill files that can compromise agent behavior.

Why it matters: SkillGate targets a novel and growing security risk in the AI coding ecosystem, offering a potential defense against malicious skill packages that could impact a wide range of users.

Full story at: arXiv Cryptography and Security

More coverage