Chaining Skills to Hijack LLM Agents
A new attack vector has been discovered that allows attackers to hijack LLM agents by chaining skills together to induce false claims of user approval. This can be done by creating a record of task progress that is used by downstream skills to direct the attacker-selected action.
Save an API key to vote.