researchactive
Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections
Schmotz, Abdelnabi, Andriushchenko
View original resourceResearch showing that Claude's Skills feature, which auto-loads Markdown instructions from the filesystem, enables trivial prompt injection via a single malicious file. Demonstrates data exfiltration and privilege escalation across common agent deployments.
Tags
agentic AIrisks
At a glance
Published
2025
Jurisdiction
International
Category
Risks and challenges
Access
Public access
Build your AI governance program
VerifyWise helps you implement AI governance frameworks, track compliance, and manage risk across your AI systems.