Schmotz, Abdelnabi, Andriushchenko
researchactive

Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections

Schmotz, Abdelnabi, Andriushchenko

View original resource

Research showing that Claude's Skills feature, which auto-loads Markdown instructions from the filesystem, enables trivial prompt injection via a single malicious file. Demonstrates data exfiltration and privilege escalation across common agent deployments.

Tags

agentic AIrisks

At a glance

Published

2025

Jurisdiction

International

Category

Risks and challenges

Access

Public access

Build your AI governance program

VerifyWise helps you implement AI governance frameworks, track compliance, and manage risk across your AI systems.

Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections | VerifyWise AI Governance Library