Opening SecureFlowSkillJack: Poisoned Experience Trajectories Become Persistent Agent Skills
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

SkillJack researchers aidefend-sf0049

SkillJack: Poisoned Experience Trajectories Become Persistent Agent Skills

  • Autonomous Agents
  • AI Infrastructure
  • Model Poisoning & Integrity
  • System Compromise & RCE

The SkillJack paper evaluates SkillX and Anything2Skill, which transform agent experience trajectories into reusable skills. In a synthetic AppWorld study using one DeepSeek-v4-flash API, poisoned trajectories survived the transformation and evaded the evaluated routing-level detectors, with reported persistence after source records were deleted. The work is a controlled research result, not a demonstrated compromise of a real organization's skill registry or external service.

Mapped threat techniques

  • AML.T0020 Training Data Poisoning
  • AML.T0119 Exploit Automated Artifact Processing Pipeline
  • AML.T0123 Obfuscated Files or Information
  • AML.T0110 AI Agent Tool Poisoning

Source