Skip to content

■ SIGNALS // RADAR SIGNAL

the skill folder is an execution surface

An evaluation of malicious skill files shows why imported agent instructions need admission, isolation, and receipts before they touch real credentials.

■ [!] ON THIS PAGE ▼

self.md radar — 2026-08-15

A folder called skills now has the same problem as a package install: somebody else’s setup instructions can arrive dressed as routine work. A new evaluation makes the cost of treating that folder as harmless prose painfully legible.

1. the skill file is an execution surface

sources:

what happened:

Researchers turned 471 real shell commands into benign-looking skill-file instructions, then tested Gemini CLI and Qwen Code in auto-approved mode. Across 5,629 completed runs, the paper reports exploitability estimates of 95.5–96.1% for Gemini CLI and 71.6–74.0% for Qwen Code; explicit safety recognition appeared in 1.99% of runs. It is a preprint, not a verdict on every agent or configuration, but the replication package shows the actual setup: an injected skill file, a sandbox template, and logs used to judge intent.

the collision:

Skills are how a personal agent stops being a chat window and starts doing useful work. That also makes each imported instruction bundle part of the permission boundary, even when it arrives as plain language in a friendly repository. “Read the skill before you run it” is not enough once an agent can read it and run the preflight itself; admission, isolation, and a receipt for every external skill become basic hygiene.

question left open:

What should an agent have to show before a skill can move from a folder on the internet into a machine with real credentials?

left on the table

  • Mole has a serious local-research posture — enforced budget, checked quotes, local data boundary — but it is still a young tool drop rather than evidence that those controls have changed somebody’s operating conditions.
  • OpenBiliClaw remains out: it was in yesterday’s published history, and its promise of local context does not yet document a credible custody boundary.
  • Google’s private-AI claim was tempting for the portable-home lens, but the available source trail did not yield a clean primary technical account; it stays a lead, not a fieldnote.