🔥 Our paper “AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems” has been accepted to NDSS 2027!
Can a malicious agent worm spread across an LLM agent ecosystem after a single message? We show that the answer can be yes.
https://t.co/1sbPMjnPQl
12/
We hope AgentWorm helps motivate stronger security foundations for autonomous agent ecosystems.
Many thanks to all our coauthors and collaborators for making this work possible!
📄 https://t.co/1sbPMjnPQl
🔥 Our paper “AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems” has been accepted to NDSS 2027!
Can a malicious agent worm spread across an LLM agent ecosystem after a single message? We show that the answer can be yes.
https://t.co/1sbPMjnPQl
10/
Agent safety therefore needs to account for ecosystem-level threats:
state integrity, skill provenance, least-privilege execution, sandboxing, and propagation-aware monitoring.
🚨 Our paper SkillSafetyBench is accepted to #EMNLP2026 Main!
Agent skills are becoming the plugin ecosystem of LLM agents. We ask a simple question: what if the attacker is not the user, but the skill itself?
📄 https://t.co/hYMbRPPJSM
Takeaway: agent safety must be evaluated at the level of executable systems, not isolated model responses. As agents lean on skills, files, memory and toolchains, the trusted operational context is the attack surface.
💻 https://t.co/5ITFtCksGV