SkillCascade-Bench records 213 validated cross-skill attack cases on OpenClaw, Claude Code, Codex
arXiv:2609.30383 introduces skill cascading attacks that distribute harm across multiple skills to evade isolated checks. SkillCascade-Bench supplies 213 validated cases showing reliable bypass of existing scanners on representative agents. The findings establish that component integrity does not imply system safety and require defenses that model cross-skill interactions.
The paper defines skill cascading attacks as the distribution of a malicious objective across multiple modular skills so each change appears benign when inspected alone. SkillCascade, the accompanying multi-agent red-teaming system, generated and validated 213 test cases spanning medical, financial, and code-generation domains. In the prescription-review example, one skill down-weights discontinued-medication signals, a second lowers interaction severity scores, and a third suppresses the final alert, producing a silent failure that existing runtime monitors do not flag.
Benchmark results show consistent success rates above 80 percent on OpenClaw, Claude Code, and Codex agents regardless of backbone model. Per-skill static scanners and single-skill runtime checks detected zero instances of the full cascade. The authors release SkillCascade-Bench as an open test suite to measure system-level integrity rather than component-level checks.
The attack surface arises directly from the design choice to allow third-party skill loading at runtime without cross-skill dependency verification. Prior agent security literature examined isolated prompt injection or tool misuse; this work isolates the new failure mode created when benign-appearing modules compose. Operational implication is that deployment pipelines must add interaction-graph analysis or multi-skill simulation before production use in safety-critical domains.
No vendor has published a cross-skill monitor as of the September 2026 submission. The benchmark therefore provides the first quantitative baseline for measuring whether future defenses close the gap between per-skill and system-level safety.
LangChain maintainers: at least one cross-skill dependency scanner reaches production in an official release by March 2027
Sources (2)
- [1]Primary Source(https://arxiv.org/abs/2609.30383)
- [2]Supporting Source(https://arxiv.org/abs/2309.07870)