Convergent Detour Hijacking: Task-Preserving Resource Amplification in Skill-Based LLM Agents
By Junliang Liu · Paper · cs.CR
LLM agents increasingly rely on third-party skills, using natural-language descriptions for selection and instruction bodies for planning. This progressive-disclosure design exposes two sequential control points to untrusted publishers: a static skill may steer an otherwise corre