How do you poison an agent that learns skills? Hijack the experience-to-skill pipeline and make the backdoor stick.
1 comment
The scary bit to me isnt even the obvious backdoor, its that the extraction step can scrub enough context that the skill looks clean while still carrying the behavior. I maintain a small provenance tracker for agent traces, and this would make me want some kind of signed lineage on skills, not just on the source trajectories.