Papers for

platform operators

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Ai agents can spread harmful content through shared memory artifacts

Share-Borne AI Virus: Memory-Hopping Attacks Across LLM Agents

Abstract: Large language models are increasingly deployed as stateful assistants that retain information across interactions and use tools to read, modify, and create persistent artifacts. As these artifacts are shared between users, they form an indirect communication channel between otherwise independent assistants. We study a failure mode in which this channel enables self-propagating attacks. We introduce artifact-mediated propagation, where adversarial content introduced through an artifact (e.g. a report), is stored in an assistant's persistent memory, reproduced in a subsequently created artifact, and acquired by another assistant that later reads it. We evaluate this process in temporal human-agent universes that model artifact exchange between independently operated assistants over time, measuring whether an attack survives successive hand-offs, how many hops it reaches, and how broadly it spreads. We find that attacks can propagate across multiple independent assistants and persist over extended interaction sequences. In larger simulated environments, even GPT-5.6 Luna exhibits substantial spread, reaching 60-80% of agents with propagation chains extending to eight hops. These results show that persistent artifacts can act as durable carriers of adversarial state, allowing attacks to outlive individual interactions and spread across isolated assistants.

Mon 28 SeptArtificial IntelligenceComputation and LanguageCryptography and Security
The gist
Large language model assistants can keep memories and share files that help them work with each other. The authors found that bad content can sneak into these shared files and then be passed along from one assistant to another, like a virus. This attack can last a long time and reach many different assistants, even if they are supposed to be separate. The researchers tested this across different setups and saw that some attacks spread widely and lasted for many steps.
Open → 2609.35576v1

AI agent skills boom shows challenges in governance and cleanup

After the Party: Governing What a Viral Agent-Skill Ecosystem Left Behind

Abstract: AI agents increasingly act through agent skills, i.e., natural-language instructions, that direct a host agent toward shell, network, credential, file, and process actions, and public registries distribute them at scale. In the first half of 2026, the OpenClaw AI agent went viral, and its public skill registry boomed: the observable stock nearly doubled in 91 days, and a majority of the listings visible in June were created in just two months. By the end of our study window, the wave had crested, and monthly listing creation and core-repository activity were falling from their spring peaks. This paper measures what the boom left behind, drawing on the OpenClaw Git history, its GitHub issues and pull requests, and three ClawHub registry snapshots. Attention is concentrated: the top 10% of skills received 46.93% of all downloads. No simple skill features (like size or download counts) remained a stable predictor of continued listing once creation cohort and skill age were controlled. Human scrutiny did not stay: 77.86% have zero stars and zero comments, while 85.06% of the readable skills carry privilege evidence. And automated cleanup is not ready: the three security scanners disagreed on 23,702 of the 61,990 skills they all cover. After human adjudication, weighted scanner sensitivity against the reference standard ranged from 21.67% to 61.06%. Governing fast-growing agent-skill registries cannot rely on simple metadata or single scanner scores; it requires robust, transparent measurement and independent validation.

Tue 15 SeptSoftware EngineeringArtificial IntelligenceComputers and Society
The gist
AI tools called agent skills help automate many computer tasks, and a popular one called OpenClaw saw a huge rise in new skills in early 2026. The authors found that most of these skills got little attention or review, many had risky permissions, and tools to automatically check their safety often disagreed. This means keeping these AI skill collections safe and well-managed is more complicated than just looking at download numbers or simple checks.
Open → 2609.17274v1