Towards a Risk Assessment of Malicious Skill Files in Coding Agents
A new study from arXiv (submitted Aug 5, 2026) finds that coding agents are highly vulnerable to malicious skill files, with Gemini CLI exploited in 95.5-96.1% of runs and Qwen Code in 71.6-74.0% of r…