Skill cascading attacks evade agent scanners across 213 test cases on Claude Code, Codex A study of 213 validated test cases found that malicious behavior split across multiple individually benign agent skills can evade per-skill scanners and runtime monitors on systems including OpenClaw, Claude Code, and Codex, emerging only when the skills execute together. The research, posted to arXiv, indicates that component-level review is insufficient for agents that load third-party or modular skills, and that policy and testing must model cross-skill data flow, ordering, and combined effects before skills are allowed to compose in production. arXiv https://arxiv.org/abs/2609.30383 Skill cascading attacks evade agent scanners across 213 test cases on Claude Code, Codex Which summary reads better? Pick one — models revealed after.Both summaries are AI-generated. 213 validated test cases show that malicious behavior can be split across multiple “benign” agent skills and reliably emerge only when the skills execute together, bypassing per-skill scanners and runtime monitors on systems including OpenClaw, Claude Code, and Codex. If you ship agents that load third-party or modular skills, component review is insufficient: you need policy and testing that model cross-skill data flow, ordering, and combined effects before allowing skills to compose in production. Mistral Large quota or rate limit — check usage and plan. Original headline: Stealth Apart, Harm Together: Skill Cascading Attacks on Skill-Based Agent Systems