SkillScope: Toward Fine-Grained Least-Privilege Enforcement for Agent Skills
Jiangrong Wu, Yuhong Nan, Yixi Lin, Huaijin Wang, Yuming Xiao, Shuai Wang, Zibin Zheng
Abstract
Agent Skills have become a practical way to extend LLM agents by packaging metadata, natural-language instructions, and executable resources into reusable capability bundles. However, this growing Skill ecosystem introduces a new compliance risk: a Skill may perform high-impact actions that fall outside the scope permitted by the user's current request, thereby violating least privilege. Existing skill detection approaches are insufficient for this problem because it is inherently task-conditioned: the same action may be legitimate under one user prompt but over-privileged under another.
In this paper, we present SkillScope, a framework for fine-grained least-privilege enforcement in Agent Skills. SkillScope adopts a graph-based analysis approach that models instruction-level procedures and code-level operations as fine-grained action nodes. It extracts potential over-privilege candidates, validates them under graph-instantiated user tasks through runtime analysis, and constrains validated over-privileged actions via control-flow privilege constraining.
We evaluate SkillScope through effectiveness experiments and large-scale real-world measurement. SkillScope achieves a 94.53% skill-level F1 score for over-privilege detection. In the wild, SkillScope validates 6,590 of 68,312 valid real-world Skills as exhibiting over-privileged behaviors, showing that least-privilege violations are prevalent in current Skill ecosystems. In the privilege-constraining evaluation, SkillScope reduces triggered over-privileged action-in-task instances by 88.56% while preserving legitimate task completion.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7b1cee6a-cc56-4596-b672-042ccef602bcBuilds on16
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni et al.NeurIPS 2020 · 19,162 citations
- G-Eval: NLG Evaluation using Gpt-4 with Better Human AlignmentYang Liu, Dan Iter, Yichong Xu, Shuohang Wang et al.EMNLP 2023 · 549 citations
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- Formalizing and Benchmarking Prompt Injection Attacks and DefensesYupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia et al.USENIX Security 2024 · 308 citations
- DRIFT: Dynamic Rule-Based Defense with Injection Isolation for Securing LLM AgentsHao Li, Xiaogeng Liu, Hung-Chun Chiu, Dianqi Li et al.NeurIPS 2025 · 76 citations
Related papers
- "Do Not Mention This to the User": Detecting and Understanding Malicious Agent Skills in the WildYi Liu, Zhihao Chen, Yanjun Zhang, Gelei Deng et al.USENIX Security 2026 · 46 citations
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless FunctionsChanghee Shin, Bom Kim, Seungsoo LeeINFOCOM 2026 · 1 citation
- Skill VM: Write Once, Run Everywhere EfficientlyLe Chen, Erhu Feng, Yubin Xia, Haibo ChenSOSP 2026
- No More, No Less: Least-Privilege Language ModelsPaulius Rauba, Dominykas Seputis, Patrikas Vanagas, Mihaela van der SchaarICML 2026
- PrivEscalate: Measuring and Augmenting the Threat of LLM-Automated Linux Privilege EscalationYixuan Liu, Zilong Zhen, Yin Wu, Yi LiCCS 2026
