ATR-2026-00125highSkill Compromiseexperimental
Context Poisoning via Compaction Survival
Detects instructions in SKILL.md files designed to survive context window compaction (summarization). When AI agents compress their context, poisoned instructions embed themselves as "important" directives that persist across compaction boundaries. Discovered via Claude Code leak analysis (2026-03): attackers used CLAUDE.md/SKILL.md to inject instructions that survived context compression by using urgency markers, persistence directives, and system-level impersonation.
嚴重度
high
類別
Skill Compromise
掃描目標
skill
作者
ATR Community
建議回應
alertblock input
參考資料
OWASP Agentic
ASI01:2026 - Agent Goal Hijack
OWASP LLM
LLM01:2025 - Prompt Injection