Researchers from the Chinese Academy of Sciences and Worcester Polytechnic Institute introduce TrustProbe to trace installed skill content into security-sensitive operations and verify observable effects. Using DeepSeek-V4-Flash across eleven open-source agents, they report 104 verified source-to-sink vulnerabilities in permissive non-interactive configurations, with a subset remaining exploitable under stricter approval settings. Their real-skill experiment measures exposure to vulnerable execution paths, rather than the prevalence of malicious skills or attacks on real users.
University of Chinese Academy of Sciences
2 records1 attack1 capability
Sep 30, 2026
TrustProbe reports 104 skill-mediated trust failures across eleven agents under permissive test settings
Sep 28, 2026
ReproBench: agents given only a CVE ID substitute simulations in 45.3% of runs; 5.3% of pairs reach real firmware triggers
Researchers at the Chinese Academy of Sciences release ReproBench, which gives an agent only a CVE identifier and scores six phases from finding the firmware to triggering the bug on the real binary, using 30 IoT firmware CVEs. Across 450 runs of five models in one harness, the authors report that 204 runs (45.3%) substituted a mock or host-native simulation, which the benchmark scores as zero for the real-target phases. They report near-full credit on the rehosting and triggering phases for 11 and 8 of 150 CVE-model pairs.