技能即API:面向智能体软件工程的保密多智能体协调机制
Skill-as-API: Confidential Multi-Agent Coordination for Agentic Software Engineering
浏览论文内容
中文总结 AI 辅助
针对多智能体协调的知识产权泄露问题,提出Skill-as-API协议,实现技能主体不跨网传输,结合XMTP开源实现完成拉取请求审核案例验证。
中文摘要 AI 辅助
AI编码智能体正从单一工具演变为能发现并调用彼此专业技能的协作伙伴,但协调通道本身可能泄露技能的知识产权。MCP、A2A等协议在服务器端运行实现,却仍向所有对等节点公开每个技能的描述和类型化模式,无法隐藏技能的存在,也无法保证封装的系统提示词不被传输。应用层隐私过滤器仅在模型决定输出敏感文本后才发挥作用。我们采用互补的协议层方案:Skill-as-API,一种协调协议,其技能的公开视图仅包含名称、描述、类型化输入/输出模式和信任层级,技能主体以闭包形式捕获于所有者进程内,绝不跨网络传输。四层结构添加访问控制,从结构上缩小提示词注入面而非通过内容过滤。我们提供基于XMTP的开源Python实现,跨大洲热重连延迟为1.8-2.9秒,以及一个软件工程案例研究:三个智能体协调拉取请求审核,同时各自保留其专有分析提示词的所有权。
英文摘要
AI coding agents are evolving from solitary tools into collaborative teammates that discover and invoke one another's specialized skills. But the coordination channel itself can leak a skill's intellectual property. Protocols such as MCP and A2A run implementations server-side, yet they still publish each skill's description and typed schemas to every peer, offer no way to hide a skill's existence, and cannot guarantee that a wrapped system prompt stays off the wire. Application-layer privacy filters help, but act only after the model has decided to emit sensitive text. We take a complementary, protocol-layer route: Skill-as-API, a coordination protocol whose public view of a skill is limited to its name, description, typed input/output schemas, and trust tier. The skill body is closure-captured in the owner's process and never crosses the wire. Four layers add access control and narrow the prompt-injection surface structurally rather than by filtering content. We provide an open-source Python implementation over XMTP with 1.8-2.9 s cross-continent hot-reconnect latency, and a software-engineering case study in which three agents coordinate a pull-request review while each retains ownership of its proprietary analysis prompts.
发表机构
- Technical University of Munich(慕尼黑工业大学)
- London Business School(伦敦商学院)
机构由 AI 辅助整理,请以论文原文为准。