发表机构
Chongqing University; Northeastern University at Qinhuangdao; Sun Yat-sen University; Tencent; Nanyang Technological University(重庆大学; 东北大学秦皇岛分校; 中山大学; 腾讯; 南洋理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究发现智能体技能扫描器存在检查-执行间隙,提出PyCache陷阱攻击方法,还提出执行感知验证(EAV)可检测此类攻击,相关代码已公开。
AI 中文摘要
智能体技能将指令与可执行资源相结合,使第三方包能够访问智能体的运行时环境。现有技能扫描器会检查文档和可见源代码,但Python可能会执行行为不同的捆绑字节码缓存。我们通过PyCache陷阱研究这种检查与执行之间的间隙,该陷阱将良性源代码与加载器接受的替换缓存配对,并将其连接到与任务相关的调用。扫描器引导的重写会改变调用措辞,同时保留缓存主体,将包准入与对隐藏行为的识别分离开来。在100个技能和7个扫描器上,PyCache陷阱实现了94%-100%的攻击成功率,且未对缓存驻留行为进行语义识别。我们提出执行感知验证(EAV),以在类型化执行图中连接已检查的指令、脚本、导入和运行时工件。EAV将基于基础的行为分析与编译工件的可信复现相结合,它检测了所有100个被评估的存在源代码的缓存替换,在5个攻击系列和200个良性技能上,在10.0%的FPR下达到92.8%的召回率。研究结果支持在技能准入过程中,检查运行时可选择的可执行工件,包括受支持的加载器和代码对象规范化。代码已在此https URL发布。
英文摘要
Agent skills combine instructions with executable resources, giving third-party packages access to an agent's runtime. Existing skill scanners inspect documentation and visible source, but Python may execute a bundled bytecode cache with different behavior. We study this gap between inspection and execution through PyCache Trap, which pairs benign source with a substituted cache accepted by the loader and connects it to a task-relevant invocation. Scanner-guided rewriting changes the invocation wording while preserving the cache body, separating package admission from recognition of the concealed behavior. Across 100 skills and seven scanners, PyCache Trap achieves 94-100% attack success, with no semantic recognition of the cache-resident behavior. We propose execution-aware validation (EAV) to connect inspected instructions, scripts, imports, and runtime artifacts in a typed execution graph. EAV combines grounded behavioral analysis with trusted reproduction of compiled artifacts. It detects all 100 evaluated source-present cache substitutions and reaches 92.8% Recall at 10.0% FPR across five attack families and 200 benign skills. The results support checking the executable artifacts a runtime can select as part of skill admission, within the supported loaders and code-object normalization. The code is released at https://github.com/leo0481/PyCacheTrap.
Comments28 pages, 5 figures. Code: https://github.com/leo0481/PyCacheTrap