Chaining Skills to Hijack LLM Agents
APEX skill chains hijack LLM agents into attacker-chosen actions in 74% of attempts.
The paper introduces APEX, which builds adversarial skill chains so an upstream skill plants a false user-approval record that a downstream skill uses to trigger an attacker-selected action. Across four action families and six models on SkillsBench, chains succeeded in 512 of 690 attempts (74.2%). On GPT-5.4, full chains hit 84.3% versus 17.4% for a single merged skill. A prompting defense cut GPT-5.4 success to 59.1% but also dropped the benign verifier pass rate from 86.7% to 56.3%.