Back to today's list

Formal Analysis and Supply Chain Security for Agentic AI Skills

Varun Pratap Bhardwaj

Published Aug 6, 2026
Editorial review6.5
Relevance0.474
Freshness0.000

Why It Matters

What makes this one worth your time

Understanding and securing agentic AI skills is crucial as their deployment increases, impacting both security and reliability in AI applications.

A formal analysis of supply chain security for agentic AI skills with an open-source evaluation tool.

Summary

The paper presents a formal analysis of agentic AI skills, focusing on supply chain security and providing an open-source tool for evaluation, while correcting previous claims and validating experimental results.

Key contributions

  • Formal proofs of five theorems related to agentic AI skills and supply chain security.
  • An open-source tool for evaluating security in AI skills, enhancing reproducibility and accessibility.
  • Corrections to prior claims regarding the prevalence of malicious tools and vulnerabilities.

Notable insights

  • The paper emphasizes the importance of accurate data verification in security claims, as seen in the corrections made to previous reports.
  • The negative result in information flow analysis suggests that traditional pattern matching may be more effective than complex analyses in this context.

Possible limitations

  • Not stated in the abstract.

Abstract

arXiv:2603.00195v2 Announce Type: replace-cross Abstract: 32 pages, 5 theorems with full proofs, 68 references, open-source tool: https://github.com/qualixar/skillfortify. v2: corrects the bibliography (22 entries had author lists that did not match the papers at the cited arXiv identifiers; all verified against the arXiv API and corrected, and affected authors notified) and three external claims against primary sources: MalTool reports 1,300 standalone and 5,727 embedded malicious tools, not 6,487; CVE-2026-25253 is authentication-token exfiltration via an unvalidated gatewayUrl, credited to depthfirst and fixed in 2026.1.29, not remote code execution through a crafted skill package; ClawHavoc counts are 341, later 824, and 1,184 by source and date, not "over 1,200". All experiments re-measured against the released v0.6.0 implementation using harnesses now committed to the repository. E1/E2 unchanged (F1 96.15%). E3 reverses to a negative result: information flow analysis adds no detections over pattern matching on this corpus. The soundness theorem's scope is stated explicitly and no longer conflated with the zero false-positive rate.