David Schmotz

h-index: 1 6 citations 2 papers (total)

Papers in Database (2)

attack arXiv Oct 30, 2025 · Oct 2025

Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections

David Schmotz, Sahar Abdelnabi, Maksym Andriushchenko · ELLIS Institute Tübingen · MPI for Intelligent Systems +1 more

Exploits LLM Agent Skills plugin framework for trivial indirect prompt injection, exfiltrating files and bypassing Claude Code guardrails

Prompt Injection Insecure Plugin Design nlp
8 citations 1 influentialPDF Code
benchmark arXiv Feb 23, 2026 · 6w ago

Skill-Inject: Measuring Agent Vulnerability to Skill File Attacks

David Schmotz, Luca Beurer-Kellner, Sahar Abdelnabi et al. · Max Planck Institute for Intelligent Systems · Snyk

Benchmarks LLM agent susceptibility to skill-file prompt injection, finding up to 80% attack success on frontier models

Prompt Injection Insecure Plugin Design nlp
PDF Code