Pith. sign in

REVIEW 1 cited by

Formal Analysis and Supply Chain Security for Agentic AI Skills

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2603.00195 v2 pith:4CWAULXN submitted 2026-02-27 cs.CR cs.AIcs.SE

classification cs.CRcs.AIcs.SE
keywords analysisarxivaddsaffectedagenticauthentication-tokenauthorauthors
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

32 pages, 5 theorems with full proofs, 68 references, open-source tool: https://github.com/qualixar/skillfortify. v2: corrects the bibliography (22 entries had author lists that did not match the papers at the cited arXiv identifiers; all verified against the arXiv API and corrected, and affected authors notified) and three external claims against primary sources: MalTool reports 1,300 standalone and 5,727 embedded malicious tools, not 6,487; CVE-2026-25253 is authentication-token exfiltration via an unvalidated gatewayUrl, credited to depthfirst and fixed in 2026.1.29, not remote code execution through a crafted skill package; ClawHavoc counts are 341, later 824, and 1,184 by source and date, not "over 1,200". All experiments re-measured against the released v0.6.0 implementation using harnesses now committed to the repository. E1/E2 unchanged (F1 96.15%). E3 reverses to a negative result: information flow analysis adds no detections over pattern matching on this corpus. The soundness theorem's scope is stated explicitly and no longer conflated with the zero false-positive rate.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SynChain: Inducing Computer-Use Agent Systems to Construct Their Own Attack Chains

    cs.CR 2026-08 conditional novelty 6.0 of 10

    A backdoored computer-use agent can be induced to write poisoned but benign-looking skills during ordinary tasks, and those skills later trigger attacks after being reloaded as trusted context.

Pith tools