{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:VWVRACYDYDQGDWMR6LZCOOTNF5","short_pith_number":"pith:VWVRACYD","schema_version":"1.0","canonical_sha256":"adab100b03c0e061d991f2f2273a6d2f7cae5da3c5d8629a7347926f64d24095","source":{"kind":"arxiv","id":"2606.03024","version":1},"attestation_state":"computed","paper":{"title":"SkillGuard: A Permission Framework for Agent Skills","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Dianshu Liao, Meixue Si, Shidong Pan, Tianyi Zhang, Xiaoyu Sun, Zhenchang Xing","submitted_at":"2026-06-02T02:01:53Z","abstract_excerpt":"Agent skills extend LLM agents with reusable instructions, scripts, tool bindings, and contextual dependencies. However, current skill ecosystems largely rely on trust-based loading and static inspection, leaving a gap between what a skill can inject into an agent's context and what it can cause the agent to do at runtime. This gap introduces new security and privacy risks, and existing defenses primarily inspect skill files statically or regulate individual tool calls, without systematically connecting a skill's declared intent with its runtime behavior. In this paper, we present SkillGuard, "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.03024","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T02:01:53Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"0458b957dc5e6ca8505cd88071c549d2a62164e10434c38bfb62b74ebe00f6f3","abstract_canon_sha256":"c0f8eb7dd6041eafe0703bdabf81a3a038584c6b8e7fab919074d5f03956313e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:29.560552Z","signature_b64":"fbCpjI7v0cDZ7h41nVCalBn5xy7wh31ca37Rj1Ae+vpq3KTh2200nlo8WM1gBZGY1n6KOPWOpWBPGvqsLG+GCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"adab100b03c0e061d991f2f2273a6d2f7cae5da3c5d8629a7347926f64d24095","last_reissued_at":"2026-06-03T01:05:29.560150Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:29.560150Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SkillGuard: A Permission Framework for Agent Skills","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Dianshu Liao, Meixue Si, Shidong Pan, Tianyi Zhang, Xiaoyu Sun, Zhenchang Xing","submitted_at":"2026-06-02T02:01:53Z","abstract_excerpt":"Agent skills extend LLM agents with reusable instructions, scripts, tool bindings, and contextual dependencies. However, current skill ecosystems largely rely on trust-based loading and static inspection, leaving a gap between what a skill can inject into an agent's context and what it can cause the agent to do at runtime. This gap introduces new security and privacy risks, and existing defenses primarily inspect skill files statically or regulate individual tool calls, without systematically connecting a skill's declared intent with its runtime behavior. In this paper, we present SkillGuard, "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.03024","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.03024/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.03024","created_at":"2026-06-03T01:05:29.560202+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.03024v1","created_at":"2026-06-03T01:05:29.560202+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.03024","created_at":"2026-06-03T01:05:29.560202+00:00"},{"alias_kind":"pith_short_12","alias_value":"VWVRACYDYDQG","created_at":"2026-06-03T01:05:29.560202+00:00"},{"alias_kind":"pith_short_16","alias_value":"VWVRACYDYDQGDWMR","created_at":"2026-06-03T01:05:29.560202+00:00"},{"alias_kind":"pith_short_8","alias_value":"VWVRACYD","created_at":"2026-06-03T01:05:29.560202+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5","json":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5.json","graph_json":"https://pith.science/api/pith-number/VWVRACYDYDQGDWMR6LZCOOTNF5/graph.json","events_json":"https://pith.science/api/pith-number/VWVRACYDYDQGDWMR6LZCOOTNF5/events.json","paper":"https://pith.science/paper/VWVRACYD"},"agent_actions":{"view_html":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5","download_json":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5.json","view_paper":"https://pith.science/paper/VWVRACYD","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.03024&json=true","fetch_graph":"https://pith.science/api/pith-number/VWVRACYDYDQGDWMR6LZCOOTNF5/graph.json","fetch_events":"https://pith.science/api/pith-number/VWVRACYDYDQGDWMR6LZCOOTNF5/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5/action/timestamp_anchor","attest_storage":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5/action/storage_attestation","attest_author":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5/action/author_attestation","sign_citation":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5/action/citation_signature","submit_replication":"https://pith.science/pith/VWVRACYDYDQGDWMR6LZCOOTNF5/action/replication_record"}},"created_at":"2026-06-03T01:05:29.560202+00:00","updated_at":"2026-06-03T01:05:29.560202+00:00"}