SigLeak Framework Extracts Proprietary Agent Skills from Execution Trajectories
Researchers have introduced SigLeak, a black-box framework that can reconstruct proprietary agent skills by analyzing execution trajectories. The framework exploits a behavioral side channel created when agents execute skills, even when the underlying code is hidden. SigLeak constructs diagnostic tasks, contrasts skill-enabled and skill-disabled trajectories, and iteratively refines reconstructed skills. The approach was validated across five scenarios, three model families, and three agent architectures. This work highlights a vulnerability in current agent deployment practices where proprietary skills can be leaked through observable behavior, posing risks to marketplace monetization and private deployment.
Key facts
- SigLeak is a black-box framework for reconstructing proprietary agent skills.
- It exploits recurring skill signatures in agent behavior.
- The framework constructs decision-rich diagnostic tasks.
- It contrasts matched skill-enabled and skill-disabled trajectories.
- The method iteratively refines a reconstructed skill from isolated patterns.
- Validation was done across five scenarios, three model families, and three agent architectures.
- The work is published on arXiv with ID 2607.25560.
- Skill Leakage is defined as reconstructing proprietary skills from trajectories without reference answers or success labels.
Entities
Institutions
- arXiv