<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Snyk Research</title><description>Notes from the security research team.</description><link>https://research.snyk.io/</link><item><title>Exploring the Threat Landscape of Agent Skills</title><link>https://research.snyk.io/blog/agent-skills-threat-landscape/</link><guid isPermaLink="true">https://research.snyk.io/blog/agent-skills-threat-landscape/</guid><description>An analysis of 3,984 AI agent skills from major marketplaces uncovered 76 confirmed malicious payloads, with 13.4% of all skills carrying at least one Critical-level security issue and several malicious skills still live at publication.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate><author>Luca Beurer-Kellner, Aleksei Kudrinskii, Marco Milanta, Kristian Bonde Nielsen, Hemang Sarkar, Liran Tal</author></item><item><title>Stealing Reasoning Traces from Proprietary LLM APIs</title><link>https://research.snyk.io/blog/stealing-reasoning-traces/</link><guid isPermaLink="true">https://research.snyk.io/blog/stealing-reasoning-traces/</guid><description>We find that encrypted chain-of-thought blocks are interchangeable across sessions with most LLM providers. This allows attackers to replay a frontier model trace into a weaker, jailbroken sibling which recovers the hidden reasoning verbatim, enabling distillation, large-scale extraction of private data such as secrets and PII from agent logs, safety violations, and invisible prompt injection.</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><author>Alexander Panfilov, David Schmotz, Ilia Shumailov, Luca Beurer-Kellner, Joachim Schaeffer, Ameya Prabhu, Jonas Geiping, Maksym Andriushchenko</author></item></channel></rss>