{
  "id": 3634520,
  "title": "EVOMAL: Self-Poisoning in Self-Evolving Coding Agents",
  "url": "https://urgent.news/2026/08/26/evomal-self-poisoning-in-self-evolving-coding-agents",
  "topic": "ai",
  "section": "AI",
  "published": "2026-08-26T13:19:12.000Z",
  "source": {
    "name": "arXiv cs.AI",
    "slug": "arxiv-cs-ai",
    "url": "https://arxiv.org/abs/2608.25776v1"
  },
  "original_language": "en",
  "account": null,
  "summary": "Self-evolving LLM coding agents write their own tools by imitating retrieved skills from shared skill libraries. We identify a vulnerability in this loop: during authoring, a retrieved malicious skill can become the template for a new skill that preserves the payload. We call this self-poisoning: the agent authors, stores, and runs the resulting malicious skill. We exploit it through EvoMal, an…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}