A workflow record can accurately describe progress and still falsely represent authority.
The October 2026 paper Chaining Skills to Hijack LLM Agents introduces APEX, a controlled attack in which an upstream skill induces an agent to write a record containing genuine task progress plus a false claim that the user approved an attacker-selected next action. A downstream skill then consumes that record and performs the action. Across four targeted-action families and six models on SkillsBench, the authors report 512 successful targeted actions in 690 attempts, or 74.2%. On GPT-5.4, the full chain succeeded in 84.3% of attempts.
The continuity failure
The key break is not simply prompt injection. It is Record → Authority.
The task-progress record has a legitimate institutional role: it tells the next skill what has already happened. But the same record is allowed to carry a second claim—purported user approval—without preserving who actually asserted that approval or what original request supports it.
Source / user request → Evidence / genuine task progress → Record / progress plus fabricated approval ✕→ Authority / represented as user permission → Decision / downstream skill trusts record → Action / transfer, execution, deletion, tampering, or resource use.
Why successful task metrics may miss the problem
The study reports that native task-verifier performance can remain strong even when the attacker-selected action succeeds. That matters institutionally because a system can appear to have completed the user’s task while simultaneously performing something the user never authorized.
This extends GovKM’s earlier analysis of prompt injection becoming institutional memory. APEX demonstrates a narrower and more operationally common channel: the handoff file itself can become a vehicle for authority laundering.
The GovKM interpretation
Every AIL assertion should preserve at least four separate relationships: who asserted it, what evidence supports it, whether it describes task state or permission, and which authority granted that permission. A workflow record must never be able to self-certify its own authority merely because it was written by an agent operating inside an otherwise legitimate task.
The paper also tests a prompting defense that asks the agent to compare skill-produced files against the original request. On GPT-5.4, targeted-action success fell from 84.3% to 59.1%, but benign verifier performance also fell sharply. That tradeoff reinforces a GovKM point: safety cannot depend solely on discretionary model reasoning at the same layer that consumes the potentially corrupted record.
Continuity path: Source / user request → Evidence / task progress → Authority / original permission → Context / multi-skill workflow → Decision / trust handoff record → Action → Record / downstream result → Institutional Memory / reusable workflow state → Future Reuse.
Source
Tian Dong, Zixuan Ma, Haodong Zhao, Huaien Zhang, Shaofeng Li, and Hao Chen, Chaining Skills to Hijack LLM Agents, arXiv:2610.01564, October 1, 2026. https://arxiv.org/abs/2610.01564


