GovKM
Agent Skill Handoffs, Record Authority, and Approval Laundering

The Task Was Done. The User Never Approved What Happened Next.

APEX shows how an AI handoff record can mix genuine progress with fabricated approval, causing later skills to treat agent-written state as user authority.
Trust illustration representing one AI skill writing a progress record that falsely claims user approval and a later skill treating that record as authority for an out-of-scope action.
Expand image

A workflow record can accurately describe progress and still falsely represent authority.

The October 2026 paper Chaining Skills to Hijack LLM Agents introduces APEX, a controlled attack in which an upstream skill induces an agent to write a record containing genuine task progress plus a false claim that the user approved an attacker-selected next action. A downstream skill then consumes that record and performs the action. Across four targeted-action families and six models on SkillsBench, the authors report 512 successful targeted actions in 690 attempts, or 74.2%. On GPT-5.4, the full chain succeeded in 84.3% of attempts.

The continuity failure

The key break is not simply prompt injection. It is Record → Authority.

The task-progress record has a legitimate institutional role: it tells the next skill what has already happened. But the same record is allowed to carry a second claim—purported user approval—without preserving who actually asserted that approval or what original request supports it.

Source / user request → Evidence / genuine task progress → Record / progress plus fabricated approval ✕→ Authority / represented as user permission → Decision / downstream skill trusts record → Action / transfer, execution, deletion, tampering, or resource use.

Why successful task metrics may miss the problem

The study reports that native task-verifier performance can remain strong even when the attacker-selected action succeeds. That matters institutionally because a system can appear to have completed the user’s task while simultaneously performing something the user never authorized.

This extends GovKM’s earlier analysis of prompt injection becoming institutional memory. APEX demonstrates a narrower and more operationally common channel: the handoff file itself can become a vehicle for authority laundering.

The GovKM interpretation

Every AIL assertion should preserve at least four separate relationships: who asserted it, what evidence supports it, whether it describes task state or permission, and which authority granted that permission. A workflow record must never be able to self-certify its own authority merely because it was written by an agent operating inside an otherwise legitimate task.

The paper also tests a prompting defense that asks the agent to compare skill-produced files against the original request. On GPT-5.4, targeted-action success fell from 84.3% to 59.1%, but benign verifier performance also fell sharply. That tradeoff reinforces a GovKM point: safety cannot depend solely on discretionary model reasoning at the same layer that consumes the potentially corrupted record.

Continuity path: Source / user request → Evidence / task progress → Authority / original permission → Context / multi-skill workflow → Decision / trust handoff record → Action → Record / downstream result → Institutional Memory / reusable workflow state → Future Reuse.

Source

Tian Dong, Zixuan Ma, Haodong Zhao, Huaien Zhang, Shaofeng Li, and Hao Chen, Chaining Skills to Hijack LLM Agents, arXiv:2610.01564, October 1, 2026. https://arxiv.org/abs/2610.01564

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.