2607.02345v1 Jul 02, 2026 cs.SE

SkillFuzz: 오픈 스킬 마켓플레이스에서 암묵적인 의도 발견을 위한 스킬 조합 퍼징

SkillFuzz: Fuzzing Skill Composition for Implicit Intents Discovery in Open Skill Marketplaces

Jinwei Hu
Jinwei Hu
Citations: 554
h-index: 10
Yi Dong
Yi Dong
Citations: 226
h-index: 6
Xiaowei Huang
Xiaowei Huang
Citations: 239
h-index: 7
Youcheng Sun
Youcheng Sun
Citations: 25
h-index: 1

최근 대규모 언어 모델(LLM) 기반 에이전트들이 재사용 가능한 스킬과 자연어 지침 문서를 활용하여 소프트웨어 엔지니어링 작업을 자동화하고 있습니다. 오픈 스킬 마켓플레이스는 사용자들이 커뮤니티에서 제공하는 스킬을 조합하여 에이전트를 구축할 수 있도록 하지만, 일반적으로 마켓플레이스 운영자는 개별 스킬만 검토합니다. 그 결과, 개별적으로는 안전한 스킬들이 함께 작동하면서 에이전트가 의도하지 않은 목표를 향하도록 유도할 수 있으며, 이를 우리는 '암묵적인 의도'라고 부릅니다. 이러한 의도를 탐지하는 것은 어렵습니다. 왜냐하면 효과는 스킬 조합을 통해서만 나타나고, 실행 환경은 종종 검증 시점에 사용할 수 없으며, 마켓플레이스의 크기가 커질수록 가능한 스킬 조합의 공간이 기하급수적으로 증가하기 때문입니다. 본 논문에서는 암묵적인 의도 발견 문제를 스킬 조합에 대한 퍼징 문제로 정의합니다. 여기서 스킬 조합은 테스트 단위이며, 계획 산출물은 실행 전에 에이전트의 의도를 드러내고, 스킬을 사용하지 않는 기본 상태와의 차이를 통해 잠재적인 오류를 감지합니다. 이러한 정의를 바탕으로, 우리는 SkillFuzz를 제안합니다. SkillFuzz는 첫 번째 비실행 퍼징 접근 방식으로, 구조화된 스킬 계약을 추출하고, 계약 기반 몬테카를로 트리 탐색을 사용하여 잠재적으로 충돌이 발생할 수 있는 조합의 우선순위를 정합니다. 대표적인 스킬 마켓플레이스 워크로드에서 SkillFuzz는 제한된 예산 내에서 1,000개 이상의 고유한 암묵적인 의도를 발견하고, 실행 시간 검증 과정에서 가장 위험도가 높은 조합 중 80% 이상을 확인하며, 다른 검색 전략보다 훨씬 적은 쌍별 상호 작용 공간을 탐색하면서도 더 많은 심각한 수준의 암묵적인 의도를 식별합니다.

Original Abstract

Large Language Model (LLM)-based agents increasingly automate software engineering tasks through reusable skills, natural-language instruction documents that guide planning and execution. Open skill marketplaces enable users to assemble agents by co-activating community-contributed skills, but marketplace operators typically audit skills in isolation. As a result, individually benign skills may interact to redirect an agent toward unintended objectives, which we term implicit intents. Detecting such intents is challenging because the effect emerges only through skill composition, execution environments are often unavailable at admission time, and the space of possible co-activations grows exponentially with marketplace size. In this paper, we formulate implicit-intent discovery as a fuzzing problem over skill compositions, where skill compositions are the unit under test, planning artifacts expose agent intent before execution, and deviations from a skill-free baseline serve as a differential oracle. Based on this formulation, we propose skillfuzz, the first execution-free testing approach that extracts structured skill contracts and uses contract-guided Monte Carlo Tree Search to prioritize potentially conflicting compositions. Across representative skill-marketplace workloads, skillfuzz discovers over 1,000 distinct implicit intents under a fixed query budget, confirms more than 80% of the highest-risk flagged compositions during execution-time validation, and identifies substantially more high-severity implicit intents than alternative search strategies while exploring only a fraction of the pairwise interaction space they require.

0 Citations
0 Influential
5 Altmetric
25.0 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!