Cross-Platform Reuse Vulnerability in Agentic Coding
Description
The same skill often runs on more than one platform. A bundle written for one assistant often gets shared between colleagues, posted in a code repository, or otherwise copied with little or no change onto another platform that reads a similar SKILL.md format but enforces a different permission model around it.
Cross-Platform Reuse is the risk that this move loses security properties nobody was tracking. A signature, a scoped permission set, or a reviewed capability list that meant something on the platform it was approved for can be dropped silently by the porting process, or simply not understood by the platform it lands on. The skill looks the same. What each platform is willing to let it do is not.
Impact
A skill reused this way can end up with more capability than it was ever reviewed for, because the review happened against one platform’s rules and the skill now runs under another’s. Metadata that encoded a restriction, such as a declared permission or a signed attestation, can be silently lost or ignored in the process, so the receiving platform has no way to tell that the skill was ever meant to be constrained at all.
This also gives a malicious skill a way to spread. A bundle rejected or flagged on one registry can be republished on another with no shared vetting between them, and each platform sees it as new.
Scenarios
A skill approved for one assistant platform, with permissions scoped to read a single project directory, is copied to a second platform to save the effort of writing it twice. The second platform has no equivalent permission field, so it simply grants the skill whatever default access it gives every skill. The scoping that made the original approval safe never made the trip.
Prevention
If you install and use skills, treat a skill copied from another platform as a new submission. Re-review what it can do on the platform where you are installing it, since a permission or restriction that applied elsewhere may not apply here.
If you build or maintain a skill platform, the responsibility is to make security properties portable rather than assume they carry over.
- Adopt a shared metadata format: Support a common way to declare permissions, signatures, and provenance, so a skill’s security properties are readable the same way everywhere, not reinterpreted per platform.
- Verify on import: Check a reused skill’s signature and declared permissions again at the point it enters your platform, and refuse anything that cannot be verified rather than trusting that another platform already did.