Top of page

AI agents are all the rage—but research shows they leak private data

Wake Forest professor uncovers significant security issues with large language models

Listen to this article · 6:40 min
Voice is AI-generated and may occasionally mispronounce words.

Before you prompt AI to answer another question or perform another task, a Wake Forest computer scientist wants you to know it could expose your sensitive data.

Ying Zhang, an assistant professor in Wake Forest University’s Department of Computer Science, studies security in software engineering. Her latest research, “How Your Credentials Are Leaked by LLM Agent Skills,” explores how large language model (LLM) agents make data vulnerable to attacks.

Ying Zhang

The exposure happens through the use of third-party AI agent skills. The tasks the skills perform could be anything from creating a presentation using your notes to scanning financial documents for compliance issues.

And, while credential leakage can happen either unintentionally or maliciously, the end result is the same—unauthorized access to private data, Zhang said.

When the agent skill is flawed or developed with malicious intent, it will steal your data and maybe pass it back to a remote server to be used in some malicious way.

Ying Zhang, Computer Science Department

Zhang, a corresponding author on the study, will present her research at the International Conference on Automated Software Engineering, Oct. 12-16 in Munich.

Undergraduate research

In additional new research from the Zhang lab, student Eric Gao finds security weaknesses in iOS apps that expand their LLM capabilities.

How do data leaks happen with AI agents?

According to Zhang’s research, these leaks happen in two ways:

“A lot of skills have credential leakage problems, and there are also malicious skills being developed and distributed,” Zhang said. “Through our work, we are helping detect these skills and remove them from the open-source market.” 

How pervasive is this problem?

The research team behind this study used 17,022 randomly selected skills to create 170,226 outputs. They used skills available on SkillsMP, the largest open-source AI agent skill marketplace. It provides access to more than 1.6 million skills.

The researchers found:

Moreover, 89.6% of leaked credentials were immediately exploitable.

When the researchers alerted SkillsMP to the problem, all malicious skills were removed, and most of the vulnerabilities created by negligent coding were fixed.

Why does it matter?

Zhang said the findings point to two problems in software development and AI: 

“When I train my students, I teach them that security is a critical component in their software design,” she said. “Every feature they develop, they have to keep security in mind.”

The rapid evolution of AI and the rise of AI-assisted software development called vibe coding makes securing people’s data even more important, she said. In this new era of software engineering, amateur developers don’t understand software security. And inexperienced developers can’t rely on AI to address security, either. 

What can stop the leaks?

More than anything, Zhang wants to see security intuitively integrated from the initial software design stage—not just after a breach. 

AI creates new security issues that developers and researchers must address, she said. Researchers need to devise a standard for data safety that AI developers must meet. Developers need a tool that analyzes AI agent skills for safety issues. And users could use assurances, in the form of a regulation or contract, that the apps they download are safe.


Categories: Research & Discovery

Share

Media Contact

Alicia Roberts

336.758.5237