Finally, a paper testing whether hiding your agent skill files actually protects them.
The short answer is no. That's concerning.
Worth reading if you sell access to a skill or share one across teams.
This new paper discusses more:
Daydreaming reconstructs a hosted multi-file skill using only the ordinary tasks the service exists to perform. The victim is never asked to reveal the skill or grade a reconstruction, so disclosure filters have nothing to catch.
At the weakest access level, where the attacker sees only the final response and returned files, it recovers 86.8 percent of the original skill's capability across 7 skills and 4 victim models.
That is roughly 4x SigLeak, at a median of 32 victim calls per skill, with disclosure defenses enabled.
Paper:
Chat with Paper: