# New research attacks two soft spots in the agent stack: skills and gated memory

SkillAtlas argues skill risk shows up only in execution traces, while BadEngram plants a backdoor in the gated parametric memories that open-weight models use to add capacity cheaply.

- Published: 2026-09-15T06:27:29.669Z
- Canonical: https://polylog.news/ai/2026-09-15/new-research-attacks-two-soft-spots-in-the-agent-stack-skill
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [arXiv (SkillAtlas)](https://arxiv.org/abs/2609.13353), [arXiv (BadEngram)](https://arxiv.org/abs/2609.13478), [Anthropic Frontier Red Team](https://www.anthropic.com/research/team/frontier-red-team)

Two papers posted to arXiv on Tuesday target layers of the agent stack that most security tooling does not inspect. SkillAtlas addresses agent skills, the reusable units that language-model agents load at runtime. Its argument is that skill…

This story is for subscribers. Read it in full at https://polylog.news/ai/2026-09-15/new-research-attacks-two-soft-spots-in-the-agent-stack-skill (subscription information: https://polylog.news/pricing).