Multi-Skill Chain Attack - ATR-2026-00063 (6375ab6a-ef7b-5475-b96e-a60d34e82af4)
Detects attack sequences where multiple MCP skills are chained together to achieve a malicious outcome that no single skill could accomplish alone. For example: (1) a reconnaissance skill reads sensitive files, (2) an encoding skill obfuscates the data, (3) a network skill exfiltrates it. Each step appears benign individually but the chain constitutes data exfiltration.