2.2 Million Agent Skills Have Been Copied Across GitHub. A Fix at the Source Almost Never Reaches the Copies.
Agent skills, the SKILL.md files that Claude Code and Codex load, have quietly become a software supply chain, and until this week nobody had measured it. A paper submitted October 8, "Skill Constellations: Tracing the Supply Chain of Agent Skills on GitHub," reconstructs the first dated copy network of these files from the git history of every SKILL.md in a large corpus. The headline number: 2,193,119 skill adoptions. The uncomfortable findings underneath it are what make this matter.
Three things fall out of the data. First, a handful of repositories are the source of almost all copies, and GitHub stars do not identify them, so the most-copied skills are not the most-starred and you cannot find the real roots by popularity. Second, copies almost never change after they are made. A skill gets duplicated into a new repo and then frozen, which means a fix at the source rarely propagates to the copies downstream. The ecosystem looks like a living network and behaves like a field of fossils. Third, provenance is invisible: there is no registry, no versioning, no reference back to where a skill came from, so a vulnerable or malicious instruction can spread and sit in thousands of repos with no way to recall it.
The authors then show their map is useful, not just descriptive. Reviewing the 100 repositories their model ranks highest prevents 14.9 percent of later adoptions of high-risk skills. Reviewing the 100 most-starred repositories prevents 0.5 percent. Thirty times the yield from the same amount of human review, purely by looking at the copy graph instead of the popularity signal. Their recommendation is the obvious structural one: platforms should distribute versioned references to skills, not frozen copies, so that provenance and fixes can flow.
This lands straight into the skills-standard thread this site has tracked for months. Every week brings another skills paper, SkillForge and its lifecycle of trial-to-retired skills, EVISKILL and its replayable evidence cards, the retrieval work showing most retrieved skills give no useful signal. All of them assume skills are managed objects with versions and provenance. This paper is the empirical rebuttal: in the wild, skills are copy-pasted text with no version, no source link, and no way to patch, and 2.2 million of them are already out there. The gap between how the research treats skills and how GitHub actually stores them is exactly where the next supply-chain incident lives.
Paper: https://arxiv.org/abs/2610.11169
Project: https://fahdseddik.github.io/Skill-Constellations/
← Back to all articles
Three things fall out of the data. First, a handful of repositories are the source of almost all copies, and GitHub stars do not identify them, so the most-copied skills are not the most-starred and you cannot find the real roots by popularity. Second, copies almost never change after they are made. A skill gets duplicated into a new repo and then frozen, which means a fix at the source rarely propagates to the copies downstream. The ecosystem looks like a living network and behaves like a field of fossils. Third, provenance is invisible: there is no registry, no versioning, no reference back to where a skill came from, so a vulnerable or malicious instruction can spread and sit in thousands of repos with no way to recall it.
The authors then show their map is useful, not just descriptive. Reviewing the 100 repositories their model ranks highest prevents 14.9 percent of later adoptions of high-risk skills. Reviewing the 100 most-starred repositories prevents 0.5 percent. Thirty times the yield from the same amount of human review, purely by looking at the copy graph instead of the popularity signal. Their recommendation is the obvious structural one: platforms should distribute versioned references to skills, not frozen copies, so that provenance and fixes can flow.
This lands straight into the skills-standard thread this site has tracked for months. Every week brings another skills paper, SkillForge and its lifecycle of trial-to-retired skills, EVISKILL and its replayable evidence cards, the retrieval work showing most retrieved skills give no useful signal. All of them assume skills are managed objects with versions and provenance. This paper is the empirical rebuttal: in the wild, skills are copy-pasted text with no version, no source link, and no way to patch, and 2.2 million of them are already out there. The gap between how the research treats skills and how GitHub actually stores them is exactly where the next supply-chain incident lives.
Paper: https://arxiv.org/abs/2610.11169
Project: https://fahdseddik.github.io/Skill-Constellations/
Comments