Security Agent Skills Have a Shadow Supply Chain: 2.19 Million GitHub Copies and Security Fixes That Almost Never Propagate Coding Assistants Microsoft Ships an AX Practitioner Playbook: Nine Failure Patterns and 46 Shipped Fixes for How Coding Agents Use Your SDK News DatologyAI Opens Its Data Curation Engine to Everyone, Betting a 12B Model Beats a 30B Baseline on One-Fifth the Compute AI Agents Memento 3 Clears Every Public ARC-AGI-3 Game Using Only 44% of the Human Action Count, With a Frozen LLM News Intel Wants a Piece of the Custom AI Chip Boom, and Its New Secret Weapon Is Marvell's Ex-Sales Chief News Autonomous Trucks Are Now Hauling Freight to America's Busiest Land Border. A Human Is Still in the Cab. Business GlobalFoundries Will Make TSMC's AI Chip Interposers in New York Under a $2 Billion, Five-Year Deal Productivity 90% of UK Lawyers Now Use AI, and the Billable Hour Is Starting to Crack Security Agent Skills Have a Shadow Supply Chain: 2.19 Million GitHub Copies and Security Fixes That Almost Never Propagate Coding Assistants Microsoft Ships an AX Practitioner Playbook: Nine Failure Patterns and 46 Shipped Fixes for How Coding Agents Use Your SDK News DatologyAI Opens Its Data Curation Engine to Everyone, Betting a 12B Model Beats a 30B Baseline on One-Fifth the Compute AI Agents Memento 3 Clears Every Public ARC-AGI-3 Game Using Only 44% of the Human Action Count, With a Frozen LLM News Intel Wants a Piece of the Custom AI Chip Boom, and Its New Secret Weapon Is Marvell's Ex-Sales Chief News Autonomous Trucks Are Now Hauling Freight to America's Busiest Land Border. A Human Is Still in the Cab. Business GlobalFoundries Will Make TSMC's AI Chip Interposers in New York Under a $2 Billion, Five-Year Deal Productivity 90% of UK Lawyers Now Use AI, and the Billable Hour Is Starting to Crack

Agent Skills Have a Shadow Supply Chain: 2.19 Million GitHub Copies and Security Fixes That Almost Never Propagate

Agent Skills Have a Shadow Supply Chain: 2.19 Million GitHub Copies and Security Fixes That Almost Never Propagate

A single-author study built the first dated copy network of agent skills from GitHub history, covering 2,193,119 adoptions of SKILL.md files — bundles that agents like Claude Code and Codex run with full user permissions. A few root repositories generate nearly all copies, stars fail to identify them, and downstream copies rarely absorb security fixes: auditing the 100 top-ranked repos would have blocked 14.9% of high-risk skill adoptions, vs 0.5% for the 100 most starred.

The fastest-spreading artifact in the AI coding world is also its least governed. Agent skills — SKILL.md files bundling instructions and scripts that agents such as Claude Code and Codex execute with the full permissions of their user — spread between repositories by plain file copying, with no registry, no versioning and no provenance. A study posted to arXiv on October 8 (2610.11169) by author Fahd Seddik maps what that means in practice, and the picture is of a software supply chain that nobody is minding.

Previous studies recorded which repositories contain which skills at a single point in time, which cannot answer the question that matters for security: who copied this from whom, and if a vulnerability is fixed upstream, which downstream copies are still exposed? The paper's contribution is the first dated copy network, reconstructed from the git history of every SKILL.md in the GitSkills corpus and covering 2,193,119 skill adoptions across GitHub, released with an interactive viewer for exploring the lineage.

Two structural findings stand out. First, the network is extraordinarily top-heavy: a tiny set of root repositories generates nearly all downstream copies — a constellation of derivations from a few stars, hence the title. Second, GitHub star counts, the ecosystem's default popularity signal, are a poor proxy for true lineage; auditing the 100 most-starred repositories would barely dent the risk.

The propagation failure is the sharpest finding. Skill copies almost never change when their source changes, so a security fix applied at the origin rarely reaches the repositories that copied the file. In a conventional package ecosystem, a patched version and a lockfile update carry the fix outward; in the copy economy, every downstream copy silently freezes at whatever state it was in when it was duplicated — including known-vulnerable scripts that grant agents shell access.

To make the map actionable, the author fit a model of which repositories others tend to copy from and used it to rank repositories for audit. The result is a 30-fold improvement over star-based triage: reviewing the 100 repositories the model ranks highest would have prevented 14.9% of subsequent adoptions of high-risk skills, against 0.5% for the 100 most starred. For security engineers wondering where to start with a corpus of millions, that is the difference between a workable short list and noise.

The paper's recommendation follows directly: platforms should distribute versioned references rather than loose copies, bringing skills into the same provenance discipline that npm, PyPI and container registries eventually adopted. Until then, the audit-ranking approach offers a pragmatic stopgap for platform teams and security researchers.

Context makes the timing pointed. Agent skills have moved from an Anthropic-originated convention to a broad ecosystem convention in barely a year, and they run with the user's own privileges — meaning a malicious or stale skill is not a sandboxed inconvenience but executable code in a developer's environment. The study is single-authored and not yet peer reviewed, and its corpus is drawn from public GitHub history, so private skill sharing is out of scope. But as a first census of how this supply chain actually behaves, it documents a gap between how fast skills spread and how slowly safety practice has caught up — and gives the defenders a prioritized map for closing it.

Comments (0)

Log in to join the discussion

Log In

No comments yet