Modern AI coding agents such as Claude Code, Codex, and terminal assistants routinely execute agent skills—instructions and executable scripts bundled in SKILL.md specifications—with full local user privileges. Developers share these skills primarily by copying files across repositories, inadvertently forging a shadow software supply chain without centralized registries, semver tagging, or provenance tracking. A seminal empirical audit by Fahd Seddik (arXiv:2610.11169) introduces Skill Constellations, constructing the first dated copy network of agent skills derived from git provenance across 2,193,119 skill adoptions on GitHub. The investigation demonstrates that a minuscule set of root repositories generates nearly all downstream copies, yet GitHub star counts correlate poorly with true lineage sources. Critically, downstream copies almost never adopt upstream security patches. By fitting a predictive copy network model, auditing just the top 100 identified root repositories halts 14.9% of subsequent high-risk skill adoptions (compared to a negligible 0.5% when inspecting the top 100 starred repos), proving the urgent necessity for decentralized package ecosystems to adopt versioned references over loose copies.
Key Takeaways
- ✓Skill Constellations delivers the first dated supply chain network of 2.19M agent skill adoptions across GitHub repositories
- ✓Reveals that a tiny cluster of progenitor repositories drives global adoption without correlating with GitHub star metrics
- ✓Auditing the top 100 root repositories prevents 14.9% of subsequent high-risk skill adoptions, outperforming star-based audits by 30x
Heavy Claude Code use: compare subscription limits and API bills
Compare 40 dev plans & simulate token costs vs $20/mo subscriptions
Project Links & Resources
Direct AccessIn-Depth Technical Analysis
Background and the Problem
AI coding agents such as Claude Code, Cursor, and terminal copilots execute agent skills—curated prompt templates, configuration instructions, and shell scripts bundled in SKILL.md specifications—with ambient developer operating system permissions. Unlike mature package ecosystems (e.g. npm, Cargo), agent skills lack package registries, cryptographic checksums, and semantic versioning. Developers distribute skills by copying raw markdown and scripts between GitHub repositories. This primitive distribution model creates an opaque shadow supply chain where source provenance, vulnerability propagation, and malicious payloads remain entirely untracked.
Architecture and How It Works
Security researcher Fahd Seddik introduces Skill Constellations (arXiv:2610.11169), presenting the first empirical audit of the GitHub agent skill ecosystem:
- Dated Copy Network Architecture: Reconstructs the git history of every
SKILL.mdartifact tracked in GitSkills, mapping temporal dependencies across 2,193,119 real-world skill adoption events on GitHub. - Root Source Dominance vs. Star Misalignment: Discovers that a minuscule fraction of root repositories serves as the progenitor for the vast majority of distributed skills, and that repository stars fail to correlate with structural adoption influence.
- Broken Patch Propagation: Downstream skill copies remain static post-fork; upstream security patches and bug fixes almost never propagate to cloned instances across GitHub.
- Copy Network Topology Ranking: Formulates a predictive graph model ranking repositories by downstream propagation influence, generating an actionable security audit roster for enterprise defense.
Benchmarks and Measured Results
Evaluated against the complete historical record of 2.19M GitHub skill adoptions:
- Top 100 Root Audits Halt 14.9% of High-Risk Adoptions: Proactively vetting the 100 highest-ranked progenitor repositories prevents 14.9% of subsequent high-risk skill adoptions.
- Inefficacy of Star-Based Vetting (0.5%): Auditing the 100 most-starred skill repositories prevents a mere 0.5% of high-risk downstream adoptions, demonstrating a 30x effectiveness gap.
- Interactive Viewer & Dataset: Releases an open dataset and interactive graph viewer mapping the supply chain constellations across all 2.19 million tracked adoptions.
Getting Started for Developers
Skill Constellations establishes that copy-paste skill management represents an acute security hazard for enterprise engineering teams. Developers using Claude Code, Codex, or terminal agent harnesses must stop manually copying unvetted SKILL.md bundles into active workspaces. Platform teams should implement internal versioned registries with cryptographic verification, enforcing immutable git commit hashes to replace unmanaged file duplication.
Benchmark side-by-side against alternatives, or calculate monthly token cost vs subscription break-even.
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.