AI Agent Skills: 50% Are Verbatim Copies With No Registry or Fix Pipeline

Found first: a primary source the press has not covered yet.

Half of all SKILL.md files on GitHub are verbatim copies of another file. Skill Constellations: Tracing the Supply Chain of Agent Skills on GitHub reconstructs 2,193,119 skill adoptions from git history across 259,596 repositories and finds no registry, no versioning, and no provenance system. When a source skill is updated, the fix almost never reaches its copies.

What the source says

Fahd Seddik at the University of British Columbia, Okanagan, submitted the paper on October 8, 2026. The GitSkills dataset covers every SKILL.md committed to GitHub from October 2025 through July 2026, a ten-month window in which the format spread to 259,596 repositories containing 1,612,846 distinct skills. Propagation is weak: only 11.1% of changes to a source skill reach all copies at each observation window, and just 4.0% of copy genealogies ever change consistently. Star counts are a poor filter. Reviewing the 100 most-starred repositories would intercept 0.5% of later high-risk skill adoptions; the authors' influence-based ranking intercepts 14.9%.

Why it matters

SKILL.md files are instructions executed by AI coding agents, and this is the first empirical map of how they propagate. The copy-based, unversioned supply chain means there is no mechanism to push a security fix to downstream adopters. Consistent change propagation occurs in only 4.0% of genealogies, so the default assumption should be that a copy never receives upstream fixes. The gap between star-based and influence-based ranking, 0.5% vs. 14.9%, shows that conventional trust signals do not identify the repositories that actually matter. The paper recommends that platforms distribute versioned references rather than copies.