The study constructs the first temporally resolved copy network of agent skills by mining the Git history of every *.skill* file in the GitSkills dataset, capturing 2,193,119 individual skill adoptions across GitHub. This dated network, accompanied by an interactive viewer, reveals that a small subset of repositories supplies the vast majority of skill copies, while GitHub star counts fail to pinpoint these influential sources. Because copied skills are rarely modified after adoption, security patches applied at the origin repository seldom propagate to downstream forks. To address this, the authors train a predictive model that estimates the likelihood a repository will be copied from, then rank repositories accordingly for auditing. Evaluating the model shows that reviewing the top 100 ranked repositories blocks 14.9 % of subsequent adoptions of high‑risk skills, whereas inspecting the top 100 most‑starred repositories averts only 0.5 %. The findings imply that platforms should replace indiscriminate skill copying with versioned, reference‑based distribution to improve supply‑chain visibility and enable timely mitigation of vulnerabilities.
Read original
huggingface/daily-papers