The paper defines Agent Skill Supply Chains (ASSCs) and SkillDepAnalyzer to extract and analyze dependency graphs from over 1.43 million LLM agent skills, revealing structural patterns and security signals.
An empirical comparison of dependency network evolution in seven software packaging ecosystems
5 Pith papers cite this work. Polarity classification is still indexing.
fields
cs.SE 5years
2026 5representative citing papers
Pre-trained models are added late in projects, accumulate rather than get replaced, and change three times less often than libraries, with distinct documentation driven by capability needs and testing uncertainty.
AI agent skills are reused mainly as one-time near-verbatim copies; half stay unmodified, later maintenance is additive and local, and the behavioural contract stays almost untouched.
A cross-level risk formula combining method-level code metrics with ecosystem fan-in identifies 'hidden amplifier' micro-dependencies invisible to current SCA tools.
CCCE uses a dynamic knowledge graph for impact and test analysis plus multi-stage AI gating to autonomously maintain enterprise codebases and reduce remediation time.
citing papers explorer
-
Skills Are Not Islands: Measuring Dependency and Risk in Agent Skill Supply Chains
The paper defines Agent Skill Supply Chains (ASSCs) and SkillDepAnalyzer to extract and analyze dependency graphs from over 1.43 million LLM agent skills, revealing structural patterns and security signals.
-
When AI Models Become Dependencies: Studying the Evolution of Pre-Trained Model Reuse in Downstream Software Systems
Pre-trained models are added late in projects, accumulate rather than get replaced, and change three times less often than libraries, with distinct documentation driven by capability needs and testing uncertainty.
-
From Registry to Repository: How AI Agent Skills Are Written, Adapted, and Maintained
AI agent skills are reused mainly as one-time near-verbatim copies; half stay unmodified, later maintenance is additive and local, and the behavioural contract stays almost untouched.
-
Hidden Amplifiers: Cross-Level Risk in Software Supply Chains
A cross-level risk formula combining method-level code metrics with ecosystem fan-in identifies 'hidden amplifier' micro-dependencies invisible to current SCA tools.
-
CCCE: A Continuous Code Calibration Engine for Autonomous Enterprise Codebase Maintenance via Knowledge Graph Traversal and Adaptive Decision Gating
CCCE uses a dynamic knowledge graph for impact and test analysis plus multi-stage AI gating to autonomously maintain enterprise codebases and reduce remediation time.