PAPER / ARXIV:2609.17274
Xiong, Y.; Zhang, T.
RESUMO
AI agents increasingly act through agent skills, i.e., natural-language instructions, that direct a host agent toward shell, network, credential, file, and process actions, and public registries distribute them at scale. In the first half of 2026, OpenClaw went viral, its public skill registry boomed: the observable stock nearly doubled in 91 days, and majority of listings visible in June were created just two months prior. By the end of our study window, the wave had crested, and monthly listing creation in core-repository activity was falling from their spring peaks. This paper measures what the boom left behind, drawing on Git history, GitHub issues and pull requests, and three ClawHub registry snapshots. Attention is concentrated: the top 10% of skills received 46.93% of all downloads. No simple skill features remained a stable predictor of continued listing creation once cohort age were controlled. Human scrutiny did not stay: 77.86% have zero stars and comments, while 85.06% of readable skills carry privilege evidence. And automated cleanup is not ready: three security scanners disagreed on 23,702 of 61,990 skills they all cover. After human adjudication, weighted scanner sensitivity against the reference standard ranged from 21.67% to 61.06%. Governing fast-growing agent-skill registries cannot rely on metadata or single scanner scores; it requires robust, transparent measurement and independent validation.
NO MESMO MAPA