🚀NEW LABGetting Started with Claude AgentsStart lab
← All papers  /  Sep 16, 2026
Agents

After the Party: Governing What a Viral Agent-Skill Ecosystem Left Behind

First page
After the Party: Governing What a Viral Agent-Skill Ecosystem Left Behind
The curator’s take

Yunpeng Xiong and Ting Zhang (Monash University) measure the OpenClaw skill registry after its 2026 boom, using Git history, GitHub issues and three ClawHub snapshots to test which governance signals hold up.

Ask this paper

Key points
01

Growth: Observable listings nearly doubled in 91 days, from 33,399 to 65,175, and 63.25% of June listings were created in March and April; creation then fell sharply by May.

02

Concentration and neglect: The top 10% of skills take 46.93% of downloads, while 77.86% have zero stars and zero comments and 85.06% of readable skills show privilege evidence such as shell or network access.

03

Metadata fails: No simple feature such as size or downloads remains a stable predictor of continued listing once creation cohort and skill age are controlled.

04

Scanners disagree: Three security scanners disagree on 23,702 of the 61,990 skills they all cover, and after human adjudication their weighted sensitivity ranges from 21.67% to 61.06%.

Abstract

AI agents increasingly act through agent skills, i.e., natural-language instructions, that direct a host agent toward shell, network, credential, file, and process actions, and public registries distribute them at scale. In the first half of 2026, the OpenClaw AI agent went viral, and its public skill registry boomed: the observable stock nearly doubled in 91 days, and a majority of the listings visible in June were created in just two months. By the end of our study window, the wave had crested, and monthly listing creation and core-repository activity were falling from their spring peaks. This paper measures what the boom left behind, drawing on the OpenClaw Git history, its GitHub issues and pull requests, and three ClawHub registry snapshots. Attention is concentrated: the top 10% of skills received 46.93% of all downloads. No simple skill features (like size or download counts) remained a stable predictor of continued listing once creation cohort and skill age were controlled. Human scrutiny did not stay: 77.86% have zero stars and zero comments, while 85.06% of the readable skills carry privilege evidence. And automated cleanup is not ready: the three security scanners disagreed on 23,702 of the 61,990 skills they all cover. After human adjudication, weighted scanner sensitivity against the reference standard ranged from 21.67% to 61.06%. Governing fast-growing agent-skill registries cannot rely on simple metadata or single scanner scores; it requires robust, transparent measurement and independent validation.

Every Monday
Get next week’s papers.
Subscribe on Substack