@skills: Attention is all you have

arXiv:2608.12610 · cs.AI · Submitted 2026-08-12 · Read on arXiv

Li Yin, Zhi Li, Zhan Shi, Haoran Zhang, Haebin Seong, Zhangyang, Wang

SylphAI · The University of Texas at Austin

cs.AI

Submitted: 2026-08-12

Updated: 2026-08-14

Comments: 7 pages main, 23 pages in total with appendix, 6 figures

Code: https://github.com/SylphAI-Inc/atskills

License: http://creativecommons.org/licenses/by/4.0/

Importance score: 75/100

The gist: The paper identifies a fundamental mismatch in the agent skills ecosystem: 56,804 indexed skills compete for fewer than 100 reliable auto-trigger slots per agent.

Terminology

Summary

The paper identifies a fundamental mismatch in the agent skills ecosystem: 56,804 indexed skills compete for fewer than 100 reliable auto-trigger slots per agent. The dominant delivery mechanism—installation—bundles three separable functions (content, persistence, and auto-triggering), and only the last actually needs prompt residency. The paper states: Installation is what an agent skill's description buys with permanent space in the prompt, and the only thing it buys is auto-triggering—firing without being asked.

Level 1 — The cap is real. Three mechanical properties of resident context bound what it can carry:

  • Distance decay: a resident description sits at a fixed place, the top of the context, while every turn, file read, and tool result lands between it and the current request; adherence to the system message measurably decays over turns

  • The standing tax: each installed description is paid on every message, relevant or not—50–280 tokens per skill in our measurements—and input length alone degrades reasoning well below the nominal context limit

  • Dilution: each added description competes with the rest, and instruction-following degrades systematically as concurrent instructions accumulate

Level 2 — The adaptations make it worse. Authors write bids instead of descriptions (Stripe's flagship skill carries roughly 150 words of trigger conditions, costing 20× more tokens than quiet descriptions); users install less than they could because trying something out costs full permanence; installed skills get forgotten because they're hidden in per-agent directories; and teams defect entirely to monolithic AGENTS.md files.

Level 3 — The damage outlasts the budget. Even if slots were free, three failures remain: everything lands in one flat bin with no hierarchy for important skills; no shared vocabulary exists across agents (a plugin contains skills in one agent, sits beside them as a sibling in another, and is one of seven peer extension types in a third); and none of the machinery serves private team work.

The protocol separates content, persistence, and triggering into three tiers:

Tier 1 — Reference: @skills: fetches a skill at the moment of use, injecting its full body at the end of the context next to the task, which is where attention is highest. Triggering is explicit and deterministic, standing cost is zero, and the skill evaporates with the session. This serves the entire long tail.

Tier 2 — Saved: :save vendors a copy at the ID's own path into the project's git-tracked .atskills/ directory. Crucially, nothing enters the prompt. The agent indexes.atskills/ for @ autocomplete and search, so saved skills surface the moment the user types, but that index lives in the tooling, outside the model's context. This is per-project, arrives with git clone, works offline, and is where a team's working set belongs.

Tier 3 — Installed: :install adds one line to .autotrigger, a .gitignore-style file. What a line costs is the skill's frontmatter alone, some 50–100 tokens held from session start, the body loading only when the skill fires. This is reserved for the few essentials that must fire unprompted—formatter conventions, security guardrails.

  • A path is the identity: The path is the identity, and the two suffixes are orthogonal and combinable. A directory is a menu—a 'bundle' is just a directory and all-or-nothing delivery does not exist.

  • No manifest, lockfile, or registration: a file tree needs none, and SKILL.md is unchanged.

  • Local-first resolution: a saved copy sits at its ID's own path and therefore answers its own address, which is vendoring as in Go's vendor/ directory.

  • Validating cache: behaves like a browser—every use asks the source whether anything changed, in a single revision probe rather than a re-download, so that unchanged serves instantly, changed fetches fresh, and offline serves the cached copy marked stale.

  • Two ownership states: A skill is theirs when one @ line follows the provider's copy without holding one locally... It becomes yours when:save copies it to its ID's own path and detaches it at that moment. The muddy third state (installed-but-stale) is designed out, not managed.

  • No update lifecycle: frozen text against a moving service offers only the appearance of safety. Save-again is the only refresh, conflict-safe by construction.

  • Composition: Several references load in one message... co-firing N skills is deterministic, whereas under installation it is a lottery in which N descriptions must each win a probabilistic match at once.

The protocol pairs with a free hub (atskills.one) "confined to the jobs paths cannot do: search and ranking across the whole public corpus, hosting for skills that have no repository, private and team collections, and one-screen authoring for the non-developers whose procedural knowledge skills capture best. The hub is a service and never a requirement—gh: and local paths resolve with no hub involvement, and GitHub-hosted skills keep their gh: identity even when the hub indexes them."

The protocol asks nothing of the agent or its vendor. SKILLS.md, a single instruction file, turns any agent that can read files, run shell commands, and fetch URLs into a full client. Native @ integration is small because it reuses the @ context system every modern agent already has—the host needs no protocol logic at all: the client computes the resident prompt block and the host splices in one string.

The paper's July 2026 crawl found: 56,804 SKILL.md directories across 1,133 public repositories; 21 major-provider organizations publishing 958 first-party skills; 79% of provider product skills mention their own CLI/API tooling; the median skill body is 921 words (1.2k–3.7k tokens); 54 distinct project-level skills directories across 75 agents; and the top fifteen repositories account for 51% of the corpus.

"The fix is subtraction, not addition... What the protocol mostly does is take things away—the install lifecycle, the update command, version pinning, per-agent directories, and the whole packaging layer above the skill—and what remains is a path, a folder, and a file of one-line decisions. A user learns one character. An agent builder adds one file, or one dependency."

The principle generalizes: resident context is a budget; spend it only on what must fire implicitly, and deliver everything else at the point of use, where attention is highest.

Install less, use more.

Improvements for AI systems

Improvements to AI systems:

  1. Add a context-budget governor to the agent loop. Before each turn, the system computes current resident-context load (system message + installed skill frontmatter + accumulated history) and dynamically demotes low-utility installed skills to on-demand references when load exceeds a threshold. The improved system maintains reasoning quality over long sessions by preventing silent degradation from standing tax and dilution.

  2. Implement path-based skill resolution as a first-class retrieval primitive. The agent gains a @skills: operator that fetches and injects skill bodies at the end of context (near the task) rather than at the top. The improved system executes complex multi-step tasks with higher adherence because instructions sit adjacent to the working state, not buried behind turns of intermediate output.

  3. Replace probabilistic auto-triggering with explicit, deterministic co-firing. When a user references multiple skills in one message, the system loads all their bodies simultaneously and merges them into a single instruction block. The improved system handles composite workflows (e.g., format this file per company style, then run security checks) without the lottery of each skill independently winning a match.

  4. Add a validating cache for skill fetches. The system probes the source with a single revision check per use; unchanged skills serve instantly from cache, changed ones fetch fresh, and offline sessions serve stale copies marked as such. The improved system operates reliably in flaky-network or air-gapped environments while never silently running outdated instructions.

  5. Introduce a two-state ownership model for skill lifecycle. Skills are either theirs (referenced remotely) or yours (vendored locally at the ID's path). The system eliminates the installed-but-stale third state by design—no update commands, no version pinning, no conflict resolution. The improved system avoids the common failure where a skill's instructions drift from the service it controls, because refresh is always an explicit, conflict-safe re-save.

  6. Expose a directory-as-menu composition interface. The system treats any directory of SKILL.md files as a bundle without all-or-nothing delivery. Users can reference a single skill, a subset, or the whole directory with one @ line. The improved system lets teams organize procedural knowledge hierarchically (e.g., @skills:deploy/aws/ vs. @skills:deploy/aws/ec2) without forcing monolithic packages.

  7. Add local-first skill indexing for autocomplete. The system scans git-tracked .atskills/ directories and surfaces matching skills the moment the user types @, with the index living in tooling, not in the model's context. The improved system provides instant discoverability of team-shared skills without consuming any prompt budget for the index itself.

  8. Implement a single-instruction-file client adapter. The system reads a SKILLS.md file that defines the @skills: protocol, enabling any agent that can read files, run shell commands, and fetch URLs to become a full client. The improved system gains cross-agent portability—the same skill set works across different agent hosts with zero vendor-specific integration.

  9. Add a hub-optional search and ranking layer. When the system encounters an unknown @skills: reference, it can query a hub (e.g., atskills.one) for search and ranking across the public corpus, but resolves gh: and local paths directly with no hub dependency. The improved system finds relevant skills from the 56,804-skill ecosystem without forcing all traffic through a central service.

  10. Enable one-screen authoring for non-developers. The system provides a minimal editor interface for creating SKILL.md files (frontmatter + body) that captures procedural knowledge without requiring git or packaging expertise. The improved system lets domain experts (e.g., compliance officers, lab technicians) contribute executable skills directly, expanding the corpus beyond developer-authored content.

What the improved AI system can do that it couldn't before:

  • Maintain high instruction-following accuracy in 200+ turn sessions by dynamically shedding resident-context weight.

  • Execute composite tasks requiring 3–5 skills simultaneously with deterministic, complete instruction delivery.

  • Operate fully offline with cached skills, marked stale but usable, without risking silent outdated behavior.

  • Share a team's working skill set via git clone, with zero installation overhead and instant @ autocomplete.

  • Adopt the protocol on any existing agent by adding one instruction file, no vendor changes required.

  • Avoid the installed-but-forgotten failure where skills sit unused in per-agent directories.

Abstract

There are 56,804 public agent skills today, and teams write many more privately. The dominant delivery model is installation: once installed, a skill's description remains in the system prompt, competing for fewer than 100 reliable trigger slots. This leaves the long tail with no practical path to use and forces teams' own playbooks to compete for the same scarce space. We observe that installation bundles three separable functions: content, persistence, and automatic triggering. Only the last requires prompt residency. We therefore propose @skills, an open protocol that separates them. A path addresses any skill, subtree, or collection, and reading a skill is sufficient to use it, so nothing is installed or made resident. The operation vendors a copy at the same path into a project's Git-tracked tree for adaptation and ownership. The operation adds one.gitignore-style line, the only element that costs prompt residency. A directory is a menu, making bundles ordinary directories rather than all-or-nothing units. The protocol requires no manifest, lockfile, or registration, and SKILL.md remains unchanged. @skills is additive, ships as an installable package, and turns any agent that can read files and run commands into a client through a single instruction file. Its open specification is at https://github.com/SylphAI-Inc/atskills and it is implemented in the AdaL CLI at https://adalagent.ai. Because paths address skills well but cannot find them, the protocol is paired with a free hub at https://atskills.one for corpus-wide search and ranking, repository-free hosting, private and team collections, and one-screen authoring. The hub is optional: gh: and local paths resolve without it, and indexed GitHub skills retain their gh: identities. Install less, use more.

Sources

Related papers