HOST: If I review the instructions our coding agents use, why should I care where other teams copied them from? EXPERT: You might use that history to decide which shared sources to inspect first, and to check whether your own copies received later changes. HOST: So why wouldn't I just look for the most popular projects? EXPERT: Yeah, the authors found that GitHub stars, which are sort of a popularity signal, didn't really identify the main sources of later copies very well. They looked instead at when repositories first acquired certain skills. HOST: So what does that tracing look like in ordinary terms? EXPERT: Imagine one project copying a folder of agent instructions from another. The authors used the files' recorded histories to date that move and identify an earlier holder. That traces distribution, not necessarily authorship. HOST: Did choosing sources that way change the review result? EXPERT: In their later data evaluation, reviewing the hundred sources ranked highest by their model prevented 14.9 percent of later high-risk skill adoptions under the evaluation's rules. The hundred most starred prevented 0.5 percent. Those are modeled review outcomes, not field results. HOST: So, can I assume a fix at a source will reach my copy? EXPERT: No, the authors found that copies rarely follow later source edits. Their data cover public GitHub's early period for this format, and their risk flags mark capabilities, not malicious intent. The practical takeaway is to check copies themselves.