Copied, Fetched, and Left Without Evidence: Permissive Washing in AI-Agent Supply Chains
Abstract
Permissive washing occurs when an artifact declares MIT, Apache-2.0, or BSD-3-Clause without the matching license text and required copyright holders that form its compliance payload. Documented in datasets and models, it now affects an AI-agent ecosystem built on shared Skills, Model Context Protocol (MCP) servers, and Plugins. These components are reused and distributed like software. Authors copy folders and files into repositories, and installers and registries deliver selected directories and packages. Their permissive licenses condition such copying and redistribution on retaining notices, so losing the compliance payload can have legal consequences. We trace the compliance payload across publication, reuse, composition, and distribution. Among 345,371 assessed Skill occurrences, 59.4% lack a complete compliance payload anywhere from folder to repository root, and only 9.5% carry one inside the Skill folder. Even when the reference was complete before reuse, 41.1% of Skill file copies and 58.5% of MCP server file copies (copies made without forking) lose it. Distribution loses it the same way. Claude Code leaves 173 of 229 repository-complete Skill deliveries without either part, Codex agrees on every shared outcome, and 22 of 121 registry archives for MCP servers omit the compliance payload. The compliance payload survives when the unit copied or delivered encloses it, not merely when the repository does. We release all data and code in a replication package.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.