ax-check rule
AXC-D025: Bundled reference missing
SKILL.md links to a bundled file that does not exist, or points outside the skill folder.
ax-check is a checker being prepared for release. This page documents the rule ahead of that release; see all 50 rules.
| Severity | error |
| Kind | Conformance. A finding is a fact about the input. |
| Mode | ax-check lint |
| Applies to | SKILL.md |
| Pattern tags | skills, drift |
| Fix in one line | Add the referenced file inside the skill folder, or correct the relative path. |
SKILL.md links to a bundled file that does not exist, or to a path outside the skill folder. When the agent follows the link, it finds nothing, and it must either guess the missing instructions or stop. Paths outside the folder are a particular risk, because an installer may copy only the skill folder itself.
What it checks
ax-check finds the file references in the SKILL.md body and checks each one against the files actually in the skill folder. It reports a reference when:
- the file (or folder) it names does not exist in the skill folder; or
- the path is absolute, or climbs out of the skill folder with
../.
Why it matters
The Agent Skills specification describes progressive loading: SKILL.md stays short, and files in scripts/, references/ and assets/ are loaded only when required. Other files are referenced with relative paths from the skill root. That design only works if the referenced files are there when the agent asks for them.
A reference outside the folder may work in the author’s repository and break after installation. In addyosmani/agent-skills issue #361, “npx packs only skills/”, per-skill installs dropped shared files that lived outside the skill folder. A link that works during development can point at nothing once installed.
Files also get renamed and moved. A missing reference is a form of drift between the instructions and the files they describe.
How to fix
- Add the missing file inside the skill folder, at the path the link uses.
- Or correct the link to the file’s real path, relative to the folder that holds SKILL.md.
- Copy shared material into each skill that needs it, rather than linking to
../shared/.
Example
Before
skills/invoice-review/SKILL.md (folder also contains references/tax-rates.md)
Check the tax rate in [the tax table](references/tax-table.md).
Follow the house style in [the style guide](../shared/invoice-style.md).
Run `scripts/check_totals.py` on the draft.
After
skills/invoice-review/SKILL.md (folder contains references/tax-rates.md,
references/invoice-style.md, scripts/check_totals.py)
Check the tax rate in [the tax table](references/tax-rates.md).
Follow the house style in [the style guide](references/invoice-style.md).
Run `scripts/check_totals.py` on the draft.
How ax-check detects it
This rule needs the list of files in the skill folder. From the command line, ax-check always lists the folder that holds each SKILL.md; the rule is skipped only when the ax-check library is given a SKILL.md without its file list. It looks at the SKILL.md body (not the frontmatter) and skips fenced code blocks that start with three backticks or three tildes. It collects two kinds of reference:
- Markdown links and images whose target is not a URL (anything with a scheme, such as
https:ormailto:), not an in-page anchor (#...) and not protocol-relative (//...); - inline code spans that look like a bundled path: an optional
./or../, thenreferences/,reference/,scripts/,assets/,templates/,examples/ordocs/, then a path that ends in a file extension.
ax-check removes any #anchor or ?query, decodes percent-encoding and resolves . and .. from the skill root. A path that starts with / or climbs above the skill root is reported as outside the folder. Any other path is reported when no file has that path and no file sits inside a folder of that name. Each target is reported once, at its first line.
Known false positives: a link written inside inline code, such as `[guide](guide.md)`, is still read as a link. A link to a sibling skill (../other-skill/SKILL.md) is reported even if your installer always copies both. Known false negatives: a path in plain text without backticks, a code span under another folder name (for example `notes/setup.md`) and anything inside a fenced code block are not checked.
If the finding does not apply, silence it with --disable AXC-D025.
Sources
- Specification: Agent Skills specification, agentskills.io, retrieved 2026-10-08. https://agentskills.io/specification. Files in
scripts/,references/andassets/are loaded only when required; reference other files with relative paths from the skill root. - Vendor issue: addyosmani/agent-skills issue #361, “npx packs only skills/”, GitHub, retrieved 2026-10-08. https://github.com/addyosmani/agent-skills/issues/361. Per-skill installs dropped shared files outside the skill folder.
Related evidence
Records in the AX evidence register that share a pattern tag with this rule. A shared tag means the record is about the same pattern, not that it tests this rule. Read the evidence class before the number.
- EV-0040: Agent skills recommended a package that does not exist (Vendor measurement). Merged pull requests in Vercel's agent plugin repository corrected skill instructions that recommended an npm package that is not published, and plugin guidance that advertised deployment cards the production MCP server does not expose.
- EV-0017: Injected skills lowered pass rates and raised token cost on average (Preprint). WebDev-Skills-Bench (preprint) found that injecting matched public skills reduced mean Pass@2 by 1.3% to 4.2% across four models and raised token cost by 72% to 394%, with gains in only 17% to 36% of skill-project pairs.
- EV-0018: Skill rules that name a command or path change what agents do (Preprint). A study of 3,159 skills (preprint) found that adding a checkable rule raised the rate at which four coding agents took the required action by +0.23 on average, with the gain coming mainly from rules naming a command or path the old skill did not mention.
- EV-0019: Skill selection precision collapses as the skill pool grows (Preprint). A preprint reports that as the pool of available skills grew from 5 to 100, the precision with which agents actually used the right skill fell from 29.6% to 3.3%.
- EV-0030: Adding the context7 MCP server gave no lift; its tools went unused (Vendor measurement). Microsoft reports that adding the context7 MCP server to an anti-hallucination skill gave no meaningful lift on an SPFx upgrade: its tools did not load in 3 of 5 runs and were not called in the other 2, while telling the agent to use CLI for Microsoft 365 raised configuration correctness from 30/80 to 75/80.
- EV-0032: Vendor claim: agents never invoked a docs skill in 56% of eval cases (Vendor claim). Vercel states that in its Next.js 16 evals the docs skill was never invoked in 56% of cases, so the skill matched the 53% pass rate of no docs, while an 8KB docs index in AGENTS.md reached 100%.
