Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry | ArxivCSExplorer