A citation can remain unchanged while the authority behind it changes completely.
Manifold Security found placeholder domains embedded across public code and agent skills that were harmless when originally cited but later served malicious or deceptive content after ownership or behavior changed. Some references had propagated through large numbers of files and forks without the citation string itself changing.
The continuity failure
The record preserved the identifier but not the continuing relationship between that identifier and its current owner, content, or purpose.
The GovKM interpretation
Provenance can expire. Future reuse therefore requires revalidation of external references, not blind trust in historical citation integrity.
Continuity path: Source / external domain → Evidence / citation → Record → Institutional Memory → Future Reuse → revalidation of current referent.
Sources
Manifold Security, “The third-party.com domain is serving a ClickFix lure to Windows users,” September 23, 2026; “Over 350,000 GitHub files cite placeholder domains serving scams,” September 24, 2026.



