Install payload
Install payload is broadly covered in current results.
92% (11/12)
Source-backed filter active — add entries to compare trust side by side.
24 results in this view
2 trust signals differ in this sample: Source provenance, Submitter
Signals differ on Source provenance, Submitter — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
92% (11/12)
Most at-risk entries in this view
Open SWE
Missing required: Install payload
GitHub Actions Security Review Capability Pack Skill
No required rollout gaps
GitHub Artifact Attestation Provenance Capability Pack Skill
No required rollout gaps
GitHub Check Runs Statusline
No required rollout gaps
GitHub Search Review Queue Statusline
No required rollout gaps
Adoption queue
2/24 visible results are in hold tier and need mitigation before adoption.
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/ci-failure-triage · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/incident-timeline · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/addy-osmani-agent-skills · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/claude-code-analytics-adoption-capability-pack · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
mcp/arabold-docs-mcp-server · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
tools/gemini-cli · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/github-actions-security-review-capability-pack · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/github-artifact-attestation-provenance-capability-pack · trust review · confidence 67%
Decision confidence
2/24 results are low-confidence and need review before adoption.
Address Metadata review, Package integrity before broader rollout.
54/100
commands/ci-failure-triage · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
commands/incident-timeline · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/addy-osmani-agent-skills · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/claude-code-analytics-adoption-capability-pack · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
mcp/arabold-docs-mcp-server · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
tools/gemini-cli · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/github-actions-security-review-capability-pack · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/github-artifact-attestation-provenance-capability-pack · trust review
Freshness distribution
Median age 52 days; all 12 scanned entries are within 90 days.
Theme distribution
91 distinct themes with no dominant one. Most common: github, claude-code, agent-skills.
91 distinct themes across 24 scanned
Expert GitHub Actions security review capability pack applying documented workflow hardening, GITHUB_TOKEN least privilege, secrets handling, and fork PR safety checks from official GitHub Actions security documentation.
Expert skill for reviewing GitHub Artifact Attestations, release artifact digests, workflow provenance, OIDC boundaries, and public release evidence before an AI agent recommends or publishes build outputs.
Claude Code statusline that reads GitHub REST check runs for the active pull request head commit and summarizes failed, pending, and passing checks.
Claude Code statusline that uses GitHub pull request search qualifiers to show review-requested queue counts for maintainers.
Index any documentation — websites, GitHub repos, npm/PyPI packages, local files — and give Claude always-current, version-specific answers with the open-source Grounded Docs MCP server. An offline-first alternative to Context7, Nia, and Ref.Tools.
Microsoft-maintained Agent Skills, plugins, custom agents, AGENTS.md templates, and MCP configurations for Azure SDKs, Microsoft Foundry, Microsoft 365 Agents SDK, Copilot SDK, MCP server building, and cloud solution work.
Expert release changelog generation capability pack for drafting, validating, and publishing user-facing release notes from conventional commits, tags, and GitHub Releases with source-backed review matrices and privacy-safe output.
Expert Claude Code analytics adoption capability pack for enabling team and enterprise dashboards, GitHub contribution metrics, adoption tracking, ROI reporting, and OpenTelemetry complements with source-backed rollout steps.
Code research MCP server that gives Claude GitHub code search, repository exploration, PR search, local ripgrep, local file reading, LSP definitions, references, call hierarchy, and package-to-source discovery.
MCP server that unifies web search, AI answer, GitHub search, and web extraction providers including Tavily, Brave, Kagi, Exa, Linkup, Firecrawl, and GitHub behind four consolidated tools.
Remote MCP server that turns any GitHub repository or GitHub Pages site into a documentation and code context source for AI coding assistants.
Open-source framework for building internal coding agents that accept tasks via Slack, Linear, or GitHub, execute code changes in isolated cloud sandboxes, and open draft pull requests automatically.
Slash command that triages a failing GitHub Actions run: it pulls the failed job logs with the GitHub CLI, isolates the first real error, classifies the failure (test, lint, type, build, dependency, or flaky), and proposes a targeted, minimal fix with the exact command to reproduce it locally.
PreToolUse hook that scans the exact text Claude Code is about to write or edit for high-confidence secret formats (AWS access keys, GitHub tokens, OpenAI keys, Slack tokens, Google API keys, Stripe keys, and private key blocks) and blocks the write with a non-zero exit before the secret ever reaches disk.
Read-only Claude Code Stop hook that checks the current GitHub pull request title against a Conventional Commits style pattern before the session ends, then falls back to the latest commit subject when no PR title is available.
LoopOver MCP connects Claude and other MCP clients to private, metadata-only Gittensor contribution workflows for branch preflight, scoreability estimates, maintainer-fit checks, and public-safe PR packets.
Google's open-source terminal AI agent for Gemini-powered coding and automation, with code understanding, file edits, shell commands, web fetching, Google Search grounding, MCP server integrations, checkpointing, GEMINI.md context files, and GitHub workflow automation.
Slash command that builds a chronological incident timeline from trusted sources such as GitHub Actions run metadata, deployment notes, and operator timestamps, then drafts a handoff-ready post-incident summary.
Expert maintainer pull request triage capability pack for classifying open PRs, applying labels, routing reviewers, checking merge readiness, and producing privacy-safe queue summaries using GitHub pull request documentation workflows.
Addy Osmani's production-grade Agent Skills pack for AI coding agents, with lifecycle slash commands, engineering workflow skills, review personas, quality gates, and cross-agent setup guidance for Claude Code, Cursor, Gemini CLI, Antigravity CLI, OpenCode, GitHub Copilot, and other agents.
MIT-licensed `skills` CLI from Vercel Labs for installing, using, finding, listing, updating, removing, and initializing Agent Skills across Claude Code, Codex, Cursor, OpenCode, OpenClaw, Gemini CLI, GitHub Copilot, Windsurf, Zed, and dozens of other agent hosts.
Multi-harness agentic plugin marketplace with 84 plugins, 192 agents, 156 skills, 102 commands, and 16 orchestrators for Claude Code, Codex CLI, Cursor, OpenCode, Gemini CLI, and GitHub Copilot from one Markdown source tree.
PreToolUse Write and Edit guardrail combining the hooks guide protected-file pattern with a local scan for common hardcoded credential shapes called out by GitHub secret scanning guidance before content is written.
MIT-licensed command-line software-engineering agent for local coding tasks, GitHub issue fixing, trajectory inspection, and SWE-bench style evaluation.