Install payload
Install payload is broadly covered in current results.
100% (3/3)
Source-backed filter active — add entries to compare trust side by side.
3 results in this view
2 trust signals differ in this sample: Source provenance, Submitter
Signals differ on Source provenance, Submitter — add entries to compare before you install.
Rollout signal scan
Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.
Install payload
Install payload is broadly covered in current results.
100% (3/3)
Adoption queue
0/3 visible results are ready for staged adoption under this preset.
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
commands/ci-failure-triage · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/github-actions-security-review-capability-pack · trust review · confidence 67%
1 blockers: Metadata review
50/100
Request metadata review from maintainers or internal owners.
Collect package checksum or signed artifact information.
skills/github-artifact-attestation-provenance-capability-pack · trust review · confidence 67%
Decision confidence
0/3 results are high-confidence for the selected preset.
Address Metadata review, Package integrity before broader rollout.
54/100
commands/ci-failure-triage · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/github-actions-security-review-capability-pack · trust review
Address Metadata review, Package integrity before broader rollout.
54/100
skills/github-artifact-attestation-provenance-capability-pack · trust review
Freshness distribution
Median age 53 days; all 3 scanned entries are within 90 days.
Theme distribution
100% of this view shares the top theme. Leading themes: github-actions, artifact-attestations, capability-pack.
12 distinct themes across 3 scanned
Expert GitHub Actions security review capability pack applying documented workflow hardening, GITHUB_TOKEN least privilege, secrets handling, and fork PR safety checks from official GitHub Actions security documentation.
Expert skill for reviewing GitHub Artifact Attestations, release artifact digests, workflow provenance, OIDC boundaries, and public release evidence before an AI agent recommends or publishes build outputs.
Slash command that triages a failing GitHub Actions run: it pulls the failed job logs with the GitHub CLI, isolates the first real error, classifies the failure (test, lint, type, build, dependency, or flaky), and proposes a targeted, minimal fix with the exact command to reproduce it locally.