Skip to main content

Browse the directory

Showing 12 resources for "provenance"
Saved
Active

11 review · 1 limited in this set — compare to see which signals differ.

Trust snapshot

12 results in this view

Claimed
0%(0/12)

2 trust signals differ in this sample: Source provenance, Submitter

Signals differ on Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

12 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (12/12)

Adoption queue

Browse adoption queue · balanced

1/12 visible results are in hold tier and need mitigation before adoption.

ready 0caution 11hold 1

Content-Only Submission PR Gate Rules

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

rules/content-only-submission-pr-gate-rules · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/github-artifact-attestation-provenance-capability-pack · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/lockfile-provenance-checker · trust review · confidence 67%

Open Source PR Security Review Agent

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

agents/open-source-pr-security-review-agent · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

guides/package-provenance-checks-before-installing-mcp-servers · trust review · confidence 67%

Privacy Metadata Rules

1 blockers: Metadata review

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

rules/privacy-metadata-rules · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/reg-suit-visual-regression-review-capability-pack · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

0/12 results are high-confidence for the selected preset.

high 0medium 12low 0

Content-Only Submission PR Gate Rules

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

rules/content-only-submission-pr-gate-rules · trust review

Open Source PR Security Review Agent

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

agents/open-source-pr-security-review-agent · trust review

Privacy Metadata Rules

Address Metadata review, Package integrity before broader rollout.

medium

54/100

Missing: Metadata reviewMissing: Package integrity

rules/privacy-metadata-rules · trust review

Freshness distribution

Current results are broadly fresh

Median age 54 days; all 12 scanned entries are within 90 days.

median 54d

Aging

91–180 days

0%

0 entries

Stale

> 180 days

0%

0 entries

Theme distribution

Results center on provenance

50% of this view shares the top theme. Leading themes: provenance, security, supply-chain.

Focused

43 distinct themes across 12 scanned

Expert agent skills retrieval source verification capability pack for validating canonical URLs, documentation reachability, repo provenance, and duplicate source claims before publishing or submitting Claude Code skills.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓
GitHub logo

Expert skill for reviewing GitHub Artifact Attestations, release artifact digests, workflow provenance, OIDC boundaries, and public release evidence before an AI agent recommends or publishes build outputs.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

PostToolUse hook that inspects an edited npm package-lock.json for supply-chain provenance risk rather than known CVEs — dependencies resolved from outside the public npm registry (git, alternate-registry, or insecure transports) and registry tarballs missing an integrity hash.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Expert reg-suit review skill for evaluating rendered UI image baselines, thresholds, snapshot storage, report artifacts, and visual QA release readiness.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Expert SLSA provenance review skill for checking source, build, artifact, and trust evidence before accepting content or package submissions.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Verify MCP server package provenance before Claude Code installation: registry publisher match, repository ownership, release artifact checksums, maintainer history, and rollback when supply-chain signals fail review.

Source-backed agent for security review of open-source pull requests, including untrusted fork boundaries, GitHub Actions permissions, secret and code scanning, dependency review, provenance signals, and maintainer-owned merge recommendations.

Source-backed rules for AI workflow directories that need consistent privacy metadata before accepting entries that touch prompts, files, local tools, hosted services, telemetry, generated artifacts, or personal data.

A practical guide for preparing source-backed HeyClaude content pull requests that stay focused, cite verifiable sources, avoid generated artifacts, and pass content validation.

Checklist for reviewing remote MCP servers before team rollout: OAuth scopes, transport security, tool surface, registry provenance, and rollback.

Source-backed rules for preparing direct content-only pull requests with one raw MDX file, reachable provenance URLs, issue closure, duplicate history, validation evidence, and no generated artifact churn.

A defense-in-depth bundle for hardening an agentic Claude Code workstation: block secrets and sensitive data before they are written, verify dependency provenance and known vulnerabilities, review supply-chain risk and run code security audits, and harden MCP tool access against prompt injection.