Skip to main content

Browse the directory

Showing 10 resources for "supply-chain"
Saved
Active

Source-backed filter active — add entries to compare trust side by side.

Trust snapshot

10 results in this view

Claimed
0%(0/10)

2 trust signals differ in this sample: Source provenance, Submitter

Signals differ on Source provenance, Submitter — add entries to compare before you install.

Rollout signal scan

2 rollout risk signals in current results

Biggest gaps: metadata review, package integrity. 0 entries have 2+ required gaps.

10 scanned

Install payload

Install payload is broadly covered in current results.

good

100% (10/10)

Adoption queue

Browse adoption queue · balanced

0/10 visible results are ready for staged adoption under this preset.

ready 0caution 10hold 0

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/claude-code-plugin-marketplace-authoring-capability-pack · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

skills/github-artifact-attestation-provenance-capability-pack · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/lockfile-provenance-checker · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/ort-dependency-license-checker-hook · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/package-download-checksum-guard-hook · trust review · confidence 67%

caution

50/100

Request metadata review from maintainers or internal owners.

Collect package checksum or signed artifact information.

hooks/package-lock-risk-detector-hook · trust review · confidence 67%

Decision confidence

Decision confidence scan · balanced

0/10 results are high-confidence for the selected preset.

high 0medium 10low 0

Freshness distribution

Current results are broadly fresh

Median age 53 days; all 10 scanned entries are within 90 days.

median 53d

Aging

91–180 days

0%

0 entries

Stale

> 180 days

0%

0 entries

Theme distribution

Results center on supply-chain

90% of this view shares the top theme. Leading themes: supply-chain, security, hooks.

Focused

35 distinct themes across 10 scanned

Security scanner from Snyk for discovering local AI agent components, including MCP servers and Agent Skills, and checking them for prompt injection, tool poisoning, tool shadowing, toxic flows, malware payloads, credential handling, and hardcoded secrets.

Expert plugin marketplace authoring capability pack applying documented marketplace.json catalogs, /plugin marketplace add flows, private repo distribution, and supply-chain review from official plugin marketplace documentation.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

Slash command that reviews the supply-chain risk of a project's dependencies using OpenSSF Scorecard health signals rather than CVE counts.

Invocation:/dependency-risk-review [package]
Safety ✓ Privacy ✓

PostToolUse hook that flags risky package-lock.json, yarn.lock, and pnpm-lock.yaml edits: missing lockfile updates, unexpected registry hosts, and dependency count spikes before merge.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Slash command that reviews a pull request diff for security regressions: authentication and authorization gaps, injection surfaces, secret exposure, unsafe deserialization, and dependency risk introduced by the change.

Invocation:/pr-security-review [pr-number]
Safety ✓ Privacy ✓
GitHub logo

Expert skill for reviewing GitHub Artifact Attestations, release artifact digests, workflow provenance, OIDC boundaries, and public release evidence before an AI agent recommends or publishes build outputs.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓

PreToolUse hook that reviews proposed Bash commands for package, installer, and archive downloads, then blocks curl or wget download commands that do not include an adjacent checksum or signature verification step.

Trigger:PreToolUse
Safety ✓ Privacy ✓

PostToolUse hook that inspects an edited npm package-lock.json for supply-chain provenance risk rather than known CVEs — dependencies resolved from outside the public npm registry (git, alternate-registry, or insecure transports) and registry tarballs missing an integrity hash.

Trigger:PostToolUse
Safety ✓ Privacy ✓

PostToolUse hook that watches dependency manifest and lockfile edits, then prompts or runs an OSS Review Toolkit dependency license analysis.

Trigger:PostToolUse
Safety ✓ Privacy ✓

Expert SLSA provenance review skill for checking source, build, artifact, and trust evidence before accepting content or package submissions.

Level:expertType:capability-packVerified:validated
Safety ✓ Privacy ✓