# SLSA Verifier Build Provenance Checker

> SLSA Verifier is the official tool from the SLSA framework for verifying build provenance attestations generated by SLSA-compliant builders. It checks that software artifacts were built from the expected source, by an authorized builder, without tampering in the build pipeline.

- Skill: `agentskillexchange/slsa-verifier-build-provenance-checker` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/slsa-verifier-build-provenance-checker`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/slsa-verifier-build-provenance-checker/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/slsa-verifier-build-provenance-checker

---


# SLSA Verifier Build Provenance Checker

SLSA Verifier is the official tool from the SLSA framework for verifying build provenance attestations generated by SLSA-compliant builders. It checks that software artifacts were built from the expected source, by an authorized builder, without tampering in the build pipeline.

## Installation

Use the upstream install or setup path that matches your environment:
- $ go install github.com/slsa-framework/slsa-verifier/v2/cli/slsa-verifier@v2.7.1
- $ go install github.com/slsa-framework/slsa-verifier/v2/cli/slsa-verifier
- $ git clone git@github.com:slsa-framework/slsa-verifier.git

Requirements and caveats from upstream:
- [npm packages built using the SLSA3 Node.js builder](#npm-packages-built-using-the-slsa3-nodejs-builder)
- | source-branch | Expects a branch like main or dev. Not supported for all GitHub Workflow triggers. | [GitHub builders](https://github.com/slsa-framework/slsa-github-generator#generation-of-provenance) |
- #### npm packages built using the SLSA3 Node.js builder

Basic usage or getting-started notes:
- You have two options to install the verifier.
- ### Compilation from source
- #### Option 1: Install via go

- Source: https://github.com/slsa-framework/slsa-verifier
- Extracted from upstream docs: https://raw.githubusercontent.com/slsa-framework/slsa-verifier/HEAD/README.md

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/slsa-verifier-build-provenance-checker/)

