Supply Chain

Block typosquats, unpinned dependencies, floating GitHub Actions tags, `curl | bash` installs, unverified agent skills/MCP servers, and post-install scripts from unknown publishers before they reach a developer machine, a CI runner, or a production image. Require lockfile-based installs, SHA-pinned third-party actions, registry-namespace verification, and provenance checks (Sigstore, npm provenance, GitHub attestations) for any code that will run.

catpilotai Updated

File contents

catpilotai/catpilot-ai-guardrails/tree/main/src/skills/core/supply-chain commit a04d0b6e49

Frequently asked questions

npx skillmds@latest add catpilotai/supply-chain