# Artifact Signing

> A skill to sign artifacts using a digital certificate and private key.

- Skill: `dvcrn/artifact-signing` (Agent Skill, multi-file: 4 files)
- Install (CLI): `npx skillmds@latest add dvcrn/artifact-signing`
- Raw SKILL.md: https://api.skillmd.com/api/skills/dvcrn/artifact-signing/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: dvcrn (https://skillmd.com/u/dvcrn)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/dvcrn/artifact-signing

---


# Artifact Signing Skill

This skill allows an AI agent to sign files, binaries, or any artifact using a PEM-encoded private key. It generates a detached signature file.

## Dependencies

- Python 3.x
- `cryptography` library (`pip install cryptography`)

## Tools

### `sign_artifact`

Signs a given artifact with a private key.

**Arguments:**

- `artifact_path`: (Required) Absolute path to the file to be signed.
- `key_path`: (Required) Absolute path to the PEM-encoded private key.
- `output_path`: (Optional) Absolute path where the signature should be saved. Defaults to `<artifact_path>.sig`.

**Example Usage:**

```powershell
python c:\Docs\skills\artifact-signing\scripts\sign_artifact.py "C:\path\to\artifact.zip" "C:\path\to\private_key.pem"
```

## Security Considerations

- **Private Key Protection**: Never share your private key. Ensure the key file has restricted permissions.
- **Verification**: Always verify the signature using the corresponding public key before trusting an artifact.

